With a simple but efficient attack, BadgerDAO hackers stole $120 million worth of cryptocurrencies

With a simple but efficient attack, BadgerDAO hackers stole $120 million worth of cryptocurrencies

While the investigation is still ongoing, members of the Badger team have told users that they believe the issue came from someone inserting a malicious script in the UI of their website. For any users who interacted with the site when the script was active, it would intercept Web3 transactions and insert a request to transfer the victim’s tokens to the attacker’s chosen address.

Someone drained assets from various cryptocurrency wallets linked to the decentralised finance website BadgerDAO on Wednesday night. The numerous tokens stolen in the hack are worth around $120 million, according to Peckshield, a blockchain security and data analytics firm that is collaborating with Badger to investigate the crime.

Because of the transparent nature of the transactions, we can see what happened once the attackers pounced. PeckShield points out one transfer that yanked 896 Bitcoin into the attacker’s coffers, worth more than $50 million. According to the team, the malicious code appeared as early as November 10th, as the attackers ran it at seemingly random intervals to avoid detection.

Decentralized finance (or DeFi) systems rely on blockchain technology to let crypto owners perform more typical finance operations like earning interest via lending. BadgerDAO promises users they can “rest easy knowing you never have to give up the private keys for your crypto, you can withdraw anytime you like, and our strategists are working day and night to put your assets to work.” Its protocol allows people who have Bitcoin to “bridge” their cryptocurrency over to the Ethereum platform via its token and take advantage of DeFi opportunities they otherwise might not have access to.

Once Badger became aware of the unauthorized transfers, it paused all smart contracts, essentially freezing its platform, and advised users to decline all transactions to the attacker’s addresses.

Thursday night, the company said it has “retained data forensics experts Chainalysis to explore the full scale of the incident & authorities in both the US & Canada have been informed & Badger is cooperating fully with external investigations as well as proceeding with its own.”

One of the things Badger is investigating is how the attacker apparently accessed Cloudflare via an API key that should’ve been protected by two-factor authentication. While the attack didn’t reveal specific flaws within Blockchain tech itself, it managed to exploit the older “web 2.0” technology that most users need to use to perform transactions. Multi-factor authentication systems protect our accounts against many phishing schemes or bulk credential stuffing attacks. Still, experts have repeatedly warned about targeted phishing attacks that can bypass it, while toolkits to automate the process have been available for years. An FBI notice in 2019 (pdf) called out criminals’ growing capabilities to bypass MFA and suggested changes or training that could make such attacks harder to pull off.

Getting two-factor authentication right can be tricky even within typical financial applications — just ask PayPal. But incidents like this one, or the stolen-and-returned $600 million hijack that Poly Network suffered in August, or the $53 million heist that hit the first DAO ever in 2016, are hopefully enough to expand awareness of security beyond protocols and encryption.

One commenter within Badger’s Discord summed up the situation by saying, “All [the] blockchain / smart contract audits in the world, and people lose 120m to a Cloudflare API leak by a sloppy team where a dude passes a new approval to his contract in the site header – GG – we still have a long way to go.” A member of the team said, “I’m sure we will have some mitigation procedures proposed after this.”  

The News Highlights

  • With a simple but efficient attack, BadgerDAO hackers stole $120 million worth of cryptocurrencies
  • Check the latest update on Security news
  • .

Disclaimer: If you need to edit or update this news from compsmag then kindly contact us Learn more

For Latest News Follow us on Google News


Latest Headlines
  • Show all
  • Trending News
  • Popular By week
With Xbox Game Pass, you can play two games right now (January 18)
With Xbox Game Pass, you can play two games right now (January 18)
Complete Quests to discover and swap between many varied and distinct Forms. Mix and match abilities in unexpected ways to unlock and complete even MORE ...
China's 'zero-COVID' campaign under pressure as Omicron rises
China’s ‘zero-COVID’ campaign under pressure as Omicron rises
The approach has kept infections at a minimum, but some experts warn that China could become the victim of its own success as a lack of exposure to COVID-19 ...
Magawa, Cambodia's landmine-sniffing 'hero' rat, dies in retirement
Magawa, Cambodia’s landmine-sniffing ‘hero’ rat, dies in retirement
“Magawa was in good health and spent most of last week playing with his usual enthusiasm, but towards the weekend he started to slow down, napping more and ...
A golden QR code can be engraved on a iPhone 13 Pro
A golden QR code can be engraved on a iPhone 13 Pro
Plenty of regular folk have taken to putting their own COVID certificate on their lock screen or home screen, to facilitate the necessary evil of displaying ...
UK Finance Minister Sunak: Of course I believe PM at lockdown parties
UK Finance Minister Sunak: Of course I believe PM at lockdown parties
Our Standards: The Thomson Reuters Trust Principles. Register Register now for FREE unlimited access to Reuters.com Reporting by William James; editing by ...
Here's What's New in the OnePlus 9RT's First Update of the Year
Here’s What’s New in the OnePlus 9RT’s First Update of the Year
Included in the update, the December 2021 security patch is there to make sure that all privacy issues and any exploits uncovered by software engineers have ...
A jump in Treasury yields has hit equity markets, particularly in the tech sector
A jump in Treasury yields has hit equity markets, particularly in the tech sector
The dollar hit a six-day high following the jump in Treasury yields, while inflation fears were bolstered as crude prices rose to their highest since 2014 on ...
Ontario reports more than 4,100 coronavirus hospitalizations as the prime minister says ‘positive news’ about restrictions coming
Ontario reports more than 4,100 coronavirus hospitalizations as the prime minister says ‘positive news’ about restrictions coming
Long-term care homes continue to battle the highly-contagious Omicron variant as there are 421 active outbreaks at homes across the province, up from 369 a ...
Tech, Bank inscriptions are among India's top stock picks for 2022
Tech, Bank inscriptions are among India’s top stock picks for 2022
Despite some concerns about lofty valuations and a gradual unwinding of easy-money policies, India’s benchmark is among those leading gains in Asia so far in ...
Crypto.com ends withdrawals after suspicious activity
Crypto.com ends withdrawals after suspicious activity
He later shared that his wallet had been refunded. One crypto user with nearly 350,000 Twitter followers, who posts under the handle @BENBALLER complained ...
Show next
We will be happy to hear your thoughts

Leave a reply

Compsmag - Latest News In Tech and Business
Logo