Etherscan 1337 Hack Did Not Compromise Crypto Wallets

Etherscan 1337 Hack Did Not Compromise Crypto Wallets
фото показано с : blokt.com

2018-7-27 16:49

Cryptocurrency investors consider security a very serious issue these days. And they could not be blamed for this very cautious stance as hackers have been known to successfully breach crypto exchanges and get away with multimillion-dollar loots in virtual currencies in numerous hacking incidents. This explains why many were alarmed on July 23, when visitors of Etherscan.io saw the deceptively simple pop-up message “1337,” which in hacker lingo meant that the site had been hacked.

Etherscan.io’s Vulnerability

One advantage of blockchain is that anyone can easily validate and confirm transactions. Basically, it’s a public record, according to Futurism, unlike transactions made via banks and other traditional financial institutions, which keep information on transactions in super secure servers where access is limited.

To access blockchain transaction details, users need to go through sites called BlockExplorers. The Etherscan.io site is a very popular BlockExplorer site, which explains why Twitter was quickly flooded with messages as users who have noticed the hack quickly warned other users to stay away from the Etherscan site, reports Motherboard.

Apparently, the hackers targeted the Disqus API, a third-party service that enables comments to be posted in Ethereum wallet addresses, according to TNW. This allowed them to inject JavaScript code into the interface, which was responsible for that pop-up “1337” message that alarmed Etherscan.io users.

After being notified, the Etherscan team quickly took charge of the situation. After disabling the comment feature, they came up with a patch addressing the vulnerability.

Was the Hack Dangerous?

What most Etherscan.io users want to know is just how potentially dangerous the 1337 pop-up hack might have been. Surprisingly, the answer to that question varies greatly depending on whom one happens to ask.

For instance, there are those who maintain that the hack did not pose any threat at all. The reason for this viewpoint is simple — the Etherscan.io site does not have a wallet service, so funds were never directly compromised.

Speaking on the attack, Michael Hahn, a programmer for the Ethereum interface MyCrypto.com, explained:

“An XSS attack, in this case, javascript injection, was taking advantage of API that Etherscan uses to grab the latest comments about addresses from the Disqus CMS. It doesn’t appear that Etherscan had been serving malicious code when it was noticed. Disqus comments on Etherscan.io were disabled until a security patch is pushed which will encode the API data to remove the vulnerability to XSS. No user funds were lost.”

However, some information security experts believe that it is more dangerous than what the seemingly harmless comment appears to be. In today’s fast-paced world, information is power and has the potential to influence market movements in the blink of an eye.

Information security expert Jim Manico posted a Twitter message, saying:

“Financial reporting site where any comment can deface the site? That can affect financial markets. For a financial information site like this, it’s a real [vulnerability].”

Security researcher Scott Helme shares a similar viewpoint and told Motherboard:

“They could alter the prices shown on graphs, maybe cause a buy/sell. I’m sure that tampering with the values could impact people.”

Regardless of what could have happened, Etherscan.io users are lucky this time. According to the Etherscan team’s analysis, there were four attempts to inject the JS alert message “1337.” The first attempt “appeared non malicious,” and the team finally blocked the fourth attempt.

Etherscan 1337 Hack Did Not Compromise Crypto Wallets was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Emerald Crypto (EMD) на Currencies.ru

$ 0.0095806 (+7.58%)
Объем 24H $0
Изменеия 24h: 2.35 %, 7d: -7.78 %
Cегодня L: $0.0086651 - H: $0.0095806
Капитализация $183.154k Rank 1690
Цена в час новости $ 0.00980991 (-2.34%)

crypto very etherscan cryptocurrency 1337 did compromise

crypto very → Результатов: 126


SEC Chair’s ‘Very Objectionable’ Approach to Crypto Sees Only ‘A Small Number’ of Cryptocurrencies as Not Securities

Gary Gensler says he’s not “negative or a minimalist about crypto,” rather standards established by Congress which can be changed by them “have a very broad definition of a security.” The post SEC Chair’s ‘Very Objectionable’ Approach to Crypto Sees Only ‘A Small Number’ of Cryptocurrencies as Not Securities first appeared on BitcoinExchangeGuide.

2021-9-15 16:20


Фото:

China Giving Crypto Power Back To The People, Sort Of

Last week, Chinese authorities made their vision on cryptocurrencies very clear, as new movements took hold across the country banning certain aspects of the industry, including the spread of crypto news on social media giants, WeChat, a block on over 100 cryptocurrency exchanges via Chinese internet and even a ban on event venues in Beijing hosting cryptocurrency and blockchain related events and conferences.

2018-8-28 15:00


Фото:

The Daily: Scrap Lipsus Crypto Trading, Luxury Market Reaches $ 100M Transactions

Lorenzo Pellegrino, CEO of Skrill, commented: “The world of cryptocurrency trading is exciting and dynamic, and our digital wallet service very much lends itself to this environment. I’m confident that the ability to trade in cryptocurrencies quickly and easily through Skrill will appeal to consumers both now and in the future. Over 25,000 deals have

2018-7-26 16:02


Фото:

This Expert Believes Bitcoin Will Reach $250,000 In Just Four Years Time

With the current momentum of Bitcoin clear, Bitcoin hitting $250,000. 00 by 2022 isn’t a totally unrealistic prospect. Although in order to reach this point, we do need to see some very significant gains and of course, Bitcoin needs to locate some stability at a number of other benchmarks too, considering that at the time of writing, Bitcoin is valued at just $8,262.

2018-7-26 15:30


Фото:

Bitwise Files With SEC for Cryptocurrency ETF

Bitwise Asset Management is the latest venture to apply for a cryptocurrency exchange-traded fund (ETF). Called the Bitwise HOLD 10 Cryptocurrency Index Fund, the ETF will track the returns of the company’s HOLD 10 Index, a “market-cap-weighted index of the 10 largest cryptocurrencies” that captures roughly 80 percent of the total cryptocurrency market capitalization.

2018-7-25 02:18


Фото:

‘Very Specific Recommendations’ Crypto Deadline Scraped by G20 Forum

Cryptocurrencies will continue to receive a broadly hands-off approach from the G20 until at least October, a meeting of the forum confirmed July 21-22. A summary of interim decisions made by the dedicated Finance Ministers & Central Bank Governors (FATF) group sees any hard-and-fast regulatory steps regarding cryptoassets remain absent. The results follow a four-month

2018-7-23 17:36


Philippines Based LoyalCoin Is Using Cryptocurrency To Create The First Global Loyalty Scheme

Philippines-based LoyalCoin is aiming to create the world’s largest loyalty network where points from thousands of different brands are interchangeable – all thanks to cryptocurrency. Customers will be able to turn reward points from numerous brands into taxi rides, air miles, fast food treats and pretty much anything else they want.

2018-7-23 23:00


Фото:

Governance, Part 2: Plutocracy Is Still Bad

Coin holder voting, both for governance of technical features, and for more extensive use cases like deciding who runs validator nodes and who receives money from development bounty funds, is unfortunately continuing to be popular, and so it seems worthwhile for me to write another post explaining why I (and Vlad Zamfir and others) do not consider it wise for Ethereum (or really, any base-layer blockchain) to start adopting these kinds of mechanisms in a tightly coupled form in any significant way.

2018-7-21 23:03


Introduce your entrance to the Internet: How Investor’s Preferred Crisp Crypto Dizma Take Blockchain.io

The buzz around the Crypto industry brings around a flood of information full of enthusiasm since it advances the conversation on the development of digital economy. However, it seldom helps investors choose among the different features and technicalities that exist on the exchange market. To pinpoint the very reason why Bitcoin seduces so many, we

2018-7-20 21:55


Introducing your Gateway to the Internet of Value: How Blockchain.io takes on investors’ favorite worst Crypto dilemma

It is safe to say now that Bitcoin and the Blockchain technology are here to stay. It is very likely that in the near future we will heavily rely on them to store and exchange value; we are confident that many other applications will come up from this groundbreaking invention. In short, the Crypto revolution […]

2018-7-20 02:30


Фото:

Be aware that there are 5 things one should stay clear of before investing in a new cryptocurrency.

by Gianluca Giancola As the blockchain and crypto space continues to grow and thrive, the industry has become increasingly mainstream and piqued the interest of many first-time investors. As the industry is still very much in its nascent stages, people getting involved with cryptocurrency investing … The post [Guest Post] 5 things to be aware

2018-7-19 23:17