Research Finds Smart Contract Exploits Hardest to Eliminate as FBI Raises Warning

2022-9-1 00:00

In a recent research report, Token Terminal finds that there are three root causes of DeFi exploits, and removing smart contract vulnerabilities is by far the most challenging of the three.

Since interest in decentralized finance has skyrocketed, so have the hacks and rug pulls in the segment with an estimated 105 on-chain exploits resulting in the theft of almost $4.2 billion from various protocols.

Interestingly, the research finds that the biggest hacks, on average, come via cross-chain bridges and central exchange (CEX) wallets, whereas yield aggregators and lending protocols are most frequently abused.

“The largest exploits tend to be across multiple chains or on major ecosystem bridges.”

FBI raises new DeFi warning for investors and platforms

The three largest DeFi exploits to date, Ronin Network ($624 million), Poly Network ($611 million), and Wormhole ($326 million), are all cross-chain bridges that dominate the list of the largest exploits. Bridges typically lost over $188 million in every hack, the report noted.

Recently, the US Federal Bureau of Investigation (FBI) cautioned the investors and platforms about these risks in DeFi in a public service announcement.

“Cyber criminals are increasingly exploiting vulnerabilities in the smart contracts governing DeFi platforms to steal cryptocurrency, causing investors to lose money,” the agency noted. “Cyber criminals seek to take advantage of investors’ increased interest in cryptocurrencies, as well as the complexity of cross-chain functionality and open source nature of DeFi platforms.”

Conversely, yield aggregators and lending protocols are the most frequently targeted systems by attacks, however, they frequently result in smaller financial losses per attack as per Token Terminal. In general, yield aggregators and lending protocols were abused more frequently, while bridges and CEXs typically suffer the biggest losses per exploit. Cross-chain bridges and CEX hot wallets account for $2.2 billion in stolen assets, or over 52% of the total amount compromised.

Safe-keeping of private keys is the simplest rescue plan

The most common causes of these exploits have been roughly categorized into smart contract loopholes, compromised private keys, and protocol frontend spoofing. Notably, loopholes in smart contracts, frequently associated with flash loans and oracle manipulation, reportedly accounted for 73% of all hacks since September 2020. But, automated formal verification and DeFi security audits are the two primary techniques for managing these smart contract risks.

The report also finds that the largest hacks, averaging $91 million each, are caused by compromised private keys, which are often obtained using spear-phishing attempts. Ironically, this attack vector is also the most avoidable by better securing the private keys and using different platforms for storage.

Lastly, frontend spoofing is an attack method that goes against specific users rather than the funds that the protocol controls, like in the case of the BadgerDAO exploit. Typically, this entails using techniques like DNS cache poisoning to replace the real protocol website’s IP address with a phony lookalike.

Meanwhile, exploiters are also reportedly looking for new options now that the standard means of cashing out ill-gotten gains, through Tornado Cash, has been discontinued via sanctions. Be[In]Crypto had reported that following the penalties against Tornado Cash, a small but rising number of decentralized finance (DeFi) projects, including dYdX, Liquidity, GMX, Kwenta, and others, are developing decentralized frontends (DeFe) instead.

With that, the FBI also recommends that DeFi platforms institute real-time analytics, monitoring, and rigorous testing apart from developing an incident response to avoid such exploits.

However, Aztec Network, an Ethereum-based rollup that offers private transactions using zero-knowledge technology, is one possible substitute to Tornado Cash as per the research report.

For Be[In]Crypto’s latest Bitcoin (BTC) analysis, click here.

The post Research Finds Smart Contract Exploits Hardest to Eliminate as FBI Raises Warning appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

SmartCash (SMART) на Currencies.ru

$ 9.67E-5 (+3.20%)
Объем 24H $55
Изменеия 24h: 4.16 %, 7d: 11.51 %
Cегодня L: $9.67E-5 - H: $9.67E-5
Капитализация $136.673k Rank 2190
Цена в час новости $ 0.0032958 (-97.07%)

research contract exploits finds smart warning three

research contract → Результатов: 87


Cardano (ADA) sets price highs ahead of smart contract update

Input-Output Hong Kong (IOHK), a blockchain infrastructure research and engineering company behind the development of the proof-of-stake Cardano (ADA) platform is on track with completing its smart contract mission as the announcement of the hard fork date, which will mark the downing of the new era, boosted the token’s price to its record high of […] The post Cardano (ADA) sets price highs ahead of smart contract update appeared first on CryptoSlate.

2021-8-22 09:08


Фото:

Cardano Is Exploring A New Mechanism That Will Transform Smart Contract Platforms

Cardano is working on a new research project or mechanism to help make transaction fees fair, stable, and more predictable over time, according to a new blog by the network’s parent company IOHK. The blog titled “Stablefees and the Decentralized Reserve System” explains that a good system should have a mechanism for adjusting transaction costs […]

2021-6-12 23:53


Фото:

SatoshiPay receives grant from Stellar to develop layer-2 Pendulum blockchain

SatoshiPay, a blockchain-powered payment solution built on Stellar, announced that it has received a research and development grant from the Stellar Development Foundation to start the development of the Pendulum network — a new second-layer blockchain that connects Stellar to the wider DeFi ecosystem by adding smart contract support and bridges to Ethereum and Polkadot.

2021-6-8 04:05


Cartesi Partners With IMPA to Open “Smart Contract Laboratory”

Research and development on both existing and future products will be carried out by PhDs at the world-renowned mathematics research institute With the applications of blockchain technology reaching further than many of us could have ever imagined, the benefits of implementing decentralized systems are now becoming too evident to ignore for the global economy. Payments […]

2021-4-22 21:16


SIMBA Chain receives $1.5M contract from the U.S. Office of Naval Research

Today, it was announced that the  U. S. Office of Navy Research has awarded a $1. 5 million Small Business Innovation Research (SBIR) Phase II contract (N68335-21-C-0178) to SIMBA Chain to design and build a blockchain solution to enable demand sensing for the Defense Logistics Agency, the combat support and supply chain agency of the United States Department […] CryptoNinjas » SIMBA Chain receives $1.

2021-1-13 19:14


Фото:

Altcoin Explorer: Cardano (ADA), the Academic and Scientific Research Driven Smart Contract Platform

Cardano (ADA) is a third-generation smart contract protocol that aims to do away with the current bottlenecks hindering the wider adoption of a blockchain-driven economy. Keeping scalability, interoperability, and sustainability at its ideological core, Cardano has cemented itself among the leading distributed ledger technology (DLT) projects today.

2020-8-4 23:00


Binance’s Latest Research Says The Failing Cryptocurrency Market is All Bakkt’s Fault

CEO of Bakkt believes that the launch of the futures contract was meant to be a “milestone for the industry.” Bitcoin dropped down to the $8,000 price level during the month of September. The cryptocurrency industry isn’t doing well for the month of September, and everyone wants to know why. Binance Research has been investigating […]

2019-10-1 17:19


Zilliqa live with first smart contract platform built on sharding

Zilliqa, the blockchain based on research from a team of computer scientists at the National University of Singapore, today announced the launch of smart contracts on the Zilliqa platform. Amrit Kumar, Zilliqa President said, “Long awaited by many members of our community, today signifies a pivotal step forward in realizing innovations on existing blockchain infrastructures […]

2019-6-10 13:07


Smart contract creation in 2019 better than 2018 levels despite bear market, claims Diar report

The cryptocurrency market saw an overhaul in terms of transaction numbers and developments and this fact has been covered by multiple research portals. In the latest Diar report, Diar analyzed everything from DApp development and Bitcoin’s [BTC] performance to the all-important spectrum of smart contracts and its benefits.

2019-5-8 19:30


Binance Shows Augur (REP) Has a Contract Design Flaw Attack on its Prediction Markets

The Ethereum-based prediction market Augur (REP) seems to be facing a design flaw attack. The information was released by Binance Research in a blog post on April 1st. According to Binance Research, there is a malicious market creator that may design a market to exploit a purposeful flaw. Binance Research Unveils Design Flaw Attack on […]

2019-4-1 23:09


EOS превзошел биткоин по объему транзакций

По данным аналитического ресурса Coinmetrics, криптовалюта EOS стала абсолютным лидером по объему транзакций. The Top 5 Coins by Onchain Transaction Count (1/14):1. EOS2. TRX3. ETH4. XRP5. BTC Note: Smart contract platforms emphasize more transactions while store of value cryptocurrencies deemphasize.

2019-1-14 20:07