Research Finds Smart Contract Exploits Hardest to Eliminate as FBI Raises Warning

2022-9-1 00:00

In a recent research report, Token Terminal finds that there are three root causes of DeFi exploits, and removing smart contract vulnerabilities is by far the most challenging of the three.

Since interest in decentralized finance has skyrocketed, so have the hacks and rug pulls in the segment with an estimated 105 on-chain exploits resulting in the theft of almost $4.2 billion from various protocols.

Interestingly, the research finds that the biggest hacks, on average, come via cross-chain bridges and central exchange (CEX) wallets, whereas yield aggregators and lending protocols are most frequently abused.

“The largest exploits tend to be across multiple chains or on major ecosystem bridges.”

FBI raises new DeFi warning for investors and platforms

The three largest DeFi exploits to date, Ronin Network ($624 million), Poly Network ($611 million), and Wormhole ($326 million), are all cross-chain bridges that dominate the list of the largest exploits. Bridges typically lost over $188 million in every hack, the report noted.

Recently, the US Federal Bureau of Investigation (FBI) cautioned the investors and platforms about these risks in DeFi in a public service announcement.

“Cyber criminals are increasingly exploiting vulnerabilities in the smart contracts governing DeFi platforms to steal cryptocurrency, causing investors to lose money,” the agency noted. “Cyber criminals seek to take advantage of investors’ increased interest in cryptocurrencies, as well as the complexity of cross-chain functionality and open source nature of DeFi platforms.”

Conversely, yield aggregators and lending protocols are the most frequently targeted systems by attacks, however, they frequently result in smaller financial losses per attack as per Token Terminal. In general, yield aggregators and lending protocols were abused more frequently, while bridges and CEXs typically suffer the biggest losses per exploit. Cross-chain bridges and CEX hot wallets account for $2.2 billion in stolen assets, or over 52% of the total amount compromised.

Safe-keeping of private keys is the simplest rescue plan

The most common causes of these exploits have been roughly categorized into smart contract loopholes, compromised private keys, and protocol frontend spoofing. Notably, loopholes in smart contracts, frequently associated with flash loans and oracle manipulation, reportedly accounted for 73% of all hacks since September 2020. But, automated formal verification and DeFi security audits are the two primary techniques for managing these smart contract risks.

The report also finds that the largest hacks, averaging $91 million each, are caused by compromised private keys, which are often obtained using spear-phishing attempts. Ironically, this attack vector is also the most avoidable by better securing the private keys and using different platforms for storage.

Lastly, frontend spoofing is an attack method that goes against specific users rather than the funds that the protocol controls, like in the case of the BadgerDAO exploit. Typically, this entails using techniques like DNS cache poisoning to replace the real protocol website’s IP address with a phony lookalike.

Meanwhile, exploiters are also reportedly looking for new options now that the standard means of cashing out ill-gotten gains, through Tornado Cash, has been discontinued via sanctions. Be[In]Crypto had reported that following the penalties against Tornado Cash, a small but rising number of decentralized finance (DeFi) projects, including dYdX, Liquidity, GMX, Kwenta, and others, are developing decentralized frontends (DeFe) instead.

With that, the FBI also recommends that DeFi platforms institute real-time analytics, monitoring, and rigorous testing apart from developing an incident response to avoid such exploits.

However, Aztec Network, an Ethereum-based rollup that offers private transactions using zero-knowledge technology, is one possible substitute to Tornado Cash as per the research report.

For Be[In]Crypto’s latest Bitcoin (BTC) analysis, click here.

The post Research Finds Smart Contract Exploits Hardest to Eliminate as FBI Raises Warning appeared first on BeInCrypto.

origin »

Bitcoin price in Telegram @btc_price_every_hour

SmartCash (SMART) на Currencies.ru

$ 3.15E-5 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 66.15 %
Cегодня L: $3.15E-5 - H: $3.15E-5
Капитализация $44.595k Rank 3257
Цена в час новости $ 0.0032958 (-99.04%)

research contract exploits finds smart warning three

research contract → Результатов: 87


Zilliqa live with first smart contract platform built on sharding

Zilliqa, the blockchain based on research from a team of computer scientists at the National University of Singapore, today announced the launch of smart contracts on the Zilliqa platform. Amrit Kumar, Zilliqa President said, “Long awaited by many members of our community, today signifies a pivotal step forward in realizing innovations on existing blockchain infrastructures […]

2019-6-10 13:07


Smart contract creation in 2019 better than 2018 levels despite bear market, claims Diar report

The cryptocurrency market saw an overhaul in terms of transaction numbers and developments and this fact has been covered by multiple research portals. In the latest Diar report, Diar analyzed everything from DApp development and Bitcoin’s [BTC] performance to the all-important spectrum of smart contracts and its benefits.

2019-5-8 19:30


Binance Shows Augur (REP) Has a Contract Design Flaw Attack on its Prediction Markets

The Ethereum-based prediction market Augur (REP) seems to be facing a design flaw attack. The information was released by Binance Research in a blog post on April 1st. According to Binance Research, there is a malicious market creator that may design a market to exploit a purposeful flaw. Binance Research Unveils Design Flaw Attack on […]

2019-4-1 23:09


EOS превзошел биткоин по объему транзакций

По данным аналитического ресурса Coinmetrics, криптовалюта EOS стала абсолютным лидером по объему транзакций. The Top 5 Coins by Onchain Transaction Count (1/14):1. EOS2. TRX3. ETH4. XRP5. BTC Note: Smart contract platforms emphasize more transactions while store of value cryptocurrencies deemphasize.

2019-1-14 20:07


EOS значительно превосходит биткоин, Ethereum и Tron по объему транзакций

По данным аналитического ресурса Coinmetrics, криптовалюта EOS стала абсолютным лидером по объему транзакций. The Top 5 Coins by Onchain Transaction Count (1/14): 1. EOS 2. TRX 3. ETH 4. XRP 5. BTC Note: Smart contract platforms emphasize more transactions while store of value cryptocurrencies deemphasize.

2019-1-14 19:44


CryptoProfile ICO

CP believes in the importance of credible ICO projects. All ICO Projects will be check and research thoroughly before we accept them as our client. We offer our clients 100% return of all profits through marketing and also a 6-month return on the original value of tokens invested through a smart contract (T&Cs apply).

2019-1-4 02:03


Фото:

Simplicity Language to Give Bitcoin Ethereum-Like Smart Contract Capabilities

Simplicity, a combinator-based, typed, and functional language for blockchain applications can reportedly enable Bitcoin’s Script language to handle more complex yet reliable smart contracts. Bitcoin Script Language is Limited, For Now According to a new research from Blockstream on Simplicity – a blockchain applications language – distributed ledgers pose a range of unique challenges, which make traditional programming languages unfit.

2018-11-30 21:00


Blockchain Business in Crypto Valley Has Doubled Since Last Year: Report

The number of blockchain-related companies in Switzerland and Liechtenstein has doubled in the last year, according to a new study published by CV VC. The Zug-based firm, in partnership with Strategy& (PwC’s global consulting arm) and inacta, compiled information about the top 50 blockchain and digital asset companies between the two countries.

2018-10-11 00:18


Фото:

DevCon 4 Will Set the Stage for Ethereum’s Next Milestone: Constantinople

Ethereum is embracing the Constantinople milestone at the end of November 2018, after DevCon4 in Prague. Constantinople is the latest Ethereum release, introduced through a hard fork, that will include five Ethereum Improvement Proposals (EIPs):Bitwise shifting instructions (EIP 145) in the Ethereum Virtual Machine (EVM) allow for direct manipulation of bytes on the EVM layer.

2018-9-11 18:15


Фото:

Promoted: The Future of Online Shopping Is Powered by Spl.yt — A Decentralized E-Commerce Protocol

As a rapidly growing business sector, e-commerce continues to open up new avenues for exploring, comparing and purchasing products worldwide. Spl. yt, a smart contract protocol, aims improve the e-commerce system for buyers and sellers by automating functions currently performed by “middlemen” marketplaces like Amazon, eBay and Alibaba.

2018-7-16 19:45