Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
The Almighty Buck Security

Someone Stole $120 Million in Crypto From a DeFi Website (theverge.com) 72

The Verge reports: On Wednesday night, someone drained funds from multiple cryptocurrency wallets connected to the decentralized finance platform BadgerDAO. According to the blockchain security and data analytics Peckshield, which is working with Badger to investigate the heist, the various tokens stolen in the attack are worth about $120 million.

While the investigation is still ongoing, members of the Badger team have told users that they believe the issue came from someone inserting a malicious script in the UI of their website. For any users who interacted with the site when the script was active, it would intercept Web3 transactions and insert a request to transfer the victim's tokens to the attacker's chosen address. Because of the transparent nature of the transactions, we can see what happened once the attackers pounced. PeckShield points out one transfer that yanked 896 Bitcoin into the attacker's coffers, worth more than $50 million.

According to the team, the malicious code appeared as early as November 10th, as the attackers ran it at seemingly random intervals to avoid detection....

One of the things Badger is investigating is how the attacker apparently accessed Cloudflare via an API key that should've been protected by two-factor authentication...

This discussion has been archived. No new comments can be posted.

Someone Stole $120 Million in Crypto From a DeFi Website

Comments Filter:
  • And nothing (Score:5, Insightful)

    by real_nickname ( 6922224 ) on Sunday December 05, 2021 @06:37AM (#62048875)
    of value was lost. This tulip mania is destroying the environment.
    • Re:And nothing (Score:5, Insightful)

      by The Real Dr John ( 716876 ) on Sunday December 05, 2021 @07:44AM (#62048957) Homepage

      Bitcoin has real value only because people have been convinced it does. If rich people started talking up dog shit, there would be a rush on that, until people figured out it was just shit.

      • Yes, so stop being jealous and start slinging fresh and natural dog chips, it’s the American dream.
      • The same reason gold has value.

        For the last 7000 years.

        • Don't forget dubious financial derivatives, junk mortgage-backed securities and NFTs. All pretty much worthless unless you convince enough people they are the cat's meow.

        • by gweihir ( 88907 )

          The same reason gold has value.

          For the last 7000 years.

          Nope. Gold has about half of its market value in actual industrial application value these days. That means it will not fall below that price. Even at its current price, it is used industrially, but it would be used a lot more if it was cheaper.

          • The same reason gold has value.

            For the last 7000 years.

            Nope. Gold has about half of its market value in actual industrial application value these days. That means it will not fall below that price. Even at its current price, it is used industrially, but it would be used a lot more if it was cheaper.

            And that's true for... how much of human history? 50 years perhaps? 100? Before that its only real use was jewelry, use in which it could be perfectly replaced by tombak, except, you know... tombak isn't gold.

            • So you can make jewelry out of gold. Can't make anything out of bitcoin.

              • And what exactly is the difference? That means the intrinsic value of gold is the same as that of tombak. Yes, it won't crash down to exactly zero, but if it were to crash down to its intrinsic value, then the few cents of value it'd retain would make exactly zero difference in how screwed we would be. And yet, somehow it didn't happen. Imagine that.
              • I can make an NFT out of Bitcoin.

      • Bitcoin mainly has value because it is used for money laundering by drug lords.
    • by waspleg ( 316038 )

      At least with tulips you could plant them.

    • by Kaenneth ( 82978 )

      You do realize the Tulip Bulb thing is mostly a myth right? it wasn't that big of a deal.

      https://www.barrons.com/articl... [barrons.com]

      If that's your best argument against it, Crypto is pretty safe.

    • This tulip mania is destroying the environment.

      To be fair, this tulip mania is adding a small bit to the top of the energy usage that is destroying the environment.

      My sitting here being pedantic with a tablet is doing the same.

  • by Computershack ( 1143409 ) on Sunday December 05, 2021 @06:43AM (#62048881)

    Because of the transparent nature of the transactions, we can see what happened once the attackers pounced.

    Which is all well and good but it goes to an anonymous wallet, you can't see who owns it and given some exchanges being quite happy to have low to non-existent ID verification you've no way to track ultimately where it ended up in fiat currency. It always makes me laugh when people bang on about the security of crypto because it is almost childs play to steal and because the exchanges are unregulated there's no comeback or method of recourse for the victim if the company/institution involved chooses to do nothing.

    • by burtosis ( 1124179 ) on Sunday December 05, 2021 @09:10AM (#62049087)
      It’s more than not keeping track, there are exchanges that bundle fairly large batches of transactions together then fragment and scramble everything so that it’s not possible to determine exactly where the money went, even with a public ledger. Money laundering is the main feature, not a bug.
      • It’s more than not keeping track, there are exchanges that bundle fairly large batches of transactions together then fragment and scramble everything so that it’s not possible to determine exactly where the money went, even with a public ledger. Money laundering is the main feature, not a bug.

        No, privacy is the main feature. Yes, like ALL forms of privacy, it enables crime, which is always the excuse of any totalitarian governemtn who wants to take away the privacy. Well, this time you won't take it away from us.

      • Comment removed based on user account deletion
    • Because of the transparent nature of the transactions, we can see what happened once the attackers pounced.

      Which is all well and good but it goes to an anonymous wallet, you can't see who owns it and given some exchanges being quite happy to have low to non-existent ID verification you've no way to track ultimately where it ended up in fiat currency. It always makes me laugh when people bang on about the security of crypto because it is almost childs play to steal and because the exchanges are unregulated there's no comeback or method of recourse for the victim if the company/institution involved chooses to do nothing.

      Uhhh, and yet whenever someone brings up that crypto enables anonymous transactions, immediately detractors appear to yell it's only pseudonymous not aonymous, and it's trivial to track transaction history, and deanonymize accounts at the moment they get changed into currecny. So, which one is it? You can't have it both ways.

    • Comment removed based on user account deletion
  • ... huge heist was something of the past?

  • by etash ( 1907284 ) on Sunday December 05, 2021 @07:06AM (#62048903)
    obscure "entrepreneurs" and crypto "visionaries" develop a product that will change the world...with "smart contracts". They also introduce some not so easily detected before the fact bug and one day .. voila.. a "hacker" exploits it. millions that people .. sorry I mean to say gullible idiots invested are lost.

    It's not the first time it happens and definitely not the last.
    • Nothing was lost. The assets were just repurposed.
    • Actually the contract looks airtight. PolyDEX was flawed from its inception, for example. BadgerDAO's mistake was using an insecure website as an interface for the smart contract.

  • by lessthan0 ( 176618 ) on Sunday December 05, 2021 @10:59AM (#62049277)

    You want DeFi tokens so "the man" can't track you or tax you. Instead, you put your trust into anonymous programmers and miners that only have their own interests in mind. There are no legal protections, no recourse, and no undo. The entire space is filled with theft, cons, scams, pump and dumps, and rug pulls. RugPullCoin will be my next project and I expect a lot of takers, haha. Call badger customer service.

  • by rsilvergun ( 571051 ) on Sunday December 05, 2021 @11:16AM (#62049309)
    There's a multi-million dollar heist two or three times a month. It was revealed that Tether, which is the coin the entire exchange system runs off of, is it giant scam where despite claiming a one-to-one ratio of dollars to coin it's more like 20 or 30%. And the price of Bitcoin just dropped 16% for no discernible reason.

    These are the sort of things and a sort of constant scandals that should undermine investor confidence and lead to either a market collapse or a complete reevaluation in how the market functions. But crypto keeps on keeping on the same way. The reason is nobody really cares when they lose a ton of money and a reason for that is that all the real money in crypto besides a handful of speculators is money laundering.
    • And the price of Bitcoin just dropped 16% for no discernible reason.

      There is always a reason why things happen.
      In this case it was one of the most common reasons for large crashes: a lot of liquidations of greedy, overleveveraged traders in a relatively illiquid market.

      • by Kaenneth ( 82978 )

        still up 160% since this day last year.

        You can't have that kind of gain without volatility.

      • I was speaking metaphorically. My point was that a sudden crash like that shouldn't really happen especially with something that's being called a currency. It's bad enough we let the stock market gamble with our lives we don't need to add a whole new form of gambling we can leave us all broke.
    • Yeah that heist is to annihilate all fiat fake cash. You know bank robberies still happen right?!
    • real investors do due diligence. These are gamblers, and they're taking a lot of the credulous and desperate with them Pinocchio style.

  • by VeryFluffyBunny ( 5037285 ) on Sunday December 05, 2021 @11:28AM (#62049331)
    Meanwhile, the rest of us will have to suffer the effects of more severe climate change/global heating because blockchain mining is sucking electricity out of our systems faster than we can build capacity to replace fossil fuels.
  • You know some people call Pepsi a Coke. No one ever puts faith in 2nd place =(
  • Greed is not a valid substitute for actual skill and insight. This is just another nice demonstration for that.

    Oh, and incidentally, real banks handling real currencies are tightly regulated to prevent crap like this (among other things).

  • I don't want to be told what it was worth in "dollars". That silly fiat currency shouldn't be used for comparison. I need to know what it's worth in Polkadot.

  • It is precisely this level of stability and security that makes cryptocurrencies just so damn appealing.

    Add in the ridiculous levels of energy needed to process each and every transaction and, golly, I really think this could be my favorite product of the 21st century.


    XOXOXO,

    Satan

You know you've landed gear-up when it takes full power to taxi.

Working...