CrypLogger.com
  • Home
  • Exclusive
  • Learn About Coins
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions
  • Current Prices
No Result
View All Result
  • Home
  • Exclusive
  • Learn About Coins
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions
  • Current Prices
No Result
View All Result
CrypLogger
No Result
View All Result
Home News

DeFi project BadgerDAO team reveals $ 121 million hack details

by Vaibhav
December 11, 2021
in News
0
Hackers withdrew more than $ 150 million from the hot wallets of the BitMart bitcoin exchange
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Team DeFi-protocol BadgerDAO revealed the details of a recent hack and reported that during the attack, the hackers used the Cloudflare Workers service, which allows them to deploy scripts on the company’s cloud network.

2 /

We believe that all remediation decisions should be made as a community with strong consideration for the long term health of the DAO and victims of this incident.

You can review a detailed technical post mortem of the incident below.

👉https://t.co/jjwDSeRwWC

– ₿adgerDAO 🦡 (@BadgerDAO) December 10, 2021

The developers paid attention to messagewhich appeared on the Cloudflare forum at the end of September. One participant noticed that unauthorized users can register accounts and create and view API– tokens that cannot be deleted or deactivated until the completion of the email verification.

See also  CFTC Technical Committee Meets In Washington To Discuss DeFi, Here's What Was Discussed

Related articles

The Central Bank of Kazakhstan reported on the completion of the second phase…

The Central Bank of Kazakhstan reported on the completion of the second phase…

March 30, 2023
Daily: Top promising cryptocurrencies to buy in 2023

Daily: Top promising cryptocurrencies to buy in 2023

March 30, 2023

After completing these steps, an attacker can wait for the account to be verified and completed, thus gaining access to the API.

After the incident, the BadgerDAO team analyzed the Cloudflare logs and found traces of unauthorized account registration and key generation for three APIs.

In mid-September, developers “unknowingly completed account registration” for one of the compromised interfaces, which was “used for legitimate Cloudflare management activities.”

“The user interface does not make it clear that the account has already been created, so a key was generated for the API. On November 10, an attacker used API access to inject malicious scripts through Cloudflare Workers into the html file of the app.badger.com website, ”the developers wrote.

The hacker has stolen assets worth more than $ 130 million, but about $ 9 million can be returned, since they have not yet been removed from the protocol vaults. Thus, the damage exceeded $ 121 million.

See also  Cryptocard from Binance for Ukraine
Assets stolen by a hacker. Data: BadgerDAO…

The project team reported that it has already closed the exploit that made the attack possible, updated the password for the Cloudflare account, and removed or updated API keys.

Since the identity of the hacker has not yet been identified, BadgerDAO brought in Mandiant and Chainalysis to investigate the incident. The developers added that they are cooperating with law enforcement agencies in the United States and Canada.

In conversation with Bloomberg a Cloudflare spokesman stressed that the company’s systems “were not hacked,” and there are no vulnerabilities in the Workers service.

“Last week we learned about the BadgerDAO incident. We contacted the project team and provided active assistance in the investigation, ”he said.

As a reminder, in September, unknown persons obtained unauthorized access to Bitcoin.org and posted a fraudulent announcement on the distribution of cryptocurrency on its main page. Site operator Cobra suggested that the issue could be related to Cloudflare’s services.

See also  Block will provide liquidity to the Lightning Network with its own...

Subscribe to Cryplogger news on Telegram: Cryplogger Feed – the entire news feed, Cryplogger – the most important news, infographics and opinions.

Found a mistake in the text? Select it and press CTRL + ENTER

Share76Tweet47

Related Posts

The Central Bank of Kazakhstan reported on the completion of the second phase…

The Central Bank of Kazakhstan reported on the completion of the second phase…

by Vaibhav
March 30, 2023
0

The NBK announced the completion of the second stage of the digital tenge pilot projectThe regulator noted good results and...

Daily: Top promising cryptocurrencies to buy in 2023

Daily: Top promising cryptocurrencies to buy in 2023

by Vaibhav
March 30, 2023
0

The most important news of the day is already hereIn this digest:Donald Trump unveiled his own NFT collectionOpera browser will...

WhiteBIT and Viber unite online fans at the biggest soccer…

WhiteBIT and Viber unite online fans at the biggest soccer…

by Vaibhav
March 30, 2023
0

Rakuten Viber, in partnership with the Ukrainian cryptocurrency exchange WhiteBIT, attracted football fans from all over the world to participate...

Weekly: SBF arrested in the Bahamas |  Trump’s NFT Collection |  Do Kwon in…

Weekly: SBF arrested in the Bahamas | Trump’s NFT Collection | Do Kwon in…

by Vaibhav
March 30, 2023
0

Here is the traditional 122 crypto news digest per week, from which you will learn why cryptocurrencies “should not exist”...

Democrats to return millions received from SBF

Democrats to return millions received from SBF

by Vaibhav
March 30, 2023
0

This decision was made by 3 partiesU.S. Attorney's Office Starts Investigating Crypto Fraudster's Connections with PoliticiansThree committees of the US...

Load More

Recent News

  • The Central Bank of Kazakhstan reported on the completion of the second phase…
  • Daily: Top promising cryptocurrencies to buy in 2023
  • WhiteBIT and Viber unite online fans at the biggest soccer…
  • Weekly: SBF arrested in the Bahamas | Trump’s NFT Collection | Do Kwon in…
  • Democrats to return millions received from SBF
  • OKX has been idle for over 9 hours
  • Bitvavo Exchange Announces Liquidity Problems with DCG
  • OCC’s new fintech office has a director and opening date
  • Sam Bankman-Fried plans to withdraw from the fight against…
  • Solidus Labs: 350 scam tokens are created daily on the network
  • UK government announces ‘tight’ cryptocurrency regulation as part of economic crime plan
  • Jefferies Forecast: FTX Lenders to Return Up to 40% of Funds
  • Nigeria plans to legalize cryptocurrencies
  • Argentina’s fan token collapsed after the country’s victory at the 2022 World Cup
  • Boerse Stuttgart Digital Subsidiary Receives Final Permission to Hold Cryptocurrency
  • CoinGecko: the number of “dead” coins increased by 2.5 times
  • SEC Commissioner: “Howey’s test is not applicable to cryptocurrencies”
  • Economic calendar December 19-23: Christmas break and…
  • Insurance companies refuse to work with firms associated with FTX
  • Japan Plans to Form Expert Group to Study Digital Yen: Report

Follow Us On Twitter

  • Home
  • About Us
  • CCPA
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms of Use
Email: contact@cryplogger.com

© 2021-23 Cryplogger.com
CrypLogger is a cult magazine about bitcoin, blockchain technology and the digital economy. Every day we supply news and analytics on the cryptocurrency market since 2021.

No Result
View All Result
  • Home
  • Artificial Intelligence
  • Forecasts
  • News
  • Opinions

© 2021-23 Cryplogger.com
CrypLogger is a cult magazine about bitcoin, blockchain technology and the digital economy. Every day we supply news and analytics on the cryptocurrency market since 2021.

Go to mobile version