<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Casper_Network_Uref_Bypass_Wallet_Draining</id>
	<title>Casper Network Uref Bypass Wallet Draining - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Casper_Network_Uref_Bypass_Wallet_Draining"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Casper_Network_Uref_Bypass_Wallet_Draining&amp;action=history"/>
	<updated>2026-05-30T06:42:36Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Casper_Network_Uref_Bypass_Wallet_Draining&amp;diff=6269&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caspernetworkurefbypasswalletdraining.php}} {{Unattributed Sources}}  Casper Network Logo/HomepageCasper Network is a proof of stake network with finality and limited numbers of validators. Late on July 25th, a vulnerability started to be exploited which allowed a total of 13 wallets to be drained. The team behind Casper Network was ultimately able to blo...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Casper_Network_Uref_Bypass_Wallet_Draining&amp;diff=6269&amp;oldid=prev"/>
		<updated>2024-10-25T19:56:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caspernetworkurefbypasswalletdraining.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Caspernetwork.jpg&quot; title=&quot;File:Caspernetwork.jpg&quot;&gt;thumb|Casper Network Logo/Homepage&lt;/a&gt;Casper Network is a proof of stake network with finality and limited numbers of validators. Late on July 25th, a vulnerability started to be exploited which allowed a total of 13 wallets to be drained. The team behind Casper Network was ultimately able to blo...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caspernetworkurefbypasswalletdraining.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Caspernetwork.jpg|thumb|Casper Network Logo/Homepage]]Casper Network is a proof of stake network with finality and limited numbers of validators. Late on July 25th, a vulnerability started to be exploited which allowed a total of 13 wallets to be drained. The team behind Casper Network was ultimately able to block finality on their network and perform an upgrade to resolve the original issue. However, it is unclear what is being done to compensate users who were affected by the exploit.&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14855&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetwork-14963&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetwork-14964&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetwork-14965&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworkdocs-14966&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14967&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14968&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14969&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14970&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14971&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14972&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14973&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;caspernetworktwitter-14974&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;youtube-14975&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cointelegraph-14976&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinpedia-14977&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;happycoin-14978&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Casper Network ==&lt;br /&gt;
&amp;quot;Instant Finality public blockchain Casper offers instant finality, while keeping transaction costs low, and being easy to build on.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Casper is a new Turing-complete smart-contracting platform, backed by a Proof-of-Stake (PoS) consensus algorithm and WebAssembly (Wasm). The network is a permissionless, decentralized, public blockchain.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The Casper Network was built based on the energy-efficient, proof-of-stake CBC Casper specifications, providing the scale, industry-leading security, and predictable cost-effective gas model to deliver the new standard for AI Governance.&lt;br /&gt;
&lt;br /&gt;
Casper Labs has been chosen by IBM for a groundbreaking solution aimed at enhancing the transparency and auditability of AI systems. The solution combines IBM’s watsonx.ai and leverages the Casper Network for managing, monitoring, and sharing AI data.&lt;br /&gt;
&lt;br /&gt;
Casper is the ideal platform for managing AI data. It provides certified, tamper-proof, transparent, secure, and auditable data, building trust in generative AI.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;On July 26, 2024, Casper Network was attacked.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Casper Network Uref Bypass Wallet Draining&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|July 25th, 2024 11:00:00 PM MDT&lt;br /&gt;
|Team Aware Of Vulnerability&lt;br /&gt;
|The time at which the Casper Network team reportedly became aware of the vulnerability issue on the Casper Network. TBD - When actual vulnerability happened.&lt;br /&gt;
|-&lt;br /&gt;
|July 26th, 2024 4:54:00 AM MDT&lt;br /&gt;
|Security Video Posted&lt;br /&gt;
|A video is posted which features Matthew Doty, a Research Fellow at the Casper Association, discussing 'Building Secure Blockchain Solutions at Casper'.&lt;br /&gt;
|-&lt;br /&gt;
|July 26th, 2024 7:00:00 AM MDT&lt;br /&gt;
|Root Cause Determined&lt;br /&gt;
|The Casper Network identifies the root cause of the exploit on their network.&lt;br /&gt;
|-&lt;br /&gt;
|July 27th, 2024 1:50:00 AM MDT&lt;br /&gt;
|Casper Network Concensus Halt&lt;br /&gt;
|The Casper Network consensus mechanism is halted to prevent potential damage to additional accounts.&lt;br /&gt;
|-&lt;br /&gt;
|July 27th, 2024 4:31:00 AM MDT&lt;br /&gt;
|Casper Network Announcement&lt;br /&gt;
|The Casper Network tweets to announce that they have&lt;br /&gt;
|-&lt;br /&gt;
|July 27th, 2024 11:33:00 AM MDT&lt;br /&gt;
|Minor Situation Update&lt;br /&gt;
|The Casper Network tweets to notify their community that they continue to work on a resolution of the issue.&lt;br /&gt;
|-&lt;br /&gt;
|July 28th, 2024 8:28:00 AM MDT&lt;br /&gt;
|Minor Situation Update&lt;br /&gt;
|The Casper Network again tweets to notify their community that they continue to work on a resolution of the issue.&lt;br /&gt;
|-&lt;br /&gt;
|July 28th, 2024 11:30:00 AM MDT&lt;br /&gt;
|Situation Limited To Wallets&lt;br /&gt;
|&amp;quot;At this point, on 28 July 2024 at 17:30 UTC, the Casper Association is confident that the extent of the security breach is limited to under 15 accounts. All unauthorized transfers have been traced by Casper and related parties.  &amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|July 29th, 2024 3:18:00 AM MDT&lt;br /&gt;
|Security Breach Tweet Posted&lt;br /&gt;
|&amp;quot;On July 26, 2024, a security breach on the Casper blockchain was detected. Casper Team/Community performed immediate actions including halting consensus and developing a patch.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|July 29th, 2024 4:39:00 PM MDT&lt;br /&gt;
|Significant Progress Report&lt;br /&gt;
|The Casper Network team reports that they have been working diligently and making significant progress on resolving the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 3:18:00 AM MDT&lt;br /&gt;
|Event Rescheduled&lt;br /&gt;
|A tweet notes that a developer event has been rescheduled, likely due to the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 11:12:00 AM MDT&lt;br /&gt;
|Casper Network Update&lt;br /&gt;
|Casper Network provides an update&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 4:10:00 PM MDT&lt;br /&gt;
|Casper Network Update&lt;br /&gt;
|&amp;quot;Casper Validators are meeting on Wednesday 31 July 2024 at 1400 UTC. In that meeting details of the upgrade will be provided. Once the validators accept the upgrade, they will then immediately resume consensus and minting of blocks&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;Casper Network discovered that malicious actors exploited a vulnerability that allowed a contract installer to bypass access rights checks on urefs, enabling them to grant the contract access to uref-based resources. This privilege escalation facilitated unauthorized access, including the ability to transfer tokens.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;According to the preliminary report released by Casper Network on July 31, 13 wallets were affected in this incident. The total amount of illicit transactions is estimated to be around $6.7 million.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $6,700,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Following the attack, Casper Network tweeted that they had worked with validators to pause the network in order to minimize the impact of the security vulnerability until it could be patched.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Following the analysis on Friday 26 July 2024, the Casper team and partners involved started to develop a patch for the problem. It was established at that time that a limited number of accounts had been targeted to obtain CSPR without proper authorization from the owners of those accounts.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;In the early morning hours (CET) on Saturday 27 July 2024 it became clear that tracing and recovering those misappropriated funds may become difficult without immediately preventing further dispersion.&lt;br /&gt;
&lt;br /&gt;
A subset of validators joined in coordination to halt the consensus and block production to enable a patch to be thoroughly tested before staging an update to the Casper blockchain. Consensus was halted on 27 July 2024 at 07:50 UTC.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
&amp;quot;The Casper Association and parties affected by this incident will conduct a thorough investigation, including working with proper authorities to recover any funds which may have been transferred without proper authorization.&amp;quot;&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14855&amp;quot;&amp;gt;[https://web.archive.org/web/20240808214412/https://hacked.slowmist.io/ SlowMist Hacked - SlowMist Zone] (Accessed Aug 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetwork-14963&amp;quot;&amp;gt;[https://casper.network/en-us/news/casper-blockchain-security-update-preliminary-incident-report Casper Network] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetwork-14964&amp;quot;&amp;gt;[https://casper.network/en-us/news/casper-blockchain-security-update-incident-contained-and-recovery-efforts-underway Casper Network] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetwork-14965&amp;quot;&amp;gt;[https://casper.network/en-us/ Casper Network] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworkdocs-14966&amp;quot;&amp;gt;[https://docs.casper.network/ What is Casper? | Casper] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14967&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1818408819971481796 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14968&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1818333832556269663 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14969&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1817852127487689114 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14970&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1818053646334181880 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14971&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1818214503382663288 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14972&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1817567910275014748 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14973&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1817252082560258372 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;caspernetworktwitter-14974&amp;quot;&amp;gt;[https://twitter.com/Casper_Network/status/1816789158456623454 @Casper_Network Twitter] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;youtube-14975&amp;quot;&amp;gt;[https://www.youtube.com/watch?v=hJwveewPv3w - YouTube] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cointelegraph-14976&amp;quot;&amp;gt;[https://cointelegraph.com/news/casper-network-halts-operations-security-breach https://cointelegraph.com/news/casper-network-halts-operations-security-breach] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinpedia-14977&amp;quot;&amp;gt;[https://coinpedia.org/news/alert-casper-network-became-victim-to-a-crypto-hack/ Alert : Casper Network Became Victim to a Crypto Hack!] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;happycoin-14978&amp;quot;&amp;gt;[https://happycoin.club/en/kriptovalyuta-casper-podeshevela-na-14-posle-ataki-na-blokchejn/ Due to blockchain hacking, the Casper cryptocurrency rate collapsed by 14%] (Accessed Aug 16, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>