All public logs
Jump to navigation
Jump to search
Combined display of all available logs of Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 11:24, 25 January 2023 Azoundria talk contribs created page KeepKey Wallet Side Channels (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/keepkeywalletsidechannels.php}} thumb|KeepKeyEarly versions of the KeepKey hardware wallet firmware were vulnerable to side channel extraction of the PIN information. Basically, different pins present a different voltage profile when performing verification, and sophisticated attackers with physical access to the device could use that to determine the set pin. The firmware was...")
- 11:24, 25 January 2023 Azoundria talk contribs created page Bitcoin Backed tBTC Stuck (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/bitcoinbackedtbtcstuck.php}} thumb|TBTCTBTC was intended to be an ethereum token matching the price of BTC. Unlike the primary wBTC (wrapped bitcoin) competitor, there was intended to be no central redemption party, and instead the system would operate in a decentralized manner with extra ethereum used as collateral. Unfortunately the first version of the protocol had an issue wi...")
- 11:24, 25 January 2023 Azoundria talk contribs created page File:Tbtc.jpg
- 11:24, 25 January 2023 Azoundria talk contribs uploaded File:Tbtc.jpg
- 11:24, 25 January 2023 Azoundria talk contribs created page Coinbase/AT&T Account Sim Swap signalme (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbaseat&taccountsimswapsignalme.php}} thumb|CoinbaseReddit user signalme was a customer of both Coinbase and AT&T. They used SMS-based two-factor authentication to secure their Coinbase account, and had a bank account with $3,500 hooked up to their account. Their AT&T account was secured with the highest level of security available at the time, which is a note that require...")
- 11:23, 25 January 2023 Azoundria talk contribs created page Ledger Shopify Data Breach 1 (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgershopifydatabreach1.php}} thumb|LedgerShopify assisted Ledger in processing orders for hardware wallets. Ledger's Shopify records were reportedly breached in two incidents on April 18th, 2020 and again on June 16th, 2020. A total of 20,000 records were reportedly breached, with contact information of customers who had ordered Ledger products. The information was sold on th...")
- 11:23, 25 January 2023 Azoundria talk contribs created page Loopring Design Defect (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/loopringdesigndefect.php}} thumb|LoopringLoopring is a decentralized trading platform. The Loopring protocol involves keys to manage transactions. These keys were based on password input provided by the user, which often had a low entropy and was poorly protected. As a result, it was possible for an attacker to interfere with ongoing trades or create unintended trades. The...")
- 11:23, 25 January 2023 Azoundria talk contribs created page File:Loopring.jpg
- 11:23, 25 January 2023 Azoundria talk contribs uploaded File:Loopring.jpg
- 11:22, 25 January 2023 Azoundria talk contribs created page MetaMask Malicious Chrome Extensions (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/metamaskmaliciouschromeextensions.php}} thumb|MetaMaskMultiple malicious Chrome extensions attempting to impersonate the MetaMask wallet were found on the Google Play, and hundreds of users had downloaded them. The extensions, if used, would attempt to steal the 24 word seed phrase of new cryptocurrency users by tricking them into providing it. There is no report of any funds...")
- 11:22, 25 January 2023 Azoundria talk contribs created page Uniswap ERC777 Reentrancy Attack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/uniswapattack.php}} thumb|UniswapSignificant funds were stored within a hot wallet/smart contract. In this exploit, one contract is run within another, enabling balances to be reduced before they are checked. This exploit was known since July of 2019, and never patched or investigated until finally being exploited. The country for this case study is not yet known. == About U...")
- 11:21, 25 January 2023 Azoundria talk contribs created page File:Uniswap.jpg
- 11:21, 25 January 2023 Azoundria talk contribs uploaded File:Uniswap.jpg
- 11:21, 25 January 2023 Azoundria talk contribs created page KeepKey Scam Chrome Application Theft (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/keepkeyscamchromeapplicationtheft.php}} thumb|KeepKeyKeepKey had a Google Chrome extension which users could previously use to manage their funds. A malicious version of the extension was created and made available for download. At least one unsuspecting user downloaded and installed the malicious extension, which requested them to enter their seed phrase. This is a global/in...")
- 11:21, 25 January 2023 Azoundria talk contribs created page Etheroll Fork Manipulation (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/etherollforkmanipulation.php}} thumb|EtherollEtheroll is an online gambling site, which enables users to interact with a smart contract for "provably fair" gambling. The contract, however, had an exploit, that allowed some players to get an advantage and win repeatedly. The contract was shut down before significant loss, and subsequently fixed. This exchange or platform is...")
- 11:21, 25 January 2023 Azoundria talk contribs created page File:Etheroll.jpg
- 11:21, 25 January 2023 Azoundria talk contribs uploaded File:Etheroll.jpg
- 11:21, 25 January 2023 Azoundria talk contribs created page Hegic Exchange Funds Locked (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/hegicexchangefundslocked.php}} thumb|Hegic ExchangeCustomer funds on the Hegic Exchange platform were locked up due to a typo in the smart contract. The platform had requested a code review by an auditing firm, and that firm failed to notice the issue at the time. In the end, the amount lost was not that significant (compared to other incidents) and was fully reimbursed...")
- 11:20, 25 January 2023 Azoundria talk contribs created page File:Hegicexchange.jpg
- 11:20, 25 January 2023 Azoundria talk contribs uploaded File:Hegicexchange.jpg
- 11:20, 25 January 2023 Azoundria talk contribs created page EOS Ecosystem Ponzi Scheme Collapses (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/eosecosystemponzischemecollapses.php}} thumb|EOS EcosystemEOS is one of the leading blockchains. EOS Ecosystem provided a wallet for EOS holders, which would reward them with interest paid on their deposited EOS tokens. The service launched in 2018 and continued to operate through to April 20th, 2020, at which time users found that they could no longer log in. Blockchain...")
- 11:20, 25 January 2023 Azoundria talk contribs created page File:Eosecosystem.jpg
- 11:20, 25 January 2023 Azoundria talk contribs uploaded File:Eosecosystem.jpg
- 11:20, 25 January 2023 Azoundria talk contribs created page Curve Finance SUSD Vulnerability (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/curvefinancesusdvulnerability.php}} thumb|Curve FinanceCurve Finance is a decentralized smart contract to enable easy switching from one stablecoin to another. As part of the exchange setup, liquidity pools are required. These were stored in a smart contract hot wallet, and an exploit was found. However, the exploit was found by an honest white hacker who returned the f...")
- 11:19, 25 January 2023 Azoundria talk contribs created page LendfMe (DForce) DeFi Protocol Breached (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/dforcelendfmedefiprotocolbreached.php}} thumb|Dforce/LendFMeThis is another exploit where one contract is run within another, enabling balances to be reduced before they are checked. This exploit was known since July of 2019, and never patched or investigated. It's part of the illustration of why smart contracts still have risks and exploits associated. In this case, we are lu...")
- 11:19, 25 January 2023 Azoundria talk contribs created page File:Lendfme.jpg
- 11:19, 25 January 2023 Azoundria talk contribs uploaded File:Lendfme.jpg
- 11:19, 25 January 2023 Azoundria talk contribs created page BISQ Donation Address Hack (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/decentralizedbisqhacked.php}} thumb|BISQThis is an excellent example of why decentralization is not a simple “silver bullet” solution. Bisq presents an interface that can be complex and overwhelming for first-time users, the RAM-intensive software must be left running continuously in order to set up any limit orders, and the escrow system means that a trader must already have...")
- 11:19, 25 January 2023 Azoundria talk contribs created page File:Bisq.jpg
- 11:19, 25 January 2023 Azoundria talk contribs uploaded File:Bisq.jpg
- 11:18, 25 January 2023 Azoundria talk contribs created page Aragon Court Vulnerabilities (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/aragoncourtvulnerabilities.php}} thumb|Aragon CourtWhen Aragon Court first launched, there were several vulnerabilities found in the smart contract, which were resolved without exploit. This is a global/international case not involving a specific country. == About Aragon Court == "Aragon Court handles subjective disputes that require the judgment of human jurors. These j...")
- 11:18, 25 January 2023 Azoundria talk contribs created page File:Aragoncourt.jpg
- 11:18, 25 January 2023 Azoundria talk contribs uploaded File:Aragoncourt.jpg
- 11:18, 25 January 2023 Azoundria talk contribs created page Ledger Fake Chrome Extension (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgerfakechromeextension.php}} thumb|Ledger LiveA fake Google Chrome application appeared for Ledger Live, and a user downloaded it. They entered their full seed phrase when setting up the wallet. Their funds were taken by an attacker. This is a global/international case not involving a specific country. == About Ledger Live == "Based in France, Ledger is the largest cryptoc...")
- 11:15, 25 January 2023 Azoundria talk contribs created page Synthetix Ether Collateral Bug (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/synthetixethercollateralbug.php}} thumb|SynthetixA bug existed in the Synthetix smart contract which would have prevented the liquidation method from being activated, a serious fatal issue. The problem was detected and resolved before the updated contract was launched. This is a global/international case not involving a specific country. == About Synthetix == "Synthetix i...")
- 11:15, 25 January 2023 Azoundria talk contribs created page MakerDao Abnormal Liquidations (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/makerdaoabnormalliquidations.php}} thumb|MakerDAOMakerDAO is the system behind the DAI stablecoin. As part of the DAI stabilizing mechanism, the platform has a system which allows for bids on liquidations. Due to the ethereum price drop, liquidations were triggered. In order to cast a bid, an ethereum transaction is required. Due to high prices, caused by attackers flooding...")
- 11:15, 25 January 2023 Azoundria talk contribs created page Ledger Fake Google Chrome Extension (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgerfakegooglechromeextension.php}} thumb|LedgerA number of malicious Google Chrome extensions were created in March 2020, which claim to be official Ledger Live wallets. The extension is also set up on Google to show up as an advertisement in the search results. During the supposed wallet setup process, users are requested to enter their seed phrase, which is sent to the att...")
- 11:14, 25 January 2023 Azoundria talk contribs created page Jan Cerato Whale Club (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/janceratowhaleclub.php}} thumb|Jan CeratoJan Cerato ran a bitcoin meetup in late 2017 where an investment opportunity called the Whale Club was promoted. Funds were pooled together and invested by Jan with a team of 4 others in different cryptocurrencies. The full details are unclear, though investors almost all lost money. The ASC found that Jan's activities were unlawful t...")
- 11:14, 25 January 2023 Azoundria talk contribs created page File:Jancerato.jpg
- 11:14, 25 January 2023 Azoundria talk contribs uploaded File:Jancerato.jpg
- 11:14, 25 January 2023 Azoundria talk contribs created page Coinbase Sim Swapping SaltedAvocadosMhh (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbasesimswappingsaltedavocadosmhh.php}} thumb|CoinbaseReddit user SaltedAvacadosMhh reports losing 1.5 BTC that was stored on Coinbase. While they used two-factor authentication, and not SMS-based two-factor authentication on CoinBase itself, the backup of the 2FA was stored in their email. This allowed the attacker to get into their CoinBase account simply by breaching th...")
- 11:14, 25 January 2023 Azoundria talk contribs created page Nexus Mutual Fund Pool Vulnerable (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/nexusmutualfundpoolvulnerable.php}} thumb|Nexus MutualNexus Mutual initially launched with a critical vulnerability which put the funds at risk. This was resolved before it could be exploited. This is a global/international case not involving a specific country. == About Nexus Mutual == Nexus Mutual is "[a] people-powered alternative to insurance". "Nexus Mutual uses th...")
- 11:14, 25 January 2023 Azoundria talk contribs created page File:Nexusmutual.jpg
- 11:14, 25 January 2023 Azoundria talk contribs uploaded File:Nexusmutual.jpg
- 11:13, 25 January 2023 Azoundria talk contribs created page Authereum Metatransactions Order (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/authereummetatransactionsorder.php}} thumb|AuthereumNow you can give access to your funds from anywhere with just a single username and password. A great feature for the average user who isn't the best at making secure passwords, operates often on computers which are public or contain malware, and often will use the same password for multiple accounts. Free yourself from the...")
- 11:13, 25 January 2023 Azoundria talk contribs created page File:Authereum.jpg
- 11:13, 25 January 2023 Azoundria talk contribs uploaded File:Authereum.jpg
- 11:13, 25 January 2023 Azoundria talk contribs created page VBITEX Hacked (Created page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/vbitexhacked.php}} thumb|VBITEXYou know you're dealing with a safe trading platform when different sites say it's based in different countries and there are no withdrawal fees listed. Unfortunately, this platform was breached and it appears that any users who had funds would have lost them. This didn't get much coverage, and there doesn't appear to be any record of how much wa...")
- 11:13, 25 January 2023 Azoundria talk contribs created page File:Vbitex.jpg
- 11:13, 25 January 2023 Azoundria talk contribs uploaded File:Vbitex.jpg