User contributions for Azoundria

Jump to navigation Jump to search
Search for contributionsExpandCollapse
⧼contribs-top⧽
⧼contribs-date⧽
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)

28 January 2023

  • 10:5410:54, 28 January 2023 diff hist 0 N File:Rarebearsnft.jpgNo edit summary current
  • 10:5410:54, 28 January 2023 diff hist +12,940 N Unchained Capital ActiveCampaign Privacy BreachCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/unchainedcapitalactivecampaignprivacybreach.php}} thumb|Unchained CapitalUnchained Capital is a bitcoin custody service which assists individuals in setting up multi-signature wallets. For marketing, they used a customer relationship management tool called ActiveCampaign. In February 2022, they closed down their account and requested all data to be deleted. However, t..."
  • 10:5410:54, 28 January 2023 diff hist 0 N File:Unchainedcapital.jpgNo edit summary current
  • 10:5410:54, 28 January 2023 diff hist +11,999 N Fantasm Finance Contract VulnerabilitiesCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/fantasmfinancecontractvulnerabilities.php}} thumb|Fantasm FinanceFantasm Finance is a protocol creating a synthetic token which is 1:1 pegged against the Fantom token. Due to a missing condition check for the minimum amount of fantom, the smart contract hot wallet was vulnerable. A malicious user exploited this and made off with over 1,007 ETH from the hot wallet. Some..."
  • 10:5310:53, 28 January 2023 diff hist 0 N File:Fantasmfinance.jpgNo edit summary current
  • 10:5310:53, 28 January 2023 diff hist +9,473 N Pirate X Pirate Private Key LeakCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/piratexpirateprivatekeyleak.php}} thumb|Pirate X PirateThe Pirate X Pirate NFT game suffered a breach that resulted in 212 BNB (~$83k USD) worth of funds being taken. The breach appears to be the result of a private key leak, and very limited details have been published on how the key may have leaked. The company has instead fired their development team and hired externa..."
  • 10:5310:53, 28 January 2023 diff hist 0 N File:Piratexpirate.jpgNo edit summary current
  • 10:5310:53, 28 January 2023 diff hist +13,151 N OpenDAO USDO Stable Coin CollapsesCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/opendaousdostablecoincollapses.php}} thumb|OpenDAOOpenDAO launched with the ambitious goal of creating a stablecoin that was intended to be widely adopted throughout decentralized finance. Unlike other coins, the OpenDao was intending to be backed also by real world assets in addition to digital assets, promising a liquidation handling method for dealing with potential default..."
  • 10:5310:53, 28 January 2023 diff hist 0 N File:Opendao.jpgNo edit summary current
  • 10:5210:52, 28 January 2023 diff hist +10,978 N TreasureDAO NFT Market HackedCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/treasuredaonftmarkethacked.php}} thumb|TreasureDAOTreasureDAO has a NFT marketplace running on the Arbitum blockchain. A bug existed in the smart contract marketplace hot wallet where the NFTs could be taken by specifying a "quantity" of zero, at which point a price of 0 would be calculated for the item. This was exploited to steal hundreds of NFTs. This is a global/inter..."
  • 10:5210:52, 28 January 2023 diff hist 0 N File:Treasuredao.jpgNo edit summary current
  • 10:5210:52, 28 January 2023 diff hist +5,597 N Ledger Phishing Attack On Dutch UsersCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/ledgerphishingattackondutchusers.php}} thumb|LedgerLedger reports that a recent phishing campaign was launched targeting Dutch users in their language. This email pretends to be from a law firm working with Ledger, and requests the users to click a malicious link for 2FA verification. While details are not provided, typically links will either try to run a malicious transaction..."
  • 10:5210:52, 28 January 2023 diff hist +7,213 N OpenSea Fake Verification Phishing EmailsCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseafakeverificationphishingemails.php}} thumb|OpenSeaMany users of OpenSea, one of the largest NFT marketplaces in the world, received phishing emails requesting them to click a link and complete a verification within the next couple of days, threatening an account suspension. The email was not from OpenSea, and likely attempted to steal assets or the private keys of users..."
  • 10:5210:52, 28 January 2023 diff hist +7,462 N Doodles NFT Discord HackedCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/doodlesnftdiscordhacked.php}} thumb|Doodles NFTThe Doodles NFT are a collection of 10,000 hand-drawn NFT images made by a Canadian artist with the handle "Burnt Toast". The Discord server of the project was hacked on February 26th by an unknown exploit. It is unknown how much was taken, and doesn't appear any was recovered. Similar exploits have commonly abused webhooks bei..."
  • 10:5110:51, 28 January 2023 diff hist 0 N File:Doodlesnft.jpgNo edit summary current
  • 10:5110:51, 28 January 2023 diff hist +7,341 N Ariva Digital Key BreachedCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/arivadigitalkeybreached.php}} thumb|Ariva DigitalAriva Digital was a blockchain project with a focus on tourism and travel. One of their staking contracts was breached, presumably due to a private key breach. All assets were liquidated via TornadoCash. According to the team, they have enough funds to reimburse all affected users, although KYC will be required to get any f..."
  • 10:5110:51, 28 January 2023 diff hist 0 N File:Arivadigital.jpgNo edit summary current
  • 10:5110:51, 28 January 2023 diff hist +15,122 N Lana Rhoades Alleged Rug PullCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/lanarhoadesallegedrugpull.php}} thumb|OpenSeaLana Rhoades created her own brand of NFT, and made promises to investors online. The market uptake of her NFTs was less than predicted, and investors started to complain after Lana Rhoades liquidated $1.5m, apparently to pay her team. Some even accused her of scamming them, including influential Coffeezilla. Following this, Lan..."
  • 10:5110:51, 28 January 2023 diff hist 0 N File:Lanarhoades.jpgNo edit summary current
  • 10:5010:50, 28 January 2023 diff hist +13,291 N Flurry Finance Vault Flash Loan AttackCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/flurryfinancevaultflashloanattack.php}} thumb|Flurry FinanceFlurry Finance is a yield farming protocol which offers a stablecoin with interest. An attacker was able to exploit the smart contract hot wallet and removed between $251,000 and $293,000 USD worth of funds by increasing their token balance using a Flash loan. The protocol has vowed to reimburse all affected use..."
  • 10:5010:50, 28 January 2023 diff hist 0 N File:Flurryfinance.jpgNo edit summary current
  • 10:5010:50, 28 January 2023 diff hist +15,196 N Compound Finance Live Critical VulnerabilityCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/compoundfinancelivecriticalvulnerability.php}} thumb|Compound FinanceCompound Finance is a protocol which allows for decentralized lending. It operates with 18 separate markets including TrueUSD. A critical vulnerability was discovered during an audit. A public function can be used to sweep tokens accidentally sent to the smart contract, however this could also be used..."
  • 10:5010:50, 28 January 2023 diff hist +13,603 N OpenSea Phishing AttackCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/openseaphishingattack.php}} thumb|OpenSeaMultiple users on the OpenSea platform were the subject of a phishing attack, from an unknown vector. OpenSea is still investigating, and hasn't been able to determine the cause. It is reported that some of the NFT tokens were returned by the attacker, while others were sold, and the proceeds mixed through TornadoCash. This is a global..."
  • 10:4910:49, 28 January 2023 diff hist +6,387 N Gold Mine Finance ScamCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/goldminefinancescam.php}} Gold Mine Finance was a new protocol on the Fantom blockchain, a fork of Tomb Finance. There were no documents or website for the fork. It was promoted solely on Twitter and some listing sites. The smart contract hot wallet had a clever vulnerability present to enable the removal of liquidity. Although $800k of liquidity was originally present in the protocol, $700k was r..."
  • 10:4910:49, 28 January 2023 diff hist +7,272 N RigoBlock Missing Access ControlsCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/rigoblockmissingaccesscontrols.php}} thumb|RigoBlockRigoBlock had an exploit on their smart contract hot wallet, where the access controls had not been set up properly. The protocol was exploited and 160.86 ETH was taken. The attacker later returned 90% of the funds, keeping the remaining 10% as a bounty. The returned funds are anticipated to be redistributed to affected use..."
  • 10:4910:49, 28 January 2023 diff hist 0 N File:Rigoblock.jpgNo edit summary current
  • 10:4910:49, 28 January 2023 diff hist +7,460 N TopGoal Hot Wallet BreachCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/topgoalhotwalletbreach.php}} thumb|TopGoalTopGoal is a system of NFT collectibles featuring historic moments of football/soccer. One of the hot wallets for the TMT token was breached through an undisclosed means, and 4,809,984 TMT was taken, liquidated for 2,600 BNB. The funds were mixed through TornadoCash. The original tokens were all belonging to the founding team. An equiv..."
  • 10:4910:49, 28 January 2023 diff hist 0 N File:Topgoal.jpgNo edit summary current
  • 10:4810:48, 28 January 2023 diff hist +13,525 N Titano Finance Evil ContractorsCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/titanofinanceevilcontractors.php}} thumb|Titano FinanceTitano is a project which offers an automatic staking protocol, meaning that tokens are automatically staked without the user having to take any action. They used a custom smart contract hot wallet, which was developed by a third party. A backdoor was left in the contract during the deployment, which allowed the thir..."
  • 10:4810:48, 28 January 2023 diff hist 0 N File:Titanofinance.jpgNo edit summary current
  • 10:4810:48, 28 January 2023 diff hist +12,103 N Build Finance Malicious Governance TakeoverCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/buildfinancemaliciousgovernancetakeover.php}} thumb|Build FinanceBuild finance operated a decentralized autonomous venture builder, launching new projects using funds in a treasury overseen by a decentralized governance model. Unfortunately, a malicious actor took over the protocol and drained the funds once they gained enough BUILD tokens, managed to disable bots that no..."
  • 10:4810:48, 28 January 2023 diff hist 0 N File:Buildfinance.jpgNo edit summary current
  • 10:4810:48, 28 January 2023 diff hist +9,358 N Coinbase Advanced Market VulnerabilityCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/coinbaseadvancedmarketvulnerability.php}} thumb|CoinbaseCoinbase had a critical bug in their centralized trading platform, which would have allowed hackers to swap assets for one another arbitrarily in making trades. For example, a user could trade BTC to USD, but actually offer up only an equivalent amount of Shiba Inu token. No funds were lost as the issue was reported by a..."
  • 10:4710:47, 28 January 2023 diff hist +7,258 N FutureSwap Credential DisclosureCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/futureswapcredentialdisclosure.php}} thumb|FutureSwapFutureSwap is a decentralized exchange that operates on Arbitrum, a layer 2 solution to scale ethereum. One of the users who held over 300,000 FST (valued ~$798k USD) suffered an account breach and their funds were stolen. Details of the specific breach method were not located. The protocol apparently paused the smart con..."
  • 10:4710:47, 28 January 2023 diff hist 0 N File:Futureswap.jpgNo edit summary current
  • 10:4710:47, 28 January 2023 diff hist +10,891 N Dego Finance Key CompromisedCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/degofinancekeycompromised.php}} thumb|Dego FinanceDego Finance offers a foundation for NFT projects to acquire users, distribute tokens, and auction or trade NFTs. It was a relatively unknown project when they fell under attack, apparently due to compromised keys. The entire liquidity pool was drained and funds were successfully mixed through TornadoCash. While the project..."
  • 10:4710:47, 28 January 2023 diff hist 0 N File:Degofinance.jpgNo edit summary current
  • 10:4710:47, 28 January 2023 diff hist +13,660 N BabyMuskCoin Honeypot RugpullCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/babymuskcoinhoneypotrugpull.php}} thumb|BabyMuskCoinBaby Musk Coin was a new meme coin launched to supposedly attract the attention of Elon Musk. The smart contract was structured to prevent the token from being sold other than by founders. The token was able to trend on CoinMarketCap and then even gained some news coverage before the founders decided to sell all tokens i..."
  • 10:4610:46, 28 January 2023 diff hist 0 N File:Babymuskcoin.jpgNo edit summary current
  • 10:4610:46, 28 January 2023 diff hist +14,960 N IRA Financial Suspicious WithdrawalsCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/irafinancialsuspiciouswithdrawals.php}} thumb|IRA FinancialIRA Financial offers the ability for clients to invest in bitcoin and ethereum, which is stored in the third party custodian Gemini. In a single day, $36m worth of client funds were transferred between accounts and removed from the Gemini platform. These funds were then mixed. Unsurprisingly, insurance is not cove..."
  • 10:4610:46, 28 January 2023 diff hist 0 N File:Irafinancial.jpgNo edit summary current
  • 10:4610:46, 28 January 2023 diff hist +12,881 N Superfluid Wallet ImpersonationCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/superfluidwalletimpersonation.php}} thumb|SuperfluidSuperfluid offers an innovative way for entities to continually stream payments, settling recurring and continual payments without multiple transactions being required. Despite multiple audits, an exploit still existed in the smart contract hot wallet which allowed the attacker to impersonate paying entities and create pay..."
  • 10:4610:46, 28 January 2023 diff hist 0 N File:Superfluid.jpgNo edit summary current
  • 10:4510:45, 28 January 2023 diff hist +11,231 N Meter.io Minting ExploitCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/meteriomintingexploit.php}} thumb|Meter.ioMeter.io is a large multi-chain bridge, which allows assets to be moved between different blockchain smart contract networks. As part of their setup, funds exist locked in smart contract hot wallets, which back representative tokens used in the transfer. Based on an attacker exploiting a missing validation check, extra tokens were mint..."
  • 10:4510:45, 28 January 2023 diff hist 0 N File:Meterio.jpgNo edit summary current
  • 10:4510:45, 28 January 2023 diff hist +11,146 N PayBito Customer Data BreachCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/paybitocustomerdatabreach.php}} thumb|PayBitoPayBito is a large cryptocurrency exchange operating in the US and India. On February 3rd, 2022, a ransom group apparently gained access to the records of over 100,000 customers, including weakly hashed passwords. The group also claimed they were going to publish the records if a ransom was not paid by February 21st. There is no ind..."
  • 10:4510:45, 28 January 2023 diff hist 0 N File:Paybito.jpgNo edit summary current
  • 10:4410:44, 28 January 2023 diff hist +24,779 N KlaySwap BGP HijackingCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/klayswapbgphijacking.php}} thumb|KlaySwapKlaySwap suffered an advanced BGP hijack attack, when an adversary managed to modify the JavaScript on the site to a malicious version which changed all transactions into a request to send funds to them. In total, $1.9M was taken over a series of 407 transactions before the malicious code was removed. The KlaySwap team has created a re..."
  • 10:4410:44, 28 January 2023 diff hist 0 N File:Klayswap.jpgNo edit summary current
  • 10:4410:44, 28 January 2023 diff hist +20,590 N Wormhole Network Signature Validation LoopholeCreated page with "{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/wormholenetworksignaturevalidationloophole.php}} thumb|Wormhole NetworkWormhole Finance is a decentralized bridge between multiple chains including Ethereum, Solana, Terra, Binance Smart Chain, Polygon, Avalanche, and Oasis. A decentralized network of 19 guardians secure the bridge. An attacker exploited a signature verification vulnerability in the smart contract hot..."
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)