CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
NewsBTC 2024-07-18 19:18:36

WazirX Exchange Releases Post-Mortem Report: Was North Korea Behind The $235M Exploit?

Indian-based cryptocurrency exchange WazirX recently fell victim to a significant security breach, resulting in the unauthorized transfer of over $230 million of assets. The incident led to the temporary suspension of withdrawals as the exchange worked to investigate and mitigate the breach. In a subsequent report released by WazirX, preliminary findings shed light on the causes of the exploit. At the same time, blockchain analytics firm Elliptic suggested the potential involvement of North Korea in this sophisticated attack. WazirX Multisig Wallet Breach WazirX disclosed that the cyber attack targeted one of their multisig wallets, which utilized the services of Liminal’s digital asset custody and wallet infrastructure since February 2023. The wallet allegedly had a configuration involving six signatories, including five from the WazirX team and one from Liminal, who were responsible for transaction verifications. Three WazirX signatories, who employed Ledger Hardware Wallets for added security, were required to approve a transaction, followed by the final approval from Liminal’s signatory. Related Reading: Crypto Analyst Predicts XRP Price To Hit $1.03 Soon, Warns Of Initial Dip Additionally, a whitelisting policy was in place to “enhance security,” allowing transactions solely to predefined addresses facilitated by Liminal. The exchange further disclosed that the breach originated from a “discrepancy” between the data displayed on Liminal’s interface and the actual contents of the transaction. During the attack, the exchange notes a “mismatch” between the information displayed on Liminal’s interface and what was signed. It is suspected that the payload was manipulated to transfer wallet control to the attacker, enabling them to exploit the vulnerability. North Korean Affiliation In $235M Breach? WazirX emphasized its implementation of “robust” security measures, including the Gnosis Safe multi-sig smart contract platform and Liminal’s whitelisting policy. Despite these precautions, the cyber attackers managed to breach the security features and execute the theft. Looking ahead, the exchange expressed its commitment to protecting customer assets and acknowledged the need for further investigation and reinforcement of security protocols. The exchange concluded by stating the following: This is a force majeure event beyond our control, but we are leaving no stone unturned to locate and recover the funds. We have already blocked a few deposits and reached out to concerned wallets for recovery. We are in touch with the best resources to help us in this endeavor. While these are our findings from our preliminary investigation, we will keep you posted with further updates. Together with your support, we shall overcome this challenge and emerge stronger and more resilient than ever. Related Reading: MOVR Bulls Assemble: Crypto Analyst Says A 2,000% Surge To $234 Is Imminent Blockchain analytics firm Elliptic, on the other hand, conducted an independent analysis of the exploit and indicated a potential connection to North Korea. According to Elliptic’s findings, approximately $235 million in various crypto assets were lost in the breach, including Shiba Inu (SHIB), Ethereum (ETH), Polygon (MATIC), and Pepe. The thief has reportedly converted some of these tokens into Ether using decentralized services, a common step in the laundering process. On-chain analysis and additional information reviewed by Elliptic suggest the alleged involvement of hackers affiliated with North Korea. Featured image from DALL-E, chart from TradingView.com

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.