More than $100m in cryptocurrency stolen from blockchain biz
(2022/06/24)
- Reference: 1656107198
- News link: https://www.theregister.co.uk/2022/06/24/harmony_100m_cryptocurrency_theft/
- Source link:
Blockchain venture Harmony offers bridge services for transferring crypto coins across different blockchains, but something has gone badly wrong.
The [1]Horizon Ethereum Bridge , one of the firm's ostensibly secure bridges, was compromised on Thursday, resulting in the loss of 85,867 ETH tokens optimistically worth more than $100 million, the organization said [2]via Twitter .
"Our secure bridges offer cross-chain transfers with Ethereum, Binance and three other chains," the cryptocurrency entity explained [3]on its website . Not so, it seems.
[4]
A similar attack in February on a bridge called Wormhole resulted in [5]a loss of $320 million . That was followed a month later by the [6]heist of about $620 million from video game Axie Infinity's Ronin Network, another bridge service.
[7]
[8]
"Blockchain bridges are the latest target and weak point of crypto attackers," observed Chris Wysopal, a security researcher and CTO of Veracode, [9]via Twitter . "In software security, vulnerabilities often occur in the complexity of two different systems interfacing with each other."
Matthew Barrett, who [10]contributes to project and appears to have taken on a communications role for [11]Mountain View, California-based Harmony but isn't listed on the organization's [12]team webpage , described the incident in [13]a post to Medium.
[14]
Barrett said in the wake of the attack, Harmony's security and exchange partners were notified, as was the FBI, in the hope the culprit and a way to recover the funds, [15]still sitting unlaundered in a visible crypto wallet, can be identified.
"Harmony believes that focusing on decentralized bridges is an essential step forward for Web3," said Barrett. "This incident is a humbling and unfortunate reminder of how our work is paramount to the future of this space, and how much of our work remains ahead of us."
The Horizon bridge was [16]audited by Peck Shield, a blockchain security firm, in October 21, 2020. The report identified five issues with the bridge's smart contract implementation: two high severity, two low severity, and one informational, all of which are said to have been fixed. The audit includes a disclaimer noting that the findings do not guarantee the non-existence of other security concerns.
[17]
An individual involved in cryptocurrency trading [18]raised questions in a Twitter thread about the Horizon bridge back in April and noted that the audit [19]didn't assess some aspects of the system . This person [20]speculates that that the hack was likely accomplished through a server/key compromise or social engineering.
Harmony has not yet identified how the attack was carried out.
[21]Cybercriminals made $7bn in pure profit in 2021, says FBI
[22]Cryptocurrency laundromat Blender shredded by US Treasury in sanctions first
[23]Capital One: Convicted techie got in via 'misconfigured' AWS buckets
[24]Intuit sued over alleged cryptocurrency thefts via Mailchimp intrusion
Matthew Green, a cryptography professor at Johns Hopkins University, expressed concern that the poor security of decentralized finance ventures amounts to a slush fund for hostile nations.
"It’s increasingly obvious that there are attackers (including state-sponsored attackers) making lists of vulnerable 'web3' services, ordered by target value and system vulnerability," he said [25]via Twitter . "And they are working systematically down those lists."
"Who is systematically defending this area to keep North Korea from collecting $100s of millions to use in its missile program?" [26]he asked .
The Lazarus Group, a cybercrime gang associated with North Korea's Reconnaissance General Bureau, [27]was sanctioned for involvement with the Ronin Network theft.
The Grift Counter, a running total cryptocurrency losses since 2021 maintained by [28]Web3IsGoingGreat.com , has now surpassed $10 billion. ®
Get our [29]Tech Resources
[1] https://github.com/harmony-one/horizon
[2] https://twitter.com/harmonyprotocol/status/1540110924400324608
[3] https://www.harmony.one/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.theregister.com/2022/02/04/wormhole_currency_theft/
[6] https://www.theregister.com/2022/05/06/us_treasury_sanctions_blender/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://twitter.com/weldpond/status/1540306857943760896
[10] https://open.harmony.one/funding/1000-contributors-78m/matt
[11] https://github.com/harmony-one
[12] https://open.harmony.one/team-founding-story
[13] https://medium.com/harmony-one/harmonys-horizon-bridge-hack-1e8d283b6d66
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://etherscan.io/address/0x0d043128146654c7683fbf30ac98d7b2285ded00
[16] https://docs.harmony.one/home/general/bridges/horizon-bridge/audit
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://twitter.com/_apedev/status/1510007663832223751
[19] https://twitter.com/_apedev/status/1510007671843393538
[20] https://twitter.com/_apedev/status/1540315286062202881
[21] https://www.theregister.com/2022/03/23/cybercriminals_made_7bn_2021/
[22] https://www.theregister.com/2022/05/06/us_treasury_sanctions_blender/
[23] https://www.theregister.com/2022/06/20/captial_one_wire_fraud/
[24] https://www.theregister.com/2022/04/25/intuit-mailchimp-cryptocurrency/
[25] https://twitter.com/matthew_d_green/status/1540336955187134464
[26] https://twitter.com/matthew_d_green/status/1540337522772959234
[27] https://www.elliptic.co/blog/further-sanctions-against-north-koreas-lazarus-group-for-laundering-stolen-ronin-funds
[28] https://web3isgoinggreat.com/
[29] https://whitepapers.theregister.com/
The [1]Horizon Ethereum Bridge , one of the firm's ostensibly secure bridges, was compromised on Thursday, resulting in the loss of 85,867 ETH tokens optimistically worth more than $100 million, the organization said [2]via Twitter .
"Our secure bridges offer cross-chain transfers with Ethereum, Binance and three other chains," the cryptocurrency entity explained [3]on its website . Not so, it seems.
[4]
A similar attack in February on a bridge called Wormhole resulted in [5]a loss of $320 million . That was followed a month later by the [6]heist of about $620 million from video game Axie Infinity's Ronin Network, another bridge service.
[7]
[8]
"Blockchain bridges are the latest target and weak point of crypto attackers," observed Chris Wysopal, a security researcher and CTO of Veracode, [9]via Twitter . "In software security, vulnerabilities often occur in the complexity of two different systems interfacing with each other."
Matthew Barrett, who [10]contributes to project and appears to have taken on a communications role for [11]Mountain View, California-based Harmony but isn't listed on the organization's [12]team webpage , described the incident in [13]a post to Medium.
[14]
Barrett said in the wake of the attack, Harmony's security and exchange partners were notified, as was the FBI, in the hope the culprit and a way to recover the funds, [15]still sitting unlaundered in a visible crypto wallet, can be identified.
"Harmony believes that focusing on decentralized bridges is an essential step forward for Web3," said Barrett. "This incident is a humbling and unfortunate reminder of how our work is paramount to the future of this space, and how much of our work remains ahead of us."
The Horizon bridge was [16]audited by Peck Shield, a blockchain security firm, in October 21, 2020. The report identified five issues with the bridge's smart contract implementation: two high severity, two low severity, and one informational, all of which are said to have been fixed. The audit includes a disclaimer noting that the findings do not guarantee the non-existence of other security concerns.
[17]
An individual involved in cryptocurrency trading [18]raised questions in a Twitter thread about the Horizon bridge back in April and noted that the audit [19]didn't assess some aspects of the system . This person [20]speculates that that the hack was likely accomplished through a server/key compromise or social engineering.
Harmony has not yet identified how the attack was carried out.
[21]Cybercriminals made $7bn in pure profit in 2021, says FBI
[22]Cryptocurrency laundromat Blender shredded by US Treasury in sanctions first
[23]Capital One: Convicted techie got in via 'misconfigured' AWS buckets
[24]Intuit sued over alleged cryptocurrency thefts via Mailchimp intrusion
Matthew Green, a cryptography professor at Johns Hopkins University, expressed concern that the poor security of decentralized finance ventures amounts to a slush fund for hostile nations.
"It’s increasingly obvious that there are attackers (including state-sponsored attackers) making lists of vulnerable 'web3' services, ordered by target value and system vulnerability," he said [25]via Twitter . "And they are working systematically down those lists."
"Who is systematically defending this area to keep North Korea from collecting $100s of millions to use in its missile program?" [26]he asked .
The Lazarus Group, a cybercrime gang associated with North Korea's Reconnaissance General Bureau, [27]was sanctioned for involvement with the Ronin Network theft.
The Grift Counter, a running total cryptocurrency losses since 2021 maintained by [28]Web3IsGoingGreat.com , has now surpassed $10 billion. ®
Get our [29]Tech Resources
[1] https://github.com/harmony-one/horizon
[2] https://twitter.com/harmonyprotocol/status/1540110924400324608
[3] https://www.harmony.one/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.theregister.com/2022/02/04/wormhole_currency_theft/
[6] https://www.theregister.com/2022/05/06/us_treasury_sanctions_blender/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://twitter.com/weldpond/status/1540306857943760896
[10] https://open.harmony.one/funding/1000-contributors-78m/matt
[11] https://github.com/harmony-one
[12] https://open.harmony.one/team-founding-story
[13] https://medium.com/harmony-one/harmonys-horizon-bridge-hack-1e8d283b6d66
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://etherscan.io/address/0x0d043128146654c7683fbf30ac98d7b2285ded00
[16] https://docs.harmony.one/home/general/bridges/horizon-bridge/audit
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrY0AtLBDlW7wurMDyRLywAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://twitter.com/_apedev/status/1510007663832223751
[19] https://twitter.com/_apedev/status/1510007671843393538
[20] https://twitter.com/_apedev/status/1540315286062202881
[21] https://www.theregister.com/2022/03/23/cybercriminals_made_7bn_2021/
[22] https://www.theregister.com/2022/05/06/us_treasury_sanctions_blender/
[23] https://www.theregister.com/2022/06/20/captial_one_wire_fraud/
[24] https://www.theregister.com/2022/04/25/intuit-mailchimp-cryptocurrency/
[25] https://twitter.com/matthew_d_green/status/1540336955187134464
[26] https://twitter.com/matthew_d_green/status/1540337522772959234
[27] https://www.elliptic.co/blog/further-sanctions-against-north-koreas-lazarus-group-for-laundering-stolen-ronin-funds
[28] https://web3isgoinggreat.com/
[29] https://whitepapers.theregister.com/