News: 1710858610

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Crypto wallet providers urged to rethink security as criminals drain them of millions

(2024/03/19)


Infosec researchers are noting rising cryptocurrency attacks and have encouraged wallet security providers to up their collective game.

Check Point specifically cites the growth of attacks that abuse Ethereum's CREATE2 opcode, dubbing it a "critical issue in the blockchain community" that's seeing millions of dollars worth of assets being drained from victims' wallets.

Introduced in 2019, CREATE2 is seen as a significant advancement for Ethereum, allowing for more efficient deployments of smart contracts – the technology that validates transactions on the blockchain.

[1]

CREATE2 is also the function that's being exploited by attackers to drain tokens from victims' wallets.

[2]

[3]

One of its key capabilities is being able to deploy smart contracts to pre-determined addresses, making the entire process more predictable for the blockchain when dealing with multiple contract interactions across the ecosystem of decentralized applications.

By pre-determined, it means that an attacker can create temporary, single-use addresses to receive a victim's assets. New addresses can be used for each attack, and this is crucial because wallet security providers rely on previously held data to flag potentially malicious transactions. If the address has no dodgy history, it's likely the transaction will evade these detections.

[4]

The fact that attackers can set up a contract before deploying it (before it even exists), using a wallet address that doesn't have a history of malicious activity, means that if they can get the victim to approve a contract they can drain their funds.

Of course, this requires some social engineering hijinkery to pull off, but we've all heard about the real-life scam stories that sound too wild to be true, but are. This attack works, and has facilitated huge single-transaction scams in recent times.

The researchers highlighted one fraud in January that saw attackers make off with $3.6 million worth of SuperVerse tokens in one fell swoop as an example of how serious these incidents can be for victims.

[5]

Remember: with blockchains, there is no legal recourse and no customer helpline to recover funds. Once they're sent and signed, that's it – tokens are gone for good.

How they work and why they work

The attack flow is as follows. First, an attacker needs to get a victim to approve a contract that hasn't yet been deployed – the bit that requires social engineering. They then use CREATE2's ability to generate new contract addresses to receive the funds and deploy the malicious contract, complete with the victim's authorization, in turn draining the victim's wallet.

The key part here is the generation of a new wallet address, one that has no history of being reported for criminal intentions. CREATE2 generates this using a calculation that includes four parameters: the attacker's wallet address, a constant prefix, a salt, and an initialization code.

This address will be created only when the victim approves the contract, meaning it's never been used before for any illicit dealings, and won't be used again, thereby bypassing the security protections that usually monitor such transactions.

"The exploitation of the CREATE2 function underscores the continuous battle between innovation and security in the blockchain sphere," [6]said Check Point researchers Oded Vanunu, Dikla Barda, and Roman Zaikin.

"As Ethereum continues to evolve, so too must the security mechanisms designed to protect users from such sophisticated attacks. Awareness and education are the first steps in safeguarding digital assets against emerging threats. Blockchain developers and users alike must remain vigilant, continuously updating their knowledge and security practices to navigate this ever-changing landscape securely.

"This vulnerability highlights the need for enhanced security measures in wallet security products to adapt to the evolving tactics of cybercriminals, ensuring the safekeeping of digital assets in the face of innovative exploits."

The big business of crypto attacks

Towards the back end of 2023, we saw a string of high-profile wallet-draining attacks netting cybercriminals hefty sums, and the attacks weren't localized to just the Ethereum blockchain either.

Justin Sun, founder of the Tron Foundation and owner of Poloniex, a crypto exchange that was [7]drained of circa $120 million in November, offered a reward for the attackers at the time to return the funds they stole.

[8]ChatGPT side-channel attack has easy fix: Token obfuscation

[9]US to probe Change Healthcare's data protection standards as lawsuits mount

[10]Cryptocurrency laundryman gets hung out to dry

[11]Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

The Monero Project was also [12]mysteriously drained of nearly half a million dollars just days before, and 5,000 Atomic Wallet users were drained earlier in the year – just a few of the high-profile incidents that took place in 2023.

While not all of these have been directly attributed to CREATE2 exploits, researchers told The Register that it seems like [13]North Korea's state-sponsored Lazarus gang may have been behind a sizable proportion of them.

The web3 anti-scam solution provider ScamSniffer analyzed a [14]series of CREATE2 incidents between May and November 2023, concluding that almost $60 million had been stolen from around 99,000 victims. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfnEpkQwggdJBRC2hUBv7gAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfnEpkQwggdJBRC2hUBv7gAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfnEpkQwggdJBRC2hUBv7gAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfnEpkQwggdJBRC2hUBv7gAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfnEpkQwggdJBRC2hUBv7gAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://research.checkpoint.com/2024/ethereums-create2-a-double-edged-sword-in-blockchain-security/

[7] https://www.theregister.com/2023/11/10/justin_sun_poloniex_reward/

[8] https://www.theregister.com/2024/03/18/chatgpt_sidechannel_attack_has_easy/

[9] https://www.theregister.com/2024/03/14/change_healthcare_ransomware_investigation/

[10] https://www.theregister.com/2024/03/13/bitcoin_fog_conviction/

[11] https://www.theregister.com/2024/03/04/alphv_ransom_payment/

[12] https://www.theregister.com/2023/11/08/monero_project_developers_announce_breach/

[13] https://www.theregister.com/2023/06/08/lazarus_link_atomic_wallet/

[14] https://drops.scamsniffer.io/post/wallet-drainers-starts-using-create2-bypass-wallet-security-alert/

[15] https://whitepapers.theregister.com/



Rather obvious?

Mike 137

" The fact that attackers can set up a contract before deploying it (before it even exists) " is a huge and glaring vulnerability that should never have been allowed. It's just asking for trouble and clearly got it. The great weakness of all these 'alternative' regulation-free financial systems is that they haven't embraced the lessons that the regulated ones took over a century to learn the hard way.

Re: Rather obvious?

I ain't Spartacus

I've seen Crypto described as like going through all the scandals of 19th Century banking again at high speed.

It seems particularly odd that security measures that are designed to track illicit payments only look for black-listed accounts. Given that the blockchain exists, you can look up the history of any account - so if a payment is due to go to a new account that has hosted zero transactions - that ought to be flagged as obviously dodgy.

Plus am I really supposed to take seriously someone saying their SuperVerse tokens have been stolen? If it's a crying 5 year-old who's lost their coins to play a Marvel game, I'm going to have some sympathy.

As with taxes, regulations are annoying. But both are often there for a reason.

Elephant in the room

Mage

Is so-called Crypto-coins or Cryptocurrency.

An environmentally damaging technology, and like Blockchain, a solution looking for a problem.

Just protect consumers by making the scam illegal. Why does Revolut offer it?

Re: Elephant in the room

hoola

Whilst it is very sad if people lose their money or the Crypto Currencies/Exchanges lose stuff I an not hugely sympathetic.

It is a completely unregulated market with no protection to anyone other than the criminals who appear to use it for anonymity.

There is a reason that banks exist, surrounded by regulation and in the UK protection for savers. It is also why returns are lower.

You could buy shares and things but the caveat is always there "you may not get back your original investment".

Hope is a waking dream.
-- Aristotle