Ankr Attack Incident Report: Former team members maliciously attacked the supply chain and are cooperating with law enforcement for prosecution
ChainCatcher news, Web3 infrastructure provider Ankr has released an attack incident report, revealing the findings of an investigation into the exploitation of the aBNBc Token vulnerability. Ankr stated that this attack originated from a former team member who maliciously conducted a supply chain attack by inserting a malicious code package, which could compromise private keys once a legitimate update was performed. Currently, Ankr is working with law enforcement to prosecute this former team member to bring them to justice.
Ankr indicated that this could affect any protocol, and the team is supporting internal human resources processes and security measures to strengthen future security posture. Ankr is implementing several improvements to its security status, including requiring all updates to undergo multi-signature authentication and time-locks, enhancing internal security measures, implementing new monitoring and notification systems, and refining the process of using DeFi protocols. (Source link)