BTC $77,595.07 -3.01%
ETH $2,438.55 -2.83%
BNB $689.45 -3.03%
XRP $1.38 -4.80%
SOL $103.59 -5.34%
TRX $0.3412 +1.05%
DOGE $0.0847 -4.31%
ADA $0.2022 -5.40%
BCH $247.74 -8.02%
LINK $11.40 -4.12%
HYPE $80.06 -6.73%
AAVE $121.69 -5.06%
SUI $0.7379 -5.46%
XLM $0.1778 -4.63%
ZEC $800.36 -2.03%
BTC $77,595.07 -3.01%
ETH $2,438.55 -2.83%
BNB $689.45 -3.03%
XRP $1.38 -4.80%
SOL $103.59 -5.34%
TRX $0.3412 +1.05%
DOGE $0.0847 -4.31%
ADA $0.2022 -5.40%
BCH $247.74 -8.02%
LINK $11.40 -4.12%
HYPE $80.06 -6.73%
AAVE $121.69 -5.06%
SUI $0.7379 -5.46%
XLM $0.1778 -4.63%
ZEC $800.36 -2.03%

pro

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.
app_icon
ChainCatcher Building the Web3 world with innovations.