• bitcoinBitcoin (BTC) $ 92,048.00
  • ethereumEthereum (ETH) $ 3,129.91
  • tetherTether (USDT) $ 0.998925
  • bnbBNB (BNB) $ 909.46
  • xrpXRP (XRP) $ 2.06
  • usd-coinUSDC (USDC) $ 0.999676
  • tronTRON (TRX) $ 0.299018
  • staked-etherLido Staked Ether (STETH) $ 3,127.37
  • dogecoinDogecoin (DOGE) $ 0.139470
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.391694
  • moneroMonero (XMR) $ 678.96
  • wrapped-stethWrapped stETH (WSTETH) $ 3,829.03
  • bitcoin-cashBitcoin Cash (BCH) $ 610.34
  • whitebitWhiteBIT Coin (WBT) $ 55.14
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,744.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,404.78
  • wrapped-eethWrapped eETH (WEETH) $ 3,396.33
  • usdsUSDS (USDS) $ 0.999561
  • chainlinkChainlink (LINK) $ 13.22
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998678
  • leo-tokenLEO Token (LEO) $ 9.06
  • wethWETH (WETH) $ 3,127.79
  • stellarStellar (XLM) $ 0.222949
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 92,015.00
  • suiSui (SUI) $ 1.80
  • zcashZcash (ZEC) $ 401.93
  • ethena-usdeEthena USDe (USDE) $ 0.999356
  • avalanche-2Avalanche (AVAX) $ 13.75
  • litecoinLitecoin (LTC) $ 76.39
  • hyperliquidHyperliquid (HYPE) $ 24.45
  • canton-networkCanton (CC) $ 0.143944
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.116214
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.168723
  • usdt0USDT0 (USDT0) $ 0.998699
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999703
  • the-open-networkToncoin (TON) $ 1.75
  • crypto-com-chainCronos (CRO) $ 0.100609
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999947
  • usd1-wlfiUSD1 (USD1) $ 0.998545
  • polkadotPolkadot (DOT) $ 2.08
  • uniswapUniswap (UNI) $ 5.43
  • mantleMantle (MNT) $ 0.957327
  • rainRain (RAIN) $ 0.008757
  • memecoreMemeCore (M) $ 1.68
  • bittensorBittensor (TAO) $ 285.47
  • aaveAave (AAVE) $ 170.55
  • bitget-tokenBitget Token (BGB) $ 3.55
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,591.06
  • okbOKB (OKB) $ 111.29
  • nearNEAR Protocol (NEAR) $ 1.74
  • falcon-financeFalcon USD (USDF) $ 0.996675
  • jito-staked-solJito Staked SOL (JITOSOL) $ 176.92
  • ethereum-classicEthereum Classic (ETC) $ 12.46
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,128.46
  • pax-goldPAX Gold (PAXG) $ 4,605.29
  • internet-computerInternet Computer (ICP) $ 3.22
  • ethenaEthena (ENA) $ 0.219527
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.206360
  • aster-2Aster (ASTER) $ 0.699120
  • solanaWrapped SOL (SOL) $ 141.12
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.152152
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.81
  • htx-daoHTX DAO (HTX) $ 0.000002
  • binance-staked-solBinance Staked SOL (BNSOL) $ 154.48
  • worldcoin-wldWorldcoin (WLD) $ 0.565153
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999574
  • pump-funPump.fun (PUMP) $ 0.002574
  • kucoin-sharesKuCoin (KCS) $ 11.15
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999741
  • aptosAptos (APT) $ 1.80
  • hash-2Provenance Blockchain (HASH) $ 0.025228
  • skySky (SKY) $ 0.058107
  • wbnbWrapped BNB (WBNB) $ 908.96
  • bfusdBFUSD (BFUSD) $ 0.998771
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,612.53
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999536
  • kaspaKaspa (KAS) $ 0.047309
  • cosmosCosmos Hub (ATOM) $ 2.54
  • ondo-financeOndo (ONDO) $ 0.391219
  • render-tokenRender (RENDER) $ 2.37
  • myx-financeMYX Finance (MYX) $ 6.35
  • gatechain-tokenGate (GT) $ 10.28
  • arbitrumArbitrum (ARB) $ 0.204816
  • algorandAlgorand (ALGO) $ 0.130791
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,321.53
  • midnight-3Midnight (NIGHT) $ 0.065683
  • filecoinFilecoin (FIL) $ 1.48
  • official-trumpOfficial Trump (TRUMP) $ 5.42
  • story-2Story (IP) $ 3.07
  • quant-networkQuant (QNT) $ 72.66
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,822.12
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 92,136.00
  • ignition-fbtcFunction FBTC (FBTC) $ 91,952.00
  • vechainVeChain (VET) $ 0.011519
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 91,927.00
  • nexoNEXO (NEXO) $ 0.967868
  • flare-networksFlare (FLR) $ 0.011220
  • bonkBonk (BONK) $ 0.000011
  • usddUSDD (USDD) $ 0.998958
  • xdce-crowd-saleXDC Network (XDC) $ 0.046584
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,392.36
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,310.51
  • usdtbUSDtb (USDTB) $ 0.999055
  • ousgOUSG (OUSG) $ 113.94
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • sei-networkSei (SEI) $ 0.121443
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999575
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999603
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011943
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,769.00
  • clbtcclBTC (CLBTC) $ 91,345.00
  • morphoMorpho (MORPHO) $ 1.30
  • blockstackStacks (STX) $ 0.385957
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,340.46
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 163.84
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • beldexBeldex (BDX) $ 0.090326
  • jupiter-exchange-solanaJupiter (JUP) $ 0.211153
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.99
  • usdaiUSDai (USDAI) $ 0.999606
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.284548
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • wrapped-flareWrapped Flare (WFLR) $ 0.011217
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,321.89
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.976899
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,127.19
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999710
  • optimismOptimism (OP) $ 0.318696
  • tezosTezos (XTZ) $ 0.566342
  • dashDash (DASH) $ 47.52
  • curve-dao-tokenCurve DAO (CRV) $ 0.402978
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,128.85
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.70
  • chilizChiliz (CHZ) $ 0.054746
  • spx6900SPX6900 (SPX) $ 0.592702
  • tbtctBTC (TBTC) $ 91,768.00
  • usual-usdUsual USD (USD0) $ 0.986141
  • lighterLighter (LIT) $ 2.17
  • lido-daoLido DAO (LDO) $ 0.624746
  • injective-protocolInjective (INJ) $ 5.17
  • aerodrome-financeAerodrome Finance (AERO) $ 0.566248
  • gtethGTETH (GTETH) $ 3,127.52
  • ghoGHO (GHO) $ 0.998927
  • flokiFLOKI (FLOKI) $ 0.000051
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998476
  • true-usdTrueUSD (TUSD) $ 0.998624
  • ether-fiEther.fi (ETHFI) $ 0.742636
  • msolMarinade Staked SOL (MSOL) $ 190.74
  • celestiaCelestia (TIA) $ 0.553268
  • fasttokenFasttoken (FTN) $ 1.09
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,379.44
  • syrupMaple Finance (SYRUP) $ 0.397484
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • stader-ethxStader ETHx (ETHX) $ 3,372.78
  • the-graphThe Graph (GRT) $ 0.041489
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,503.04
  • riverRiver (RIVER) $ 21.92
  • jasmycoinJasmyCoin (JASMY) $ 0.008714
  • newton-projectAB (AB) $ 0.004461
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.209249
  • sbtc-2sBTC (SBTC) $ 92,389.00
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • staked-aaveStaked Aave (STKAAVE) $ 169.32
  • starknetStarknet (STRK) $ 0.082018
  • usdbUSDB (USDB) $ 1.01
  • doublezeroDoubleZero (2Z) $ 0.118542
  • iotaIOTA (IOTA) $ 0.095892
  • justJUST (JST) $ 0.040613
  • sun-tokenSun Token (SUN) $ 0.020752
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.24
  • conflux-tokenConflux (CFX) $ 0.075701
  • bitcoin-svBitcoin SV (BSV) $ 19.33
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.383998
  • chain-2Onyxcoin (XCN) $ 0.008877
  • pyth-networkPyth Network (PYTH) $ 0.065847
  • fartcoinFartcoin (FARTCOIN) $ 0.377380
  • gnosisGnosis (GNO) $ 142.13
  • dogwifcoindogwifhat (WIF) $ 0.372194
  • pendlePendle (PENDLE) $ 2.17
  • apenftAINFT (NFT) $ 0.00000037
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.873752
  • c8ntinuumc8ntinuum (CTM) $ 0.144472
  • crvusdcrvUSD (CRVUSD) $ 0.997251
  • kaiaKaia (KAIA) $ 0.061345
  • cap-usdCap USD (CUSD) $ 0.994620
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,912.00
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.139347
  • euro-coinEURC (EURC) $ 1.17
  • telcoinTelcoin (TEL) $ 0.003746
  • kinesis-goldKinesis Gold (KAU) $ 147.62

WazirX finds no evidence of compromised devices, blames Liminal security

0 97

WazirX finds no evidence of compromised devices, blames Liminal security

WazirX said its preliminary investigation found no evidence indicating that the machines of WazirX signers were compromised during a recent sophisticated cyber attack on its multi-signature Ethereum wallet, according to a July 25 blog post,

The attack, which occurred earlier this month, has prompted significant concern and scrutiny within the crypto community. The exchange initially said the hack occurred due to an issue with its custody service provider, Liminal’s user interface.

However, Liminal said in its July 19 investigation report its infrastructure was not responsible for the hack and that compromised hardware wallets were the most likely cause.

WazirX investigation

WazirX emphasized that its ongoing forensic analysis has not uncovered any signs of malware or tampering on their signers’ devices. The attacked wallet required the signatures of three WazirX signers and one from Liminal, a custody service provider.

The malicious transactions were signed using devices at different locations, each accessing the legitimate Liminal website. The hardware wallets, crucial in securing transactions, did not detect any new connection requests, indicating the website used was authentic.

Despite the rigorous security measures in place, the attack involved legitimate signatures. The exchange believes this points to a potential breach within Liminal’s system. Furthermore, it said that even if the hardware wallets were compromised, Liminal’s fourth signature was the final “line of defense.”

WazirX outlined two possible scenarios that could explain the breach:

  • Breach within Liminal’s Infrastructure: Malicious transactions were received directly from Liminal due to a potential compromise of their system. This scenario is currently considered more likely due to the absence of new connection requests to hardware wallets and the use of whitelisted addresses.
  • Compromise of WazirX Signers’ Devices: This scenario involves malware infecting the devices of WazirX signers, although no preliminary evidence has been found to support this. It would also require a breach of Liminal’s firewall to obtain the final signature.

The exchange emphasized that the malicious transactions did not originate from WazirX servers, which points to a potential breach of Liminal’s security.

The hack

The India-based crypto exchange suffered the catastrophic hack on July 18. The attacker stole roughly 45% of the crypto it held, forcing it to halt operations. WazirX said that the hack only affected its multi-sig wallet and assured users that their fiat currency deposits remained safe.

The exchange said it is working with all relevant authorities and plans to resume services once a viable solution is found. It’s currently discussing possible partnerships that would allow it to make customers whole.

Cybersecurity experts have suggested the involvement of the notorious North Korean Lazarus Group, known for its advanced cyber attacks on financial institutions and crypto exchanges.

The incident highlights the evolving challenges of securing multi-signature wallets, particularly the risks associated with “blind signing,” where hardware wallets do not display transaction details.

WazirX said it had implemented industry-standard best practices, including verifying website URLs, using reputable platforms, and employing multi-factor authentication.

Source

Leave A Reply

Your email address will not be published.