0

Hacking free-for-all relieves crypto bridge users of $200 million

 1 year ago
source link: https://finance.yahoo.com/news/nomad-cryptocurrency-bridge-hack-203006606.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Hacking free-for-all relieves crypto bridge users of $200 million

Jon Fingas
·Reporter
Wed, August 3, 2022, 5:30 AM·1 min read
86c0b3c0-7ee1-11ec-ae7f-d8c7b4fc0840
Dado Ruvic / reuters

Cryptocurrency hacks are all too common, but they've rarely been quite so anarchic as the latest example. As The Verge notes, Nomad has confirmed that its cryptocurrency bridge (a service that lets you swap tokens between blockchains) was the victim of an August 1st "incident" where a slew of hackers stole nearly $200 million in funds. As Paradigm researcher Samczsun explained, the intruders took advantage of a misconfiguration that let any reasonably knowledgeable user authorize their own withdrawals. The result was a "chaotic" hack where people could swap their crypto address into a known-good transaction to steal digital money.

In an update, Nomad said it's "working around the clock" to resolve the problem with help from law enforcement and blockchain intelligence firms. It hopes to both pinpoint involved accounts and recover funds. A16z's security team suggested that well-intentioned white hat hackers would return crypto they took "preemptively," but there's no word on identifying thieves.

1/ Nomad just got drained for over $150M in one of the most chaotic hacks that Web3 has ever seen. How exactly did this happen, and what was the root cause? Allow me to take you behind the scenes 👇 pic.twitter.com/Y7Q3fZ7ezm

— samczsun (@samczsun) August 1, 2022

Bridges like these are major targets for hackers thanks to both their high asset volume and the potential for exploits in their sophisticated code. An attacker swiped roughly $625 million from the Ronin blockchain underpinning Axie Infinity in March, and an exploit in the Wormhole bridge led to a $325 million hack in February. While the Nomad breach isn't quite as financially damaging, it illustrates just how vulnerable bridges can be.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK