More than 280 blockchains at risk of ‘zero-day’ exploits, warns security firm

Greater than 280 blockchain networks are prone to “zero-day” exploits that might put at the least $25 billion price of crypto in danger, in keeping with cybersecurity agency Halborn.

In a March 13 weblog submit, Halborn warned of the vulnerability it dubbed “Rab13s” — including it has already labored with some blockchains, akin to Dogecoin, Litecoin and Zcash, to institute a repair for it.

Halborn stated it was contracted in March 2022 to conduct a safety overview of Dogecoin’s codebase and located “a number of essential and exploitable vulnerabilities.”

It later decided those self same vulnerabilities “affected over 280 different networks” that risked billions of {dollars} price of cryptocurrencies.

Halborn outlined three vulnerabilities, the “most important” of which permits an attacker to “ship crafted malicious consensus messages to particular person nodes, inflicting every to close down.”

It added these messages over time may expose the blockchain to a 51% assault the place an attacker controls the vast majority of the community’s mining hash charge or staked tokens to make a brand new model of the blockchain or take it offline.

Different zero-day vulnerabilities it discovered would enable potential attackers to crash blockchain nodes by sending Distant Process Name (RPC) requests — a protocol permitting a program to speak and request providers from one other.

It added the probability of RPC-related exploits was decrease because it requires legitimate credentials to undertake the assault.

“Resulting from codebase variations between the networks not all of the vulnerabilities are exploitable on all of the networks, however at the least one in all them could also be exploitable on every community,” Halborn warned.

Associated: Leap Crypto and Oasis.app ‘counter exploits’ Wormhole hacker for $225M

The agency stated right now it’s not releasing additional technical particulars of the exploits because of their severity and added it made a “good religion effort” to contact all affected events to reveal the potential exploits and supply remediation for the vulnerabilities.

Dogecoin, Zcash and Litecoin have already applied patches for the found vulnerabilities, however a whole bunch may nonetheless be uncovered, in keeping with Halborn.

Source link

Subscribe to our mailing list to receive new updates and special offers

We don’t spam! Read our [link]privacy policy[/link] for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
You have not selected any currencies to display