Dude, it’s crazy how these exploits are popping up everywhere, right? From exchanges to DeFi and bridges, innovation just makes it easier for hackers.
KelpDAO, the Echo eBTC exploit, and now the H tokens mess. Anyone catch that news yesterday? Just found out that the compromise happened through three out of six Gnosis Safe keys controlling the Hyperlane bridge. Almost $36 million vanished. Pretty wild stuff.
New Exploits and Minting Scams Shaking Crypto World
15 replies 385 views
Is there even a way to tell if this has been used before? I doubt it.
From what I’ve heard, serious audits are needed to figure out actual supply, but honestly, the chance that someone spotted this flaw before seems slim.
I can’t say for sure if new ZEC has been minted. Just sharing what I know about the vulnerability. No solid explanation yet.
Zcash devs claim they found no signs of exploitation, but who knows? Could be lies or bribes, though I doubt that.
Exactly, don’t just take their word for it.
Zcash devs’ statements won’t clear the air around this coin. We need an independent audit from a reputable firm to really put those concerns to rest.
pix3l_h4shNewbie
Posts: 62 · Reputation: 22
#5Nov 19, 2017, 04:47 AM
Actually, it was $36 million worth of H tokens, not a typo.
As I’ve always said, new bridges and protocols can make projects super vulnerable to attacks. It’s never just random; someone has to open back doors. Those three laptops from the staff were the gateway for accessing H tokens.
What’s interesting about these attacks is the security failure key takeovers and draining wallets. But for H tokens, no new minting reports yet.
Only $36?
I’m pretty sure that’s a typo. Bridges and protocols on BSC that haven’t had proper audits are a goldmine for hackers. Heard a guy explain exploitation methods recently, and I think there are actually way more hacks happening than the media covers.
If you quote me next time like JeromeTash did, it'd be awesome, but hey, you still get a merit for the fix. Got the notification when you quoted me.
Yeah, it was a typo; it’s corrected now. Appreciate it.
ZEC developers have been doing detailed checks and found no new ZEC minted from that bug. They’ve patched it up to prevent a repeat.
If new ZEC was minted, I think it’d be dumped on the market already.
pix3l_h4shNewbie
Posts: 62 · Reputation: 22
#9Nov 19, 2017, 04:54 PM
True, that’s how it should work. But I know you’d fix the typo even if I hadn’t quoted you.
You always check your posts. Anyway, latest news on H coin shows no new coins minted, just some hot wallet keys compromised.
There’s a proposed improvement for users to verify Zcash in the Orchard pools.
Seems like this hasn’t been implemented yet though, just a quick emergency patch. Let’s hope it can detect any excess Zcash supply that’s been hidden. Some people mentioned that verification could be tricky.
chris_maxiNewbie
Posts: 85 · Reputation: 36
#11Nov 20, 2017, 07:05 AM
Bigger question is: why the heck do tokens even have minting mechanisms in the first place?
The H case is bizarre since you can literally mint tokens from thin air just by accessing the private key. Seems ridiculous to me. Should we really trust tokens with minting abilities?
f0rk_5tackNewbie
Posts: 47 · Reputation: 3
#12Nov 20, 2017, 08:40 AM
It’s not three laptops but three keys from the same laptop that were compromised, giving total control to the attacker. Three out of six multisig keys on BNB chain and one admin wallet also compromised.
That’s just pure incompetence on the admins’ part. No hardware wallets, and the key control was poorly handled. Total failure.
Glad you noticed. I edited to clarify: three of six Gnosis Safe keys for Hyperlane were indeed compromised along with three of five on BSC.
If the keys were on one laptop, that’s a colossal blunder.
chris.viperMember
Posts: 93 · Reputation: 213
#14Nov 20, 2017, 01:56 PM
Seriously, people with just 0.01 BTC never store their seed phrases on a laptop, yet a project worth millions keeps three private keys on a laptop?
That's seriously sketchy to me.
RogueShardMember
Posts: 11 · Reputation: 220
#15Nov 21, 2017, 01:58 AM
Right? It was thought this only happened with NFTs. But we can't be sure. Maybe it’s a new trend in crypto?
New stuff is bound to have bugs, hacks, and exploits. We see loads of news on them right now. Maybe as things mature, we can expect better security. But a crypto private key is like an actual key in real life; if you lose it, you’re done.
chris_maxiNewbie
Posts: 85 · Reputation: 36
#16Nov 22, 2017, 05:43 PM
Minting in their token contract is fine if they don’t set a total supply on sites like CMC or Coingecko, which suggests a fixed supply.
But these tokens are super shady, especially this one. Yet there’s still a trading volume of $77 million? That’s just ridiculous.