SlowMist: 2019 Blockchain Security Major Events Summary (Released in 2019)
In 2019, the blockchain industry developed rapidly, and concepts such as centralized exchanges/decentralized exchanges, DApp, Staking, CeFi/DeFi, and Web3.0 gradually became familiar, and the influx of large amounts of funds continued to attract the attention of underground hackers Transfer to the blockchain industry. According to statistics from the hacked archives of SlowMist blockchain (hacked.slowmist.io), there were more than 130 security incidents in the blockchain industry in 2019, with a cumulative loss of more than US$5 billion. Hackers attack hardest hit areas.
SlowMist will use this article to sort out the major events that occurred in the blockchain security and privacy ecology in 2019, review the details of the events for readers, and attach SlowMist’s views on each event. Although the list in this article is only the tip of the iceberg, it is very representative.
№1 ETC suffered a 51% attack
Event date: 2019–01–05
Event description:
On the afternoon of January 5th, the ETC block with a height of 7245623 changed. On January 7th, the SlowMist security team disclosed that a 51% attack was suspected to have occurred on ETC, and many blocks were rolled back. During the period, the ETC network suffered at least 11 suspected double-spending attacks, and lost about $460,000 worth of ETC. On January 8, the Gate.io Research Institute announced that it had confirmed that the ETC network had suffered a 51% attack and located the attacker’s ETC address.
SlowMist’s view:
When double-spending attacks become common, the public chain needs to prevent and control double-spending attacks as part of the risk control mechanism. As a participant in the cryptocurrency ecosystem, preventing double-spending attacks may not only be the responsibility of the public chain. Exchanges, wallets, and investors all need to be more vigilant.
№2 Cryptopia goes bankrupt after attack
Event date: 2019–01–14
Event description:
On January 14, the New Zealand cryptocurrency exchange Cryptopia was hacked. Hackers stole a total of $16 million worth of Ethereum and ERC20 tokens, and then suspended its platform services. The police then became involved in the investigation into the hack, and the Cryptopia exchange was unable to continue operating. In May, the Cryptopia exchange announced it was shutting down and filed for bankruptcy protection, owing creditors more than $2.7 million.
SlowMist’s view:
The hacking of Cryptopia became the first “thief” of the exchange in the new year of 2019. Underground hackers shifted the focus of their attacks to cryptocurrency exchanges, and the offensive and defensive battlefields on the cryptocurrency exchange side began to heat up. Following the development of the cryptocurrency ecology, underground professional hackers have stepped into the world of blockchain attack and defense.
№3 Many EOS DApps have encountered transaction exclusion attacks
Event date: Starting January 2019
Event description:
In the early hours of January 11, 2019, EOS.WIN was hacked. The attackers of EOS.WIN are using a new attack method called “transaction crowding attack”, which is the same attack method as the previous attack method on bocai.game. The attacker first initiates a normal transfer transaction, and then uses another contract account to detect the winning behavior. If you don’t win, a large number of defer transactions will be initiated to “squeeze” the project party’s lottery transactions into the next block. This type of attack originates from the use of time seeds in the random number algorithm of the project side, which increases the chance of winning the prize for the attacker, resulting in the success of the attack.
SlowMist’s view:
There is no perfect random number scheme on the blockchain. As long as variables on the chain are used as random number factors, there is a possibility of being hacked. It is recommended that developers adopt the random number security practice “Randomization in Contracts” officially recommended by EOS, or introduce oracles. At the same time, a risk control mechanism is added to the contract design, for example, the transfer of a large amount of the prize pool exceeds a certain threshold and is automatically suspended.
№4 DragonEx was hacked and lost more than $6 million
Event date: 2019–03–24
Event description:
The cryptocurrency exchange DragonEx announced that the platform wallet was hacked, resulting in the theft of digital assets of users and the platform, involving more than 20 mainstream digital assets such as BTC, ETH, EOS, XRP, and TRX, with a total loss of more than 6 million US dollars.
SlowMist’s view:
After the attack, many security companies at home and abroad confirmed that the incident was done by the hacker organization Lazarus. By operating and simulating normal quantitative software, the organization lures the exchange’s high-level executives to use it with high profits and high returns through the exchange’s external customer service. There are hidden backdoors in the quantified software. Once the software is delivered to the computer of a key person, a series of infiltration and hacking actions will be carried out. With the development of cryptocurrencies, the hacker organization Lazarus has become more and more interested in cryptocurrencies, and there are more and more hacker attacks, showing the nature of APT (Advanced Persistent Threat). Only when the exchange itself takes protective measures can hackers no longer take advantage of it.
№5 Three million EOS and 20 million XRP stolen from Bithumb
Event date: 2019–03–29
Event description:
On March 29, South Korean cryptocurrency exchange Bithumb admitted to being hacked. A manager said that at around 10:15 p.m. local time on March 29, an abnormal withdrawal from the hot wallet was detected. Hackers stole about 3 million EOS, worth about $13.4 million, and 20 million XRP, worth $6 million. As early as June 2018, the exchange lost $31 million worth of cryptocurrencies due to hacking attacks. In less than a year, Bithumb has been hacked twice in succession.
SlowMist’s view:
The second attack on the cryptocurrency exchange may also be the crime committed by the insider. Indeed, in the face of the magic power of money, human nature cannot stand the test, and the internal security risk control construction work of many exchanges is too lacking, which has prompted the inside ghosts to have enough motivation to commit crimes, resulting in the exchange being stolen.
№6 7,074 bitcoins stolen from Binance
Event date: 2019–05–08
Event description:
On May 8, the cryptocurrency exchange Binance issued a security announcement saying that at 17:15:24 on May 7, hackers stole 7,074 bitcoins (worth about $40 million) from the Binance hot wallet.
SlowMist’s view:
Underground professional hackers through advanced phishing and Trojan horse implantation, penetrated layer by layer and finally obtained the private key authority of the exchange, resulting in the theft of coins from the cryptocurrency exchange. In the face of the offensive of the underground professional hacker army, the security defense of the exchange side is extremely weak. The exchange can conduct in-depth cooperation with a credible and professional security team, deploy security recommendations tailored to local conditions, and approach the world with an untrustworthy mentality by default.
№7 TokenStore takes away billions of assets from users
Event date: 2019–06–10
Event description:
On May 31, TokenStore announced that due to hacker attacks, the system will be fully upgraded and maintained for 10 days, and emphasized that no matter what happens, the platform will continue to operate. On June 10, many users in the community reported that TokenStore was suspected of running away 10 days after the upgrade announcement was released, and billions of investors’ funds were swept away.
SlowMist’s view:
There are so many tricks… These projects are often packaged with terms such as “high-yield” and “the latest blockchain technology”, but they are actually Ponzi schemes. Distinguish carefully and refrain from participating.
№8 PlusToken Takes About $2 Billion in Cryptocurrencies
Event date: 2019–06–27
Event description:
On the evening of June 27, some investors found that their PlusToken wallets could not be withdrawn, and many people encountered the same problem. Someone found that in the past, the cash withdrawal time was as little as 10 minutes and as long as 3 hours. There has been no response for several days in a row, and the app cannot be logged in, and the customer service is not online. It was later confirmed that PlusToken ran away, and the scam absorbed more than $2 billion worth of cryptocurrencies, including 180,000 BTC, 6,400,000 ETH, 111,000 USDT, etc.
SlowMist’s view:
PlusToken is the one with the largest amount of money involved and the most victimized users among similar fund projects, which has brought serious negative effects to the blockchain ecology. The SlowMist AML system has continuously tracked and traced the on-chain transactions of the PlusToken wallet. From the statistical data, it is found that most of the cryptocurrencies have been cleaned by using Mixer (mixer), KYC-free currency exchange platform, and then Convert to legal currency and leave the market.
№9 Bitrue Stolen 9.3 Million XRP
Event date: 2019–06–27
Event description:
At 1 a.m. on June 27, Bitrue, an encrypted asset exchange headquartered in Singapore, suffered a major hack. Its hot wallet lost 9.3 million XRP and 2.5 million ADA. The stolen XRP and ADA were worth more than $4.5 million and $237,500.
SlowMist’s view:
Bitrue officials stated that hackers used the loopholes in the risk control system to access users’ personal funds and Bitrue hot wallets, and then steal coins. Due to the lack of security awareness of the exchange’s internal personnel, system flaws that should not have been exposed were exposed, giving underground hackers an opportunity to steal coins. There is an obvious gap between attack and defense in the blockchain world, so the defense capabilities of most exchanges are not enough to resist the invasion of professional underground hackers. The construction of a security system is very complicated, and the defense work needs to be comprehensive, but the intrusion work can be broken through at a single point.
№10 BitPoint stolen worth about $32 million
Event date: 2019–07–11
Event description:
Bitpoint was hacked on July 11. Hackers attacked the exchange’s hot and cold wallets and stole about $32 million worth of bitcoin, bitcoin cash, litecoin, ripple and ethereum, with about $23 million in digital currencies belonging to the exchange user. BitPoint said the number of victims was close to half of the exchange’s total users, as many as 50,000. The exchange said it would cover all losses from users.
SlowMist’s view:
Two-thirds of the stolen funds belonged to customers, and the Financial Services Agency lost face. Although the method has not been made public, it does not rule out APT-type attacks. Underground hacker attacks are becoming more and more intense, and the security defense of cryptocurrency exchanges is facing new challenges.
№11 Third-party issues lead to platform attacks
Event date: July 2019
Event description:
On July 5, the NPM official blog published an article saying that the NPM security team worked with Komodo to discover and stop malicious poisoning threats targeting all users of the cryptocurrency wallet named Agama. The attackers placed malicious packages into Agama’s build chain, using this technique to steal wallet private keys and other login passwords used in the wallet app.
SlowMist’s view:
In the current technical architecture, third-party JavaScript libraries cannot be separated, and all technical teams of project parties should force at least one core technology to completely review all third-party modules.
№12 BitMEX, Binance User Identity Information Leaked
Event date: August, November 2019
Event description:
On November 1, 2019, when BitMEX sent platform email notifications, the email addresses of all recipients of the email were leaked because they did not adopt the BCC setting. Afterwards, a researcher tweeted that more than 23,000 email addresses had been collected.
Binance user KYC data leakage occurred in August 2019. Someone publicly released Binance user KYC data through the Telegram group “FIND YOUR BINANCE KYC”. No, the picture does not have a Binance-specific electronic watermark, and it cannot be proved that it is from Binance.
SlowMist’s view:
User identity information should be highly encrypted and protected, and the platform should implement this strategy in the early architecture design to avoid such sensitive information leakage incidents.
№13 342,000 ETH stolen from Upbit
Event date: 2019–11–27
Event description:
South Korean exchange Upbit announced that 342,000 ETH was stolen and transferred to an unknown ETH address (0xa098…029), with a total value of about $50 million. Previously, according to the on-chain data monitored by WhaleAlert, Upbit frequently transferred large amounts of cryptocurrencies, including SNT, EOS, OMG, XLM, TRX, ETH, etc., with a total value of more than 100 million US dollars. Then the official announcement clarified that only ETH was stolen by hackers, and the rest of the assets were transferred to the cold wallet by the exchange itself for safety.
SlowMist’s view:
At present, it is suspected that it is related to APT (Advanced Persistent Threat) attack. The characteristic of this attack is long-term latency until it encounters a large amount of money that can be manipulated, and a large sum of money is stolen at one time. Of course, the possibility of ghosts cannot be ruled out. What was stolen was Upbit’s ETH hot wallet, and the cold wallet should be risk-free.
In 2019, a large number of security incidents occurred in the exchange field, and each of them caused huge losses. SlowMist has deep experience in the security attack and defense of exchanges. We concluded that there are mainly the following attack methods:
1. The inner ghost commits the crime. Indeed, in the face of the magic power of money, human nature cannot stand the test, and the internal security risk control construction work of many exchanges is too lacking, which has prompted the insiders to have enough motivation to commit crimes, resulting in stolen coins;
2. False top-up vulnerability attack. Some exchanges have insufficient security experience on the various public chains or tokens that are docked, resulting in fake funds in the recharge process, but the exchange system thinks it is real, resulting in stolen coins;
3. APT attack. Professional underground hackers through advanced phishing and Trojan horse implantation, infiltrated layer by layer and finally obtained the private key authority of the exchange, resulting in stolen coins;
4. Supply chain attacks. The third-party components used by the exchange were hacked and implanted with malicious code, which indirectly affected the security defense of the exchange and resulted in stolen coins;
5. Careless. Due to the lack of security awareness of the exchange’s internal personnel, system flaws that should not have been exposed were exposed, giving underground hackers an opportunity to steal coins.
From the perspective of these main attack methods, two main features can be summarized:
1. Evil human nature and lack of safety awareness and safety experience of internal personnel;
2. The gap between attack and defense is obvious, so the defense capabilities of most exchanges are not enough to resist the invasion of professional underground hackers.
About SlowMist
SlowMist is a blockchain security firm established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as Huobi, OKX, Binance, imToken, Crypto.com, Amber Group, Klaytn, EOS, 1inch, PancakeSwap, TUSD, Alpaca Finance, MultiChain, O3Swap, etc.
Website:
https://www.slowmist.com
Twitter:
https://twitter.com/SlowMist_Team
Github:
https://github.com/slowmist/
