• bitcoinBitcoin (BTC) $ 66,171.00
  • ethereumEthereum (ETH) $ 1,759.78
  • tetherTether (USDT) $ 0.999324
  • bnbBNB (BNB) $ 621.13
  • xrpXRP (XRP) $ 1.23
  • usd-coinUSDC (USDC) $ 0.999755
  • solanaSolana (SOL) $ 72.63
  • tronTRON (TRX) $ 0.320544
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • hyperliquidHyperliquid (HYPE) $ 68.15
  • dogecoinDogecoin (DOGE) $ 0.089776
  • usdsUSDS (USDS) $ 0.999703
  • leo-tokenLEO Token (LEO) $ 9.80
  • zcashZcash (ZEC) $ 534.38
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • rainRain (RAIN) $ 0.013534
  • cardanoCardano (ADA) $ 0.184985
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.194715
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 345.35
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.166707
  • whitebitWhiteBIT Coin (WBT) $ 54.02
  • chainlinkChainlink (LINK) $ 8.42
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.79
  • bitcoin-cashBitcoin Cash (BCH) $ 223.88
  • ethena-usdeEthena USDe (USDE) $ 0.999418
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • daiDai (DAI) $ 0.999715
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.92
  • hedera-hashgraphHedera (HBAR) $ 0.082094
  • litecoinLitecoin (LTC) $ 45.94
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.812791
  • nearNEAR Protocol (NEAR) $ 2.47
  • labLAB (LAB) $ 9.97
  • usdt0USDT0 (USDT0) $ 0.998824
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • avalanche-2Avalanche (AVAX) $ 6.93
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • crypto-com-chainCronos (CRO) $ 0.062456
  • paypal-usdPayPal USD (PYUSD) $ 0.999681
  • global-dollarGlobal Dollar (USDG) $ 0.999873
  • bittensorBittensor (TAO) $ 278.43
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • tether-goldTether Gold (XAUT) $ 4,323.18
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • worldcoin-wldWorldcoin (WLD) $ 0.618207
  • pax-goldPAX Gold (PAXG) $ 4,333.34
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.060936
  • mantleMantle (MNT) $ 0.582885
  • ondo-financeOndo (ONDO) $ 0.385098
  • polkadotPolkadot (DOT) $ 1.02
  • aster-2Aster (ASTER) $ 0.638371
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • uniswapUniswap (UNI) $ 2.68
  • ripple-usdRipple USD (RLUSD) $ 0.999930
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • okbOKB (OKB) $ 77.08
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.995458
  • pi-networkPi Network (PI) $ 0.135395
  • internet-computerInternet Computer (ICP) $ 2.58
  • usddUSDD (USDD) $ 0.999432
  • skySky (SKY) $ 0.056961
  • bfusdBFUSD (BFUSD) $ 0.998907
  • morphoMorpho (MORPHO) $ 2.00
  • bitget-tokenBitget Token (BGB) $ 1.81
  • pepePepe (PEPE) $ 0.000003
  • audieraAudiera (BEAT) $ 4.30
  • ethereum-classicEthereum Classic (ETC) $ 7.40
  • aaveAave (AAVE) $ 74.08
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • cosmosCosmos Hub (ATOM) $ 2.00
  • quant-networkQuant (QNT) $ 69.56
  • united-stablesUnited Stables (U) $ 0.999801
  • kucoin-sharesKuCoin (KCS) $ 7.25
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.96
  • render-tokenRender (RENDER) $ 1.86
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.11
  • usdtbUSDtb (USDTB) $ 1.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.033137
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • dexeDeXe (DEXE) $ 18.76
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • algorandAlgorand (ALGO) $ 0.095655
  • stable-2​​Stable (STABLE) $ 0.035198
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.078019
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • nexoNEXO (NEXO) $ 0.815664
  • ethenaEthena (ENA) $ 0.087689
  • venice-tokenVenice Token (VVV) $ 16.24
  • humanityHumanity (H) $ 0.404211
  • gatechain-tokenGate (GT) $ 6.88
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.697059
  • flare-networksFlare (FLR) $ 0.008049
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • justJUST (JST) $ 0.077176
  • filecoinFilecoin (FIL) $ 0.819467
  • beldexBeldex (BDX) $ 0.081911
  • jupiter-exchange-solanaJupiter (JUP) $ 0.189618
  • xdce-crowd-saleXDC Network (XDC) $ 0.030797
  • ghoGHO (GHO) $ 0.999051
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • aptosAptos (APT) $ 0.694702
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • pump-funPump.fun (PUMP) $ 0.001623
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • yldsYLDS (YLDS) $ 0.999721
  • usual-usdUsual USD (USD0) $ 0.998546
  • midnight-3Midnight (NIGHT) $ 0.033270
  • clbtcclBTC (CLBTC) $ 76,920.00
  • arbitrumArbitrum (ARB) $ 0.088169
  • injective-protocolInjective (INJ) $ 5.45
  • hash-2Provenance Blockchain (HASH) $ 0.009618
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • a7a5A7A5 (A7A5) $ 0.013148
  • usxUSX (USX) $ 0.999441
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • dashDash (DASH) $ 39.56
  • true-usdTrueUSD (TUSD) $ 0.998442
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.217147
  • tbtctBTC (TBTC) $ 70,942.00
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.55
  • official-trumpOfficial Trump (TRUMP) $ 2.03
  • adi-tokenADI (ADI) $ 3.73
  • kite-2Kite (KITE) $ 0.197752
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.40
  • euro-coinEURC (EURC) $ 1.16
  • vechainVeChain (VET) $ 0.005222
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007151
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.658469
  • bonkBonk (BONK) $ 0.000005
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • lighterLighter (LIT) $ 1.70
  • apxusdapxUSD (APXUSD) $ 0.962433
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • hastra-primePRIME (PRIME) $ 1.04
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000073
  • aerodrome-financeAerodrome Finance (AERO) $ 0.412450
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • sei-networkSei (SEI) $ 0.055773
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • the9bitThe9bit (9BIT) $ 0.045092
  • curve-dao-tokenCurve DAO (CRV) $ 0.240846
  • blockstackStacks (STX) $ 0.196748
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997771
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • celestiaCelestia (TIA) $ 0.362979
  • kinesis-goldKinesis Gold (KAU) $ 140.35
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • sun-tokenSun Token (SUN) $ 0.017053
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • skyaiSkyAI (SKYAI) $ 0.331254
  • spx6900SPX6900 (SPX) $ 0.344339
  • pyth-networkPyth Network (PYTH) $ 0.040658
  • ethgas-2ETHGas (GWEI) $ 0.148724
  • jito-governance-tokenJito (JTO) $ 0.632889
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ether-fiEther.fi (ETHFI) $ 0.345682
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • unibaseUnibase (UB) $ 0.120684
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • gnosisGnosis (GNO) $ 110.18
  • grassGrass (GRASS) $ 0.465614
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • layerzeroLayerZero (ZRO) $ 1.11
  • zebec-networkZebec Network (ZBCN) $ 0.002830
  • kinesis-silverKinesis Silver (KAG) $ 70.69
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • monadMonad (MON) $ 0.022559
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • chilizChiliz (CHZ) $ 0.025469
  • apenftAINFT (NFT) $ 0.00000027
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • jasmycoinJasmyCoin (JASMY) $ 0.005362
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Humanity’s $36 million exploit tied to compromised laptop hosting a ‘multisig’ wallet

0 0


Humanity Protocol explained how attackers were able to steal more than $36 million of its H token, and the cause was a serious lapse in how it secured its keys.

In an incident update shared with CoinDesk, the decentralized identity project said the breach started when an employee’s laptop was compromised. The machine held several keys that controlled the project’s token bridges, the tools that move H (and other tokens) between blockchains.

Those bridges ran through multisignature wallets, which require a number of separate keys to approve any change. A multisignature wallet is supposed to spread keys across different people and devices so that no single machine can move funds.

In this case, all the keys were stored on a single device, meaning a compromise allowed the exploier to cross the approval threshold on both chains, Humanity said.

The attacker obtained three of the six keys controlling the bridge’s admin account on Ethereum, enough to seize controls linked to the project’s deployment on the network.

The attacker then transferred ownership to their own wallet, swapped the bridge’s code for a malicious version and drained about 141 million H in one transaction.

In a Telegram message to CoinDesk, Humanity founder Terence Kwok said the team had set up a multisig wallet across four individuals (as it should have).

Humanity suspects that “some of the keys were accidentally backed up to a compromised device during setup,” Kwok said. “We use a licensed custodian for the majority of token treasury, mpc for operations treasury, and for certain contracts multisig keys were set up in one place and then dispersed.

“Unfortunately in this scenario, the keys were backed up on a compromised device,” he said.

The attacker executed similar steps on BNB Chain with three of five keys. This time, installing code with an unlimited mint function, which allowed the creation of tokens at will, and minted about 200 million new H straight to their wallet.

Humanity has since removed the team page from its website. The project said it has halted deposits and withdrawals on the affected bridges and is working with exchanges and the police to recover funds.

Humanity raised $20 million from Pantera Capital and Jump Crypto last year at a $1.1 billion valuation.

ZachXBT, a prominent onchain investigator, said the key compromise and a separate round of suspicious market-making in the token were not connected.

He also raised questions about how the token traded in the weeks before the breach, ahead of a large scheduled token unlock, as H token prices shot up from 20 cents to 70 cents within two weeks.

The token has clawed back some of the lost ground. After falling as low as about 5 cents during the attack, it recovered to around 20 cents, according to CoinGecko data. It remains well below the roughly pre-breach level of 67 cents.



Source link

Leave A Reply

Your email address will not be published.