Security firm dWallet Labs flags validator vulnerability that could affect $1B in crypto

Share This Post

Validator service provider InfStones disagreed and told Cointelegraph that “nothing close to $1 billion in assets would be at risk,” even in the worst-case scenario.

Blockchain security firm dWallet Labs recently disclosed a vulnerability that they claim could affect up to $1 billion worth of crypto, with assets such as Ether (ETH), Aptos (APT), BNB (BNB) and Sui (SUI) at risk.

In a paper sent to Cointelegraph, dWallet Labs reported a potential vulnerability in validators hosted by an infrastructure provider called InfStones. According to dWallet Labs, they started a research paper on attacking blockchain networks and collecting private keys with Web2 attacks. During this research, dWallet Labs said, they discovered vulnerabilities in InfStones validators. They wrote:

“A chain of vulnerabilities we discovered and exploited during our research allowed us to gain full control, run code and extract private keys of hundreds of validators on multiple major networks, potentially leading to direct losses equivalent to over one billion dollars in cryptocurrencies such as ETH, BNB, SUI, APT and many others.” 

According to dWallet Labs, an attacker who exploits the vulnerability can acquire the private keys of validators across different blockchain networks. “Over one billion dollars of staked assets were staked on all of these validators, and such an attacker would have been able to gain full control of all of them,” they added. 

Related: Exploits, hacks and scams stole almost $1B in 2023: Report

On Nov. 21, InfStones responded to Cointelegraph’s request for comment, denying that the bug could affect $1 billion in assets. Darko Radunovic, a representative from InfStones, told Cointelegraph that the potential vulnerability could only affect a small fraction of the live nodes they’ve already launched.

According to Radunovic, the potential vulnerability was discovered in 237 instances, including 212 cases designated for testing and 25 instances as freshly launched nodes in the production environment. “The instances identified in production constitute a fraction below 0.1% of the live nodes we have launched to date,” Radunovic said in a statement. The company also published a blog post saying the vulnerability was resolved.

Radunovic also highlighted that in response to the vulnerability, they’ve done internal reviews and had an accredited security firm audit their systems and company policies. The company also launched a bug bounty program to encourage any third party to work with them directly on any bugs they may find. 

Magazine: $3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Infomon Blends Pokémon Go With NFTs and X Integration

Imagine Pokémon Go but with NFT ownership, token rewards, and social media integration—welcome to Infomon, a revolutionary Web3 game that brings AR to the blockchain Quick Recap from OpenSeason

Bitcoin $178K Target In Sight? Analyst Highlights Bollinger Band Retest Mirroring Jan. 2024 Rally

Bitcoin has been on a correction path since it reached a new all-time high of $108,135 on December 17 Notably, this correction has seen the leading cryptocurrency decline by about 10% up until the

‘$600M Would Buy a Lot of Bitcoin’: Microstrategy Boss Steers Bezos Wedding Drama Toward Crypto

Michael Saylor, co-founder and executive chairman of Microstrategy, brought bitcoin into the spotlight during an online exchange with Jeff Bezos on X The Amazon founder found himself in the headlines

El Salvador Reinforces Bitcoin Allegiance: Purchases BTC in Defiance of IMF Agreement

The government of El Salvador has clarified that it will continue pushing bitcoin as part of its economic strategy, even as it inked an agreement with the IMF to wind down its bitcoin operations El

XRP Historic Moment Coming In 2025? This Crypto Exchange Believes So

In the cryptocurrency space, XRP is gaining much attention, and many people are making predictions regarding its prospects for 2025 Bitstamp, a cryptocurrency exchange, excites investors with its

Stablecoin Frenzy: USDE Nears $6B as USD0 Rockets Past $1B in Market Supply

Over the past month, the stablecoin market has swelled over $200 billion, and two fiat-backed tokens have experienced eye-catching expansions Ethena’s yield-generating stablecoin, USDE, has