Langsung ke konten utama

Axie Infinity Loses $620 Million After Hacker Compromised Ronin Validators

Axie Infinity Loses $620 Million After Hacker Compromised Ronin Validators

According to Sky Mavis, the creators of the blockchain NFT game Axie Infinity, the Ronin network has been attacked, and a hacker has managed to siphon 173,600 in ethereum and 25.5 million usd coin (USDC). The attacker has obtained roughly $620 million worth of crypto assets, and the Ronin bridge and Katana Dex have been paused.

The Largest NFT Blockchain Game Axie Infinity Suffers From a $620 Million Hack

The largest non-fungible token (NFT) blockchain game, Axie Infinity, has suffered from an attack on Tuesday after the Ronin network validators were compromised. Sky Mavis, the company behind the Axie Infinity project, explained that the validators were compromised as early as March 23.

The funds were drained in two transactions (transaction 1 and transaction 2) and Sky Mavis discovered the attack after a user complained that they could not withdraw 5,000 ether from the Ronin bridge.

“The attacker used hacked private keys in order to forge fake withdrawals,” Sky Mavis’s post mortem statement discloses. While the Ronin bridge and Katana Dex has been halted, Sky Mavis also said: “We are working with law enforcement officials, forensic cryptographers, and our investors to make sure all funds are recovered or reimbursed. All of the AXS, RON, and SLP on Ronin are safe right now.”

The team further explained that the project uses nine validator nodes to run Ronin, and in order to deposit or withdraw, five out of nine are needed to process a transaction.

“The attacker managed to get control over Sky Mavis’s four Ronin Validators and a third-party validator run by Axie DAO,” Sky Mavis said. “The validator key scheme is set up to be decentralized so that it limits an attack vector, similar to this one, but the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator.”

What’s worse is that Sky Mavis notes that the attacker got away with it because of a change made back in November 2021, and they discontinued the “Axie DAO allowlisted” scheme the very next month.

However, the “allowlist access was not revoked” the team said, and Sky Mavis added that “once the attacker got access to Sky Mavis systems they were able to get the signature from the Axie DAO validator by using the gas-free RPC.” Sky Mavis’s post mortem continued:

We have confirmed that the signature in the malicious withdrawals match up with the five suspected validators.

The attack against Ronin is one of the largest hacks against a crypto protocol this year, as it surpassed the attack against the Wormhole bridge. That specific attack against the Wormhole bridge saw the loss of $320 million, but the funds were replaced by Jump Crypto. Sky Mavis explained on Tuesday that the team is working with law enforcement in order to “ensure the criminals get brought to justice.”

Moreover, the team is in the process of discussing with stakeholders and talking about how to make sure users are compensated. “Sky Mavis is here for the long term and will continue to build,” the team’s post mortem concludes.

What do you think about Axie Infinity losing $620 million to someone who found a validator exploit? Let us know what you think about this subject in the comments section below.



source https://news.bitcoin.com/axie-infinity-loses-620-million-after-hacker-compromised-ronin-validators/

Komentar

Postingan populer dari blog ini

Spanish Treasury Secretary Says Cryptocurrencies Carry a ‘Risk of Default’, Repeats Bank of Spain’s Lack of Regulation Rhetoric

The government of Spain continues to harden its stance against widely adopting cryptocurrencies. The Spanish Secretary of State for the Economy recently expressed her concerns on risks that she thinks cryptos possess for the national economy. Secretary Doesn’t Like Bitcoin as It Cannot Be ‘Supervised or Sanctioned’ During the Online Fintech Summit 2021 , Ana de la Cueva said that cryptocurrencies such as bitcoin ( BTC ) carry “a risk of default, given that the user does not have the protection offered by traditional payment systems against a default by the counterparty.” In fact, the Secretary blasted off on the lack of a “centralized guarantee system” in bitcoin. Interestingly, at the beginning of her speech, De La Cueva mentioned that the cryptocurrency’s technology is based on blockchain. However, she later pointed out that there is no standard “clarity” on the nature of bitcoin. The Secretary repeated the same rhetoric of Spanish state entities on crypto assets, saying that th...

Barry Silbert Resigns as Chairman of Grayscale Investments

Digital Currency Group (DCG) founder Barry Silbert has resigned from his position as the chairman of Grayscale Investments. Current DCG chief financial officer Mark Shifke succeeds Silbert and is joined by Edward McGee and Matthew Kummell as members of the new look board. Preparing for Grayscale’s Next Chapter Barry Silbert, the founder and CEO of Digital Currency Group, has resigned from his position as chairman of the digital asset management company Grayscale and will be replaced by Mark Shifke. According to the company’s filing with the Securities and Exchange Commission (SEC), starting Jan. 1, 2024, Grayscale’s board will be composed of Mark Shifke, Matthew Kummell, and Edward McGee. Current Grayscale Investments CEO Michael Sonnenshein is also a board member, while Mark Murphy, the president of Digital Currency Group (DCG), departs alongside Silbert. Commenting on the changes to the board, an unidentified Grayscale spokeswoman reportedly said: “Grayscale and our investors ...

48 US Lawmakers Ask SEC Chair Gensler to Clarify Whether ETH Is a Security — Warn of ‘Negative Repercussions’

Forty-eight U.S. lawmakers have sent a letter to U.S. Securities and Exchange Commission (SEC) Chairman Gary Gensler asking him to clarify whether ether is a security. “The negative repercussions of the SEC implicitly or directly classifying ETH as a digital asset security will cascade throughout the digital asset marketplace both in the short and long […] source https://news.bitcoin.com/48-us-lawmakers-ask-sec-chair-gensler-to-clarify-whether-eth-is-a-security-warn-of-negative-repercussions/