Cybersecurity & Co. πŸ‡ΊπŸ‡¦
6.84K subscribers
269 photos
11 videos
3 files
522 links
Aleksandr Litreev about cybersecurity, blockchain & other joys of life.

litreev.com
Download Telegram
Forwarded from SOLAR Labs
Meet #MNEMOGATE. Exposed wallets in Cosmos-based blockchains.

Recently, our joint investigation team SOLAR Labs & MightyFrog found out that there’s a relatively easy way to lose your tokens due to confusing naming of transaction parameters in Cosmos-based blockchains. Some of the users put their mnemonics (wallet private key, in other words) into publicly visible MEMO of transactions, which is basically acting like more a "note" for a transaction.

Our team made some efforts to take situation under control and save inattentive people's tokens:

1) First of all, we've introduced a website to check if your wallet was exposed. We've scanned Cosmos, Persistence, CertiK, Akash & Sentinel blockchain networks and found wallets with tokens of total worth over 1,300,000 U.S. dollars. Go and check if your wallet is compromised.

2) We've delegated most of available tokens of such wallets to reliable validators β€” to make sure no one is able to withdraw them from you without your consent. For Sentinel β€” it's our SOLAR Validator and Amphibious, for other blockchains it's No. #1 validator of the network. Tokens cannot be withdrawn unless unbonded and unbonding period is long enough to take further actions and prepare to protect vulnerable wallets.

3) We're preparing pull requests for wallet apps and etc. to make sure, that MEMO parameter is changed to something less confusing and users are not submitting their mnemonics into it.

We've also introduced a hotline email to provide support to everyone, who were affected by this issue β€” help@wasmywalletleaked.com. Feel free to reach us if you have any questions.

Stay tuned,
Aleksandr Litreev
CEO at Solar Labs

Drink water, wash your hands and keep your mnemonic safe and secret.
Cybersecurity & Co. πŸ‡ΊπŸ‡¦
Meet #MNEMOGATE. Exposed wallets in Cosmos-based blockchains. Recently, our joint investigation team SOLAR Labs & MightyFrog found out that there’s a relatively easy way to lose your tokens due to confusing naming of transaction parameters in Cosmos-based…
ВстрСчайтС #MNEMOGATE. Π‘ΠΊΠΎΠΌΠΏΡ€ΠΎΠΌΠ΅Ρ‚ΠΈΡ€ΠΎΠ²Π°Π½Π½Ρ‹Π΅ кошСльки Π² Π±Π»ΠΎΠΊΡ‡Π΅ΠΉΠ½Π°Ρ… Π½Π° Π±Π°Π·Π΅ Cosmos. ΠŸΠ΅Ρ€Π΅Π²ΠΎΠ΄.

НСдавно наша ΠΈΡΡΠ»Π΅Π΄ΠΎΠ²Π°Ρ‚Π΅Π»ΡŒΡΠΊΠ°Ρ Π³Ρ€ΡƒΠΏΠΏΠ° SOLAR Labs ΠΈ MightyFrog нашла ΠΎΠ΄ΠΈΠ½ ΠΎΡ‡Π΅Π½ΡŒ простой способ ΠΏΠΎΡ‚Π΅Ρ€ΡΡ‚ΡŒ всС ваши Ρ‚ΠΎΠΊΠ΅Π½Ρ‹ ΠΈΠ·-Π·Π° ΠΏΡƒΡ‚Π°ΡŽΡ‰Π΅Π³ΠΎ ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ названия ΠΎΠ΄Π½ΠΎΠ³ΠΎ ΠΈΠ· ΠΏΠ°Ρ€Π°ΠΌΠ΅Ρ‚Ρ€ΠΎΠ² Ρ‚Ρ€Π°Π½Π·Π°ΠΊΡ†ΠΈΠΉ. НСкоторыС ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»ΠΈ ΠΎΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π»ΠΈ свои ΠΌΠ½Π΅ΠΌΠΎΠ½ΠΈΠΊΠΈ (ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹Π΅ ΠΊΠ»ΡŽΡ‡ΠΈ кошСльков, Π΄Ρ€ΡƒΠ³ΠΈΠΌΠΈ словами) Π² ΠΏΠΎΠ»Π΅ MEMO, ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠ΅ слуТит простым "ΠΊΠΎΠΌΠΌΠ΅Π½Ρ‚Π°Ρ€ΠΈΠ΅ΠΌ" ΠΊ Ρ‚Ρ€Π°Π½Π·Π°ΠΊΡ†ΠΈΠΈ ΠΈ доступно всСобщСму ΠΎΠ±ΠΎΠ·Ρ€Π΅Π½ΠΈΡŽ Π² Π±Π»ΠΎΠΊΡ‡Π΅ΠΉΠ½Π΅.

Наша ΠΊΠΎΠΌΠ°Π½Π΄Π° прСдприняла ΠΌΠ΅Ρ€Ρ‹, Ρ‡Ρ‚ΠΎΠ±Ρ‹ Π²Π·ΡΡ‚ΡŒ ΡΠΈΡ‚ΡƒΠ°Ρ†ΠΈΡŽ ΠΏΠΎΠ΄ ΠΊΠΎΠ½Ρ‚Ρ€ΠΎΠ»ΡŒ ΠΈ ΡΠΎΡ…Ρ€Π°Π½ΠΈΡ‚ΡŒ Ρ‚ΠΎΠΊΠ΅Π½Ρ‹ Π½Π΅Π²Π½ΠΈΠΌΠ°Ρ‚Π΅Π»ΡŒΠ½Ρ‹Ρ… ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ:

1) Π’ΠΎ-ΠΏΠ΅Ρ€Π²Ρ‹Ρ…, ΠΌΡ‹ прСдставили сайт, Π½Π° ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠΌ ΠΌΠΎΠΆΠ½ΠΎ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΈΡ‚ΡŒ, скомпромСтирован Π»ΠΈ ваш кошСлСк. ΠŸΡ€ΠΎΡΠΊΠ°Π½ΠΈΡ€ΠΎΠ²Π°Π² сСти Cosmos, Persistence, CertiK, Akash ΠΈ Sentinel, ΠΌΡ‹ нашли кошСльки с Ρ‚ΠΎΠΊΠ΅Π½Π°ΠΌΠΈ ΠΎΠ±Ρ‰Π΅ΠΉ суммой Π±ΠΎΠ»Π΅Π΅ Ρ‡Π΅ΠΌ Π½Π° 1,300,000 Π΄ΠΎΠ»Π»Π°Ρ€ΠΎΠ² БША. ΠŸΡ€ΠΎΠ²Π΅Ρ€ΡŒΡ‚Π΅, Ρ‡Ρ‚ΠΎ ваш кошСлСк Π½Π΅ скомпромСтирован.

2) ΠœΡ‹ Π΄Π΅Π»Π΅Π³ΠΈΡ€ΠΎΠ²Π°Π»ΠΈ Π±ΠΎΠ»ΡŒΡˆΠΈΠ½ΡΡ‚Π²ΠΎ доступных Ρ‚ΠΎΠΊΠ΅Π½ΠΎΠ² Ρ‚Π°ΠΊΠΈΡ… кошСльков Π½Π°Π΄Π΅ΠΆΠ½Ρ‹ΠΌ Π²Π°Π»ΠΈΠ΄Π°Ρ‚ΠΎΡ€Π°ΠΌ сСти. Π­Ρ‚ΠΎ сдСлано для Ρ‚ΠΎΠ³ΠΎ, Ρ‡Ρ‚ΠΎΠ±Ρ‹ Π½ΠΈΠΊΡ‚ΠΎ Π½Π΅ ΠΌΠΎΠ³ ΡΠΏΠΈΡΠ°Ρ‚ΡŒ Ρ‚ΠΎΠΊΠ΅Π½Ρ‹ с Π²Π°ΡˆΠΈΡ… кошСльков Π±Π΅Π· вашСго согласия. Для сСти Sentinel β€” это наш SOLAR Validator ΠΈ Amphibious, Π° для Π΄Ρ€ΡƒΠ³ΠΈΡ… Π±Π»ΠΎΠΊΡ‡Π΅ΠΉΠ½ΠΎΠ² ΠΌΡ‹ Π²Ρ‹Π±Ρ€Π°Π»ΠΈ ВОП-1 Π²Π°Π»ΠΈΠ΄Π°Ρ‚ΠΎΡ€Π° сСти. Π’ΠΎΠΊΠ΅Π½Ρ‹ Π½Π΅ ΠΌΠΎΠ³ΡƒΡ‚ Π±Ρ‹Ρ‚ΡŒ списаны Π΄ΠΎ раздСлСгирования, Π° ΠΏΠ΅Ρ€ΠΈΠΎΠ΄ раздСлСгирования достаточно Π΄ΠΎΠ»Π³ΠΈΠΉ, Ρ‡Ρ‚ΠΎΠ±Ρ‹ ΠΏΡ€ΠΈΠ½ΡΡ‚ΡŒ ΠΌΠ΅Ρ€Ρ‹ ΠΏΠΎ Π΄Π°Π»ΡŒΠ½Π΅ΠΉΡˆΠ΅ΠΌΡƒ спасСнию ΡƒΡ‚ΠΎΠΏΠ°ΡŽΡ‰ΠΈΡ….

3) ΠœΡ‹ ΠΏΠΎΠ΄Π³ΠΎΡ‚ΠΎΠ²ΠΈΠΌ ряд Pull Request'ΠΎΠ² Π² прилоТСния кошСльков, Π΄Π°Π±Ρ‹ ΡƒΠ±Π΅Π΄ΠΈΡ‚ΡŒΡΡ, Ρ‡Ρ‚ΠΎ ΠΏΠ°Ρ€Π°ΠΌΠ΅Ρ‚Ρ€ MEMO ΠΏΠ΅Ρ€Π΅ΠΈΠΌΠ΅Π½ΠΎΠ²Π°Π½ Π²ΠΎ Ρ‡Ρ‚ΠΎ-Ρ‚ΠΎ Π±ΠΎΠ»Π΅Π΅ понятноС ΠΈ Π½ΠΈΠΊΡ‚ΠΎ ΠΈΠ· ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ Π½Π΅ ΠΏΡƒΠ±Π»ΠΈΠΊΡƒΠ΅Ρ‚ свои ΠΌΠ½Π΅ΠΌΠΎΠ½ΠΈΠΊΠΈ Π½Π° всСобщСС ΠΎΠ±ΠΎΠ·Ρ€Π΅Π½ΠΈΠ΅ Ρ‡Π΅Ρ€Π΅Π· Π½Π΅Π³ΠΎ.

Π’Π°ΠΊΠΆΠ΅, запустили "горячий" адрСс эл. ΠΏΠΎΡ‡Ρ‚Ρ‹, ΠΏΠΎ ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠΌΡƒ ΠΏΠΎΠΌΠΎΠ³Π°Π΅ΠΌ Ρ‚Π΅ΠΌ, ΠΊΡ‚ΠΎ пострадал ΠΎΡ‚ этой ΠΏΡ€ΠΎΠ±Π»Π΅ΠΌΡ‹ β€” help@wasmywalletleaked.com. ΠŸΠΈΡˆΠΈΡ‚Π΅, Ссли Ρƒ вас Π΅ΡΡ‚ΡŒ ΠΊΠ°ΠΊΠΈΠ΅-Ρ‚ΠΎ вопросы.

Π‘Π»Π΅Π΄ΠΈΡ‚Π΅ Π·Π° новостями,
АлСксандр Π›ΠΈΡ‚Ρ€Π΅Π΅Π²
CEO Π² Solar Labs

ΠŸΠ΅ΠΉΡ‚Π΅ Π²ΠΎΠ΄Ρƒ, ΠΌΠΎΠΉΡ‚Π΅ Ρ€ΡƒΠΊΠΈ ΠΈ Π΄Π΅Ρ€ΠΆΠΈΡ‚Π΅ свою ΠΌΠ½Π΅ΠΌΠΎΠ½ΠΈΠΊΡƒ Π² сСкрСтС.