🚀 Evoq Finance Suffers $420,000 Loss in BNB Chain Smart Contract Attack
#EvoqFinance #BNBChain #SmartContractAttack #SecurityBreach #OwnershipTransfer #TransferOwnership #ProxyUpgrade #DrainingFunds #TokenApprovals #MultiSignature #KeyRotation #0xF9C74A65B04C73B911879DB0131616C556A626bE #0xF08d1c #0x7b416F
According to PANews, Evoq Finance's smart contract on the BNB Chain was compromised, resulting in a significant security breach. The attacker managed to steal the owner's account, transferring ownership to themselves and subsequently upgrading the contract to a malicious version. This led to the theft of approximately $420,000 from the protocol and user approvals.
Users are advised to immediately revoke token approvals for the contract at address 0xF9C74A65B04C73B911879DB0131616C556A626bE to prevent further losses. The project team is urged to implement multi-signature protection and regular key rotation to safeguard high-privilege accounts.
The attack overview indicates that the perpetrator likely obtained the private key of the owner's account (0xF08d1c) and used the transferOwnership function to shift ownership to their address (0x7b416F). They then upgraded the proxy contract, draining funds from both the contract and approved user accounts.#EvoqFinance #BNBChain #SmartContractAttack #SecurityBreach #OwnershipTransfer #TransferOwnership #ProxyUpgrade #DrainingFunds #TokenApprovals #MultiSignature #KeyRotation #0xF9C74A65B04C73B911879DB0131616C556A626bE #0xF08d1c #0x7b416F
🚀 World ID v4.0 Introduces Account Abstraction and Enhanced Security Features
#WorldIDv4 #AccountAbstraction #EnhancedSecurity #MultiKeySupport #KeyRotation #KeyRevocation #RecoveryAgent #PrivacyProtection #OPRF #RelyingPartyRegistry #PhishingPrevention #ProtocolUpdate
World has announced the release of World ID v4.0, incorporating account abstraction into its protocol. According to Foresight News, this upgrade transitions World ID from a single key to an abstract record within the public registry "WorldIDRegistry," enabling multiple authorization keys for users to generate proofs across various devices or platforms.
Key features of this upgrade include multi-key support, allowing users to manage multiple authenticators while maintaining a single identity. The protocol's resilience is enhanced with support for key rotation and revocation, and the introduction of an optional recovery agent to address key loss.
Additionally, a web-based reference authenticator has been launched to simplify browser usage. Privacy protection is strengthened through OPRF nodes that generate one-time nullifiers, preventing long-term tracking while maintaining proof integrity.
The update also introduces a Relying Party Registry, enabling authenticators to identify request sources to prevent phishing attacks and laying the groundwork for future protocol fees.#WorldIDv4 #AccountAbstraction #EnhancedSecurity #MultiKeySupport #KeyRotation #KeyRevocation #RecoveryAgent #PrivacyProtection #OPRF #RelyingPartyRegistry #PhishingPrevention #ProtocolUpdate