• bitcoinBitcoin (BTC) $ 61,810.00
  • ethereumEthereum (ETH) $ 2,909.88
  • tetherTether (USDT) $ 0.999401
  • bnbBNB (BNB) $ 586.53
  • solanaSolana (SOL) $ 146.36
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.507529
  • staked-etherLido Staked Ether (STETH) $ 2,907.59
  • the-open-networkToncoin (TON) $ 6.90
  • dogecoinDogecoin (DOGE) $ 0.149048
  • cardanoCardano (ADA) $ 0.434380
  • shiba-inuShiba Inu (SHIB) $ 0.000024
  • avalanche-2Avalanche (AVAX) $ 32.78
  • tronTRON (TRX) $ 0.124949
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,832.00
  • polkadotPolkadot (DOT) $ 6.62
  • bitcoin-cashBitcoin Cash (BCH) $ 436.13
  • chainlinkChainlink (LINK) $ 13.37
  • nearNEAR Protocol (NEAR) $ 7.15
  • matic-networkPolygon (MATIC) $ 0.660356
  • litecoinLitecoin (LTC) $ 81.07
  • internet-computerInternet Computer (ICP) $ 11.96
  • leo-tokenLEO Token (LEO) $ 5.90
  • daiDai (DAI) $ 0.998695
  • uniswapUniswap (UNI) $ 6.94
  • fetch-aiFetch.ai (FET) $ 2.07
  • pepePepe (PEPE) $ 0.000011
  • render-tokenRender (RNDR) $ 10.26
  • hedera-hashgraphHedera (HBAR) $ 0.108728
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • ethereum-classicEthereum Classic (ETC) $ 25.89
  • aptosAptos (APT) $ 8.03
  • crypto-com-chainCronos (CRO) $ 0.123001
  • cosmosCosmos Hub (ATOM) $ 8.35
  • mantleMantle (MNT) $ 0.970847
  • wrapped-eethWrapped eETH (WEETH) $ 3,014.20
  • immutable-xImmutable (IMX) $ 2.10
  • filecoinFilecoin (FIL) $ 5.50
  • dogwifcoindogwifhat (WIF) $ 3.01
  • stellarStellar (XLM) $ 0.103484
  • okbOKB (OKB) $ 49.16
  • blockstackStacks (STX) $ 1.99
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,860.82
  • kaspaKaspa (KAS) $ 0.115882
  • optimismOptimism (OP) $ 2.49
  • the-graphThe Graph (GRT) $ 0.271960
  • arbitrumArbitrum (ARB) $ 0.970238
  • arweaveArweave (AR) $ 38.93
  • makerMaker (MKR) $ 2,698.03
  • vechainVeChain (VET) $ 0.033565
  • moneroMonero (XMR) $ 133.93
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • bittensorBittensor (TAO) $ 341.67
  • suiSui (SUI) $ 0.937281
  • injective-protocolInjective (INJ) $ 22.27
  • theta-tokenTheta Network (THETA) $ 1.98
  • fantomFantom (FTM) $ 0.671689
  • thorchainTHORChain (RUNE) $ 5.59
  • flokiFLOKI (FLOKI) $ 0.000192
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,213.39
  • celestiaCelestia (TIA) $ 8.61
  • bonkBonk (BONK) $ 0.000023
  • lido-daoLido DAO (LDO) $ 1.68
  • bitget-tokenBitget Token (BGB) $ 1.05
  • coredaoorgCore (CORE) $ 1.64
  • galaGALA (GALA) $ 0.040877
  • algorandAlgorand (ALGO) $ 0.176293
  • jupiter-exchange-solanaJupiter (JUP) $ 1.06
  • whitebitWhiteBIT Coin (WBT) $ 9.84
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,986.85
  • quant-networkQuant (QNT) $ 94.15
  • sei-networkSei (SEI) $ 0.468661
  • flowFlow (FLOW) $ 0.839148
  • aaveAave (AAVE) $ 81.88
  • akash-networkAkash Network (AKT) $ 5.26
  • bitcoin-svBitcoin SV (BSV) $ 60.56
  • bittorrentBitTorrent (BTT) $ 0.000001
  • singularitynetSingularityNET (AGIX) $ 0.868759
  • worldcoin-wldWorldcoin (WLD) $ 5.14
  • beam-2Beam (BEAM) $ 0.022241
  • ondo-financeOndo (ONDO) $ 0.757614
  • flare-networksFlare (FLR) $ 0.026657
  • dydx-chaindYdX (DYDX) $ 1.93
  • cheeleeCheelee (CHEEL) $ 18.83
  • ethenaEthena (ENA) $ 0.740535
  • gatechain-tokenGate (GT) $ 8.05
  • neoNEO (NEO) $ 14.81
  • elrond-erd-2MultiversX (EGLD) $ 38.27
  • chilizChiliz (CHZ) $ 0.114948
  • zebec-protocolZebec Protocol (ZBC) $ 0.019707
  • axie-infinityAxie Infinity (AXS) $ 6.81
  • ribbon-financeRibbon Finance (RBN) $ 1.01
  • wormholeWormhole (W) $ 0.528697
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.79
  • the-sandboxThe Sandbox (SAND) $ 0.415656
  • kucoin-sharesKuCoin (KCS) $ 9.79
  • ecasheCash (XEC) $ 0.000047
  • jasmycoinJasmyCoin (JASMY) $ 0.018457
  • eosEOS (EOS) $ 0.776341
  • msolMarinade Staked SOL (MSOL) $ 173.82
  • tezosTezos (XTZ) $ 0.894220
  • aioz-networkAIOZ Network (AIOZ) $ 0.772523
  • safeSafe (SAFE) $ 1.97
  • mina-protocolMina Protocol (MINA) $ 0.761221
  • starknetStarknet (STRK) $ 1.15
  • conflux-tokenConflux (CFX) $ 0.206090
  • roninRonin (RON) $ 2.54
  • havvenSynthetix Network (SNX) $ 2.40
  • book-of-memeBOOK OF MEME (BOME) $ 0.011375
  • heliumHelium (HNT) $ 4.73
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,894.71
  • ordinalsORDI (ORDI) $ 37.17
  • decentralandDecentraland (MANA) $ 0.407404
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,928.03
  • usddUSDD (USDD) $ 0.998684
  • apecoinApeCoin (APE) $ 1.16
  • gnosisGnosis (GNO) $ 278.24
  • dexeDeXe (DEXE) $ 11.92
  • kavaKava (KAVA) $ 0.627088
  • iotaIOTA (IOTA) $ 0.208383
  • nexoNEXO (NEXO) $ 1.21
  • lido-staked-solLido Staked SOL (STSOL) $ 173.18
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.56
  • nervos-networkNervos Network (CKB) $ 0.015048
  • fraxFrax (FRAX) $ 0.998913
  • pendlePendle (PENDLE) $ 4.02
  • axelarAxelar (AXL) $ 0.943518
  • pyth-networkPyth Network (PYTH) $ 0.414210
  • fasttokenFasttoken (FTN) $ 1.95
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000105
  • theta-fuelTheta Fuel (TFUEL) $ 0.092130
  • klay-tokenKlaytn (KLAY) $ 0.165341
  • frax-etherFrax Ether (FRXETH) $ 2,894.21
  • mantra-daoMANTRA (OM) $ 0.708652
  • tether-goldTether Gold (XAUT) $ 2,346.04
  • bitcoin-goldBitcoin Gold (BTG) $ 32.68
  • livepeerLivepeer (LPT) $ 17.64
  • ocean-protocolOcean Protocol (OCEAN) $ 0.873949
  • swethSwell Ethereum (SWETH) $ 3,070.76
  • blurBlur (BLUR) $ 0.350855
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000027
  • oasis-networkOasis Network (ROSE) $ 0.083664
  • echelon-primeEchelon Prime (PRIME) $ 13.99
  • wemix-tokenWEMIX (WEMIX) $ 1.50
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,105.31
  • osmosisOsmosis (OSMO) $ 0.796467
  • dydxdYdX (ETHDYDX) $ 1.92
  • golemGolem (GLM) $ 0.514891
  • arkhamArkham (ARKM) $ 2.34
  • true-usdTrueUSD (TUSD) $ 0.999686
  • xdce-crowd-saleXDC Network (XDC) $ 0.036323
  • illuviumIlluvium (ILV) $ 78.39
  • curve-dao-tokenCurve DAO (CRV) $ 0.412969
  • woo-networkWOO (WOO) $ 0.266156
  • popcatPopcat (POPCAT) $ 0.500049
  • astarAstar (ASTR) $ 0.086013
  • mx-tokenMX (MX) $ 4.93
  • jito-governance-tokenJito (JTO) $ 3.92
  • apenftAPENFT (NFT) $ 0.00000048
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,146.28
  • memecoin-2Memecoin (MEME) $ 0.025059
  • radixRadix (XRD) $ 0.043446
  • venomVenom (VENOM) $ 0.274835
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.07
  • iotexIoTeX (IOTX) $ 0.046857
  • dymensionDymension (DYM) $ 2.58
  • ethereum-name-serviceEthereum Name Service (ENS) $ 13.81
  • pax-goldPAX Gold (PAXG) $ 2,333.24
  • 1inch1inch (1INCH) $ 0.370094
  • ankrAnkr Network (ANKR) $ 0.042479
  • stepnGMT (GMT) $ 0.207675
  • superfarmSuperVerse (SUPER) $ 0.910361
  • zilliqaZilliqa (ZIL) $ 0.022309
  • raydiumRaydium (RAY) $ 1.55
  • enjincoinEnjin Coin (ENJ) $ 0.281546
  • altlayerAltLayer (ALT) $ 0.298982
  • corgiaiCorgiAI (CORGIAI) $ 0.001176
  • celoCelo (CELO) $ 0.748864
  • aerodrome-financeAerodrome Finance (AERO) $ 0.899663
  • manta-networkManta Network (MANTA) $ 1.57
  • terra-luna-2Terra (LUNA) $ 0.572849
  • rocket-poolRocket Pool (RPL) $ 19.37
  • magaMAGA (TRUMP) $ 8.46
  • polymeshPolymesh (POLYX) $ 0.372890
  • amp-tokenAmp (AMP) $ 0.006985
  • siacoinSiacoin (SC) $ 0.006837
  • ether-fiEther.fi (ETHFI) $ 3.39
  • holotokenHolo (HOT) $ 0.002174
  • ravencoinRavencoin (RVN) $ 0.027952
  • 0x0x Protocol (ZRX) $ 0.452153
  • safepalSafePal (SFP) $ 0.823044
  • paypal-usdPayPal USD (PYUSD) $ 0.999326
  • qtumQtum (QTUM) $ 3.55
  • aelfaelf (ELF) $ 0.512679
  • zetachainZetaChain (ZETA) $ 1.58
  • compound-wrapped-btccWBTC (CWBTC) $ 1,238.38
  • nosanaNosana (NOS) $ 4.43
  • compound-governance-tokenCompound (COMP) $ 53.84
  • stader-ethxStader ETHx (ETHX) $ 2,983.19
  • project-galaxyGalxe (GAL) $ 3.17

Crypto security firms more concerned with social media clout than the details

0 34

Crypto security firms more concerned with social media clout than the details

  protos.com 1 h

Crypto security firms more concerned with social media clout than the details

With memecoins regularly outperforming more established crypto projects, there’s plenty of evidence to back up the assertion that the cryptosphere often rewards attention over innovation.

From crypto influencers dumping on their followers to SocialFi projects such as FriendTech, social media following can act as a proxy for value, especially for projects without their own token.

Even crypto security auditors, supposedly behind-the-scenes players, are keen to try their hand at the social media game. Sometimes, at the expense of their credibility.

Peckshield’s classic “you may want to take a look” has caused many a heart to sink over the years, typically accompanied by a transaction hash in which hackers have extracted millions of dollars of crypto-assets.

Hi @MIM_Spell, you may want to take a look (w/ $6.49M Loss) pic.twitter.com/uHs0JweuoM

— PeckShield Inc. (@peckshield) January 30, 2024

However, while hacks may be bad for decentralized finance (DeFi) applications — not to mention their users — being the first to report them is great for engagement.

Relative newcomer Cyvers was the first to identify the attack on crypto casino Stake by the North Korean Lazarus Group in September last year. However, since then, seemingly chasing the same high, it’s been prone to jumping the gun. Yesterday, an ‘ALERT’ suggested that Eigenlayer had fallen victim to a phishing scam.

🚨ALERT🚨Hey @eigenlayer, it seems you may have become a phishing victim.

Check out this link 👇https://t.co/zeXMFZdEgx#CyversAlert pic.twitter.com/VvMizA7wtD

— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) March 5, 2024

Unfortunately, the ‘fake news’ was quickly shot down by ZachXBT who added “your team cannot read a block explorer” and linked to an explanation of a common phishing attack in which users are tricked into authorizing the withdrawal of assets from Eigenlayer to a scammer’s address.

In November last year, Cyvers sounded the alarm on ‘multiple suspicious transactions’ worth $12.5 million from Iranian crypto exchange Nobitex. This, however, also turned out to be overblown, amounting to nothing more than a rotation of the exchange’s hot wallets.

Cyvers isn’t the only culprit when it comes to posting engagement bait before corroborating the underlying issue, however. Tagging DeFi giants Lido and Curve Finance is a surefire way to get plenty of eyeballs on the alert.

A story in three acts, and they’re still wrong pic.twitter.com/qp0MF0MZOh

— Igor Igamberdiev (@FrankResearcher) February 1, 2024

Even well-respected firm BlockSec has faced criticism, notably in the fallout from the $70M Curve Finance hack in July of last year.

By publicly disclosing sensitive details of a vulnerability being actively exploited, many were concerned that the information could give the hacker, or copycats, an edge over teams aiming to mitigate the problem.

Since then, some firms have tended to be more measured in their announcements, sharing partial screenshots instead of transaction links and making clear clarifications of any misinformation shared in haste.

Such was the case yesterday when BlockSec retracted its alert after the affected project hit back that the issue had occurred a week before and was already resolved.

@BlockSecTeam

Stop trying to get more followers on other’s back by tweeting this kind of nonsense!

We are fine, there’s no hack, all funds are safe.

There was a bug we found in the zap gateway A WEEK AGO which was immediately fixed. One user lost 2.8 ETH and we compensated… https://t.co/D736HHOOZC

— f(x) Protocol (@protocol_fx) March 5, 2024

Interconnected projects make identification tricky

The composability of DeFi products means that a quick glance at Etherscan isn’t enough to fully understand the target of an attack.

If even crypto security firms are prone to making errors, it seems a tall order to expect DeFi users to have the required crypto-literacy to distinguish a genuine threat from a security firm crying wolf.

When large projects like Eigenlayer, Lido, and Curve (Ethereum’s first, second, and eleventh largest protocols) are tagged in such ‘alerts,’ panic can spread rapidly, and scammers know how to take advantage of that panic.

Certik, whose audits are often seen as a red flag rather than a seal of approval, recently had its own X (formerly Twitter) account hacked via a common vector involving a fake Calendly link.

It looks like @CertiK’s X account has been compromised and is sharing a link to a fake Revoke website. Uniswap is NOT compromised. pic.twitter.com/G5xw7PQR6n

— Revoke.cash (@RevokeCash) January 5, 2024

The account was used to announce a (fictional) vulnerability in Uniswap, directing users to a fake Revoke.Cash site where they could revoke token approvals to remain safe.

Certik-audited WOOFi was hacked for $8.5 million on Arbitrum yesterday via a price manipulation attack.

Source

Leave A Reply

Your email address will not be published.