• bitcoinBitcoin (BTC) $ 67,954.00
  • ethereumEthereum (ETH) $ 3,282.36
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 582.36
  • solanaSolana (SOL) $ 182.93
  • usd-coinUSDC (USDC) $ 0.999959
  • xrpXRP (XRP) $ 0.603446
  • staked-etherLido Staked Ether (STETH) $ 3,281.26
  • dogecoinDogecoin (DOGE) $ 0.134791
  • the-open-networkToncoin (TON) $ 6.74
  • cardanoCardano (ADA) $ 0.418354
  • tronTRON (TRX) $ 0.137456
  • avalanche-2Avalanche (AVAX) $ 28.63
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 68,005.00
  • shiba-inuShiba Inu (SHIB) $ 0.000017
  • chainlinkChainlink (LINK) $ 13.57
  • polkadotPolkadot (DOT) $ 5.85
  • bitcoin-cashBitcoin Cash (BCH) $ 377.43
  • nearNEAR Protocol (NEAR) $ 5.72
  • uniswapUniswap (UNI) $ 7.70
  • leo-tokenLEO Token (LEO) $ 5.82
  • litecoinLitecoin (LTC) $ 71.36
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000012
  • wrapped-eethWrapped eETH (WEETH) $ 3,422.51
  • matic-networkPolygon (MATIC) $ 0.514458
  • internet-computerInternet Computer (ICP) $ 9.70
  • kaspaKaspa (KAS) $ 0.181229
  • ethereum-classicEthereum Classic (ETC) $ 22.94
  • aptosAptos (APT) $ 6.95
  • ethena-usdeEthena USDe (USDE) $ 0.999176
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.29
  • stellarStellar (XLM) $ 0.103221
  • moneroMonero (XMR) $ 162.53
  • mantleMantle (MNT) $ 0.853783
  • blockstackStacks (STX) $ 1.85
  • render-tokenRender (RENDER) $ 6.80
  • filecoinFilecoin (FIL) $ 4.63
  • dogwifcoindogwifhat (WIF) $ 2.63
  • bittensorBittensor (TAO) $ 351.60
  • injective-protocolInjective (INJ) $ 25.78
  • makerMaker (MKR) $ 2,676.86
  • crypto-com-chainCronos (CRO) $ 0.091615
  • okbOKB (OKB) $ 40.86
  • hedera-hashgraphHedera (HBAR) $ 0.068292
  • arbitrumArbitrum (ARB) $ 0.728930
  • cosmosCosmos Hub (ATOM) $ 6.17
  • immutable-xImmutable (IMX) $ 1.54
  • vechainVeChain (VET) $ 0.028465
  • arweaveArweave (AR) $ 31.17
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999586
  • bonkBonk (BONK) $ 0.000029
  • suiSui (SUI) $ 0.790071
  • optimismOptimism (OP) $ 1.74
  • the-graphThe Graph (GRT) $ 0.200448
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,671.12
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,324.60
  • flokiFLOKI (FLOKI) $ 0.000181
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,409.45
  • bitget-tokenBitget Token (BGB) $ 1.14
  • thorchainTHORChain (RUNE) $ 4.70
  • theta-tokenTheta Network (THETA) $ 1.51
  • notcoinNotcoin (NOT) $ 0.014360
  • whitebitWhiteBIT Coin (WBT) $ 10.10
  • aaveAave (AAVE) $ 97.71
  • ondo-financeOndo (ONDO) $ 1.00
  • pyth-networkPyth Network (PYTH) $ 0.398856
  • jupiter-exchange-solanaJupiter (JUP) $ 1.07
  • lido-daoLido DAO (LDO) $ 1.58
  • jasmycoinJasmyCoin (JASMY) $ 0.029015
  • based-brettBrett (BRETT) $ 0.132623
  • fantomFantom (FTM) $ 0.460917
  • coredaoorgCore (CORE) $ 1.38
  • celestiaCelestia (TIA) $ 5.98
  • sei-networkSei (SEI) $ 0.371207
  • algorandAlgorand (ALGO) $ 0.142626
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,270.96
  • quant-networkQuant (QNT) $ 72.85
  • flowFlow (FLOW) $ 0.675410
  • mantra-daoMANTRA (OM) $ 1.20
  • gatechain-tokenGate (GT) $ 7.60
  • msolMarinade Staked SOL (MSOL) $ 220.16
  • kucoin-sharesKuCoin (KCS) $ 9.70
  • popcatPopcat (POPCAT) $ 0.937628
  • beam-2Beam (BEAM) $ 0.018230
  • elrond-erd-2MultiversX (EGLD) $ 33.53
  • axie-infinityAxie Infinity (AXS) $ 6.07
  • ethereum-name-serviceEthereum Name Service (ENS) $ 27.13
  • heliumHelium (HNT) $ 5.30
  • bitcoin-svBitcoin SV (BSV) $ 44.87
  • galaGALA (GALA) $ 0.023735
  • eosEOS (EOS) $ 0.576864
  • flare-networksFlare (FLR) $ 0.019296
  • bittorrentBitTorrent (BTT) $ 0.00000087
  • tokenize-xchangeTokenize Xchange (TKX) $ 10.38
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,340.69
  • neoNEO (NEO) $ 11.60
  • ordinalsORDI (ORDI) $ 38.60
  • akash-networkAkash Network (AKT) $ 3.27
  • ethenaEthena (ENA) $ 0.463801
  • dydx-chaindYdX (DYDX) $ 1.31
  • tezosTezos (XTZ) $ 0.779249
  • the-sandboxThe Sandbox (SAND) $ 0.329344
  • fasttokenFasttoken (FTN) $ 2.33
  • conflux-tokenConflux (CFX) $ 0.174843
  • usddUSDD (USDD) $ 1.00
  • roninRonin (RON) $ 2.08
  • starknetStarknet (STRK) $ 0.538921
  • worldcoin-wldWorldcoin (WLD) $ 2.36
  • ecasheCash (XEC) $ 0.000035
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.007717
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000032
  • nexoNEXO (NEXO) $ 1.21
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,535.19
  • fraxFrax (FRAX) $ 0.996794
  • decentralandDecentraland (MANA) $ 0.342002
  • raydiumRaydium (RAY) $ 2.41
  • mog-coinMog Coin (MOG) $ 0.000002
  • chilizChiliz (CHZ) $ 0.070312
  • frax-etherFrax Ether (FRXETH) $ 3,266.15
  • pendlePendle (PENDLE) $ 3.94
  • paypal-usdPayPal USD (PYUSD) $ 0.999386
  • oasis-networkOasis Network (ROSE) $ 0.088539
  • mina-protocolMina Protocol (MINA) $ 0.522553
  • book-of-memeBOOK OF MEME (BOME) $ 0.008588
  • zksyncZKsync (ZK) $ 0.161148
  • tether-goldTether Gold (XAUT) $ 2,386.84
  • aioz-networkAIOZ Network (AIOZ) $ 0.525752
  • havvenSynthetix Network (SNX) $ 1.74
  • gnosisGnosis (GNO) $ 215.28
  • iotaIOTA (IOTA) $ 0.165127
  • nervos-networkNervos Network (CKB) $ 0.012373
  • dexeDeXe (DEXE) $ 9.56
  • swethSwell Ethereum (SWETH) $ 3,482.83
  • apecoinApeCoin (APE) $ 0.791302
  • klay-tokenKlaytn (KLAY) $ 0.143844
  • astarAstar (ASTR) $ 0.075171
  • wormholeWormhole (W) $ 0.291833
  • layerzeroLayerZero (ZRO) $ 4.69
  • aerodrome-financeAerodrome Finance (AERO) $ 0.938036
  • livepeerLivepeer (LPT) $ 15.10
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,582.52
  • axelarAxelar (AXL) $ 0.678212
  • true-usdTrueUSD (TUSD) $ 1.00
  • safeSafe (SAFE) $ 1.15
  • zcashZcash (ZEC) $ 32.38
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000086
  • xdce-crowd-saleXDC Network (XDC) $ 0.031207
  • 1inch1inch (1INCH) $ 0.369557
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.99
  • aevo-exchangeAevo (AEVO) $ 0.528875
  • theta-fuelTheta Fuel (TFUEL) $ 0.068674
  • kavaKava (KAVA) $ 0.418816
  • illuviumIlluvium (ILV) $ 67.90
  • bitcoin-goldBitcoin Gold (BTG) $ 25.49
  • pax-goldPAX Gold (PAXG) $ 2,386.03
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.02
  • apenftAPENFT (NFT) $ 0.00000043
  • iotexIoTeX (IOTX) $ 0.044904
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.004219
  • wemix-tokenWEMIX (WEMIX) $ 1.03
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.080961
  • turboTurbo (TURBO) $ 0.005887
  • usdbUSDB (USDB) $ 0.999185
  • h2o-daoH2O Dao (H2O) $ 0.482415
  • jito-governance-tokenJito (JTO) $ 3.17
  • g-tokenGravity (G) $ 0.053884
  • mx-tokenMX (MX) $ 3.98
  • project-galaxyGalxe (GAL) $ 3.26
  • woo-networkWOO (WOO) $ 0.198787
  • stader-ethxStader ETHx (ETHX) $ 3,396.51
  • ether-fiEther.fi (ETHFI) $ 2.21
  • manta-networkManta Network (MANTA) $ 0.972981
  • safepalSafePal (SFP) $ 0.779558
  • arkhamArkham (ARKM) $ 1.46
  • compound-ethercETH (CETH) $ 65.97
  • compound-governance-tokenCompound (COMP) $ 51.33
  • memecoin-2Memecoin (MEME) $ 0.015465
  • superfarmSuperVerse (SUPER) $ 0.772913
  • stepnGMT (GMT) $ 0.151590
  • golemGolem (GLM) $ 0.345038
  • singularitynetSingularityNET (AGIX) $ 0.551482
  • venomVenom (VENOM) $ 0.187113
  • 0x0x Protocol (ZRX) $ 0.401032
  • rocket-poolRocket Pool (RPL) $ 16.37
  • blurBlur (BLUR) $ 0.188534
  • dymensionDymension (DYM) $ 1.70
  • kusamaKusama (KSM) $ 21.52
  • ponkePONKE (PONKE) $ 0.603130
  • osmosisOsmosis (OSMO) $ 0.486402
  • aragonAragon (ANT) $ 8.17
  • availAvail (AVAIL) $ 0.190171
  • zilliqaZilliqa (ZIL) $ 0.017161
  • dashDash (DASH) $ 27.09
  • beldexBeldex (BDX) $ 0.048065
  • altlayerAltLayer (ALT) $ 0.138796
  • echelon-primeEchelon Prime (PRIME) $ 7.46
  • curve-dao-tokenCurve DAO (CRV) $ 0.266932
  • corgiaiCorgiAI (CORGIAI) $ 0.000921
  • enjincoinEnjin Coin (ENJ) $ 0.189803

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

0 68

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

  coinedition.com 25 m

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

Recent reports highlighted a malicious javascript code present in the two-month-old governance proposal introduced by the Tornado Cash community developer Butterfly Effects. According to the findings, the funds deposited since January 1, 2024, are at risk, posing a potential exploit.

Chinese crypto reporter Colin Wu shared an X post on his official page known as Wu Blockchain, providing insights on the vulnerability identified in the malicious proposal. According to his post, the governance proposal might have resulted in the leakage of the deposit notes of Tornado Cash to a private malicious server owned by the alleged developer since January 1.

The community has found that a malicious javascript code was hidden from the 2-month-old governance proposal made by the alleged Tornado Cash community developer Butterfly Effects from the previous governance proposal 44 and thus we estimate that since Jan 1st the deposit notes…

— Wu Blockchain (@WuBlockchain) February 25, 2024

Notably, the vulnerability is identified in the IPFS version of Tornado Cash. While Tornado Cash is a decentralized privacy solution for crypto transactions maintaining anonymity, the IPFS version is resistant to censorship and surveillance. Thus, the malicious code has become a “hidden trap” for the scammer, as the version would easily track them.

According to the SlowMist Founder Yu Xian, the malicious code in the IPFS version of Tornado Cash allows for the hijacking of deposit certificates. Though there are hints for some funds to be stolen since the approval of the proposal, it is unclear how many users are affected.

The community urges users to change their notes using the recommended IPFS ContextHash deployment which was previously used for tornadocash.eth. In addition, the community asked the users to vote to veto the previously deployed proposals to restrict any possible malicious exploit hidden on the proposal contract.

Last year, a hacker stole more than $1 million through a malicious governance proposal. Allegedly granting 1.2 million votes to the malevolent proposal, they gained control over Tornado Cash’s decentralized finance (DeFi) protocol, leading to the embezzlement of funds.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source

Leave A Reply

Your email address will not be published.