• bitcoinBitcoin (BTC) $ 63,550.00
  • ethereumEthereum (ETH) $ 2,973.44
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 548.17
  • solanaSolana (SOL) $ 134.87
  • usd-coinUSDC (USDC) $ 1.01
  • staked-etherLido Staked Ether (STETH) $ 2,965.28
  • xrpXRP (XRP) $ 0.469731
  • dogecoinDogecoin (DOGE) $ 0.148969
  • the-open-networkToncoin (TON) $ 5.93
  • cardanoCardano (ADA) $ 0.446367
  • avalanche-2Avalanche (AVAX) $ 33.71
  • shiba-inuShiba Inu (SHIB) $ 0.000021
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 63,459.00
  • tronTRON (TRX) $ 0.109292
  • bitcoin-cashBitcoin Cash (BCH) $ 462.81
  • polkadotPolkadot (DOT) $ 6.37
  • chainlinkChainlink (LINK) $ 13.10
  • matic-networkPolygon (MATIC) $ 0.648538
  • litecoinLitecoin (LTC) $ 75.49
  • internet-computerInternet Computer (ICP) $ 11.93
  • leo-tokenLEO Token (LEO) $ 5.83
  • nearNEAR Protocol (NEAR) $ 5.07
  • daiDai (DAI) $ 1.00
  • uniswapUniswap (UNI) $ 6.81
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • aptosAptos (APT) $ 8.87
  • ethereum-classicEthereum Classic (ETC) $ 25.12
  • blockstackStacks (STX) $ 2.52
  • mantleMantle (MNT) $ 1.07
  • crypto-com-chainCronos (CRO) $ 0.124055
  • bittensorBittensor (TAO) $ 484.16
  • cosmosCosmos Hub (ATOM) $ 8.00
  • okbOKB (OKB) $ 51.64
  • filecoinFilecoin (FIL) $ 5.63
  • stellarStellar (XLM) $ 0.103663
  • immutable-xImmutable (IMX) $ 2.01
  • vechainVeChain (VET) $ 0.038810
  • render-tokenRender (RNDR) $ 7.26
  • arbitrumArbitrum (ARB) $ 1.03
  • hedera-hashgraphHedera (HBAR) $ 0.075449
  • kaspaKaspa (KAS) $ 0.113509
  • makerMaker (MKR) $ 2,802.36
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • dogwifcoindogwifhat (WIF) $ 2.34
  • the-graphThe Graph (GRT) $ 0.228891
  • optimismOptimism (OP) $ 2.14
  • pepePepe (PEPE) $ 0.000005
  • injective-protocolInjective (INJ) $ 23.53
  • moneroMonero (XMR) $ 115.95
  • wrapped-eethWrapped eETH (WEETH) $ 3,068.14
  • fetch-aiFetch.ai (FET) $ 1.93
  • theta-tokenTheta Network (THETA) $ 1.93
  • fantomFantom (FTM) $ 0.652446
  • celestiaCelestia (TIA) $ 9.89
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,277.62
  • lido-daoLido DAO (LDO) $ 1.86
  • thorchainTHORChain (RUNE) $ 4.90
  • bitget-tokenBitget Token (BGB) $ 1.14
  • arweaveArweave (AR) $ 23.95
  • galaGALA (GALA) $ 0.040261
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,057.56
  • ethenaEthena (ENA) $ 1.03
  • suiSui (SUI) $ 1.07
  • quant-networkQuant (QNT) $ 95.01
  • algorandAlgorand (ALGO) $ 0.166804
  • flokiFLOKI (FLOKI) $ 0.000133
  • sei-networkSei (SEI) $ 0.483002
  • flowFlow (FLOW) $ 0.861058
  • whitebitWhiteBIT Coin (WBT) $ 8.91
  • bitcoin-svBitcoin SV (BSV) $ 65.19
  • beam-2Beam (BEAM) $ 0.024010
  • jupiter-exchange-solanaJupiter (JUP) $ 0.930103
  • flare-networksFlare (FLR) $ 0.031984
  • aaveAave (AAVE) $ 82.03
  • bittorrentBitTorrent (BTT) $ 0.000001
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,944.75
  • coredaoorgCore (CORE) $ 1.33
  • ribbon-financeRibbon Finance (RBN) $ 1.18
  • neoNEO (NEO) $ 15.82
  • tokenize-xchangeTokenize Xchange (TKX) $ 13.55
  • ondo-financeOndo (ONDO) $ 0.728084
  • zebec-protocolZebec Network (ZBCN) $ 0.020558
  • ecasheCash (XEC) $ 0.000052
  • starknetStarknet (STRK) $ 1.38
  • elrond-erd-2MultiversX (EGLD) $ 37.30
  • bonkBonk (BONK) $ 0.000015
  • nervos-networkNervos Network (CKB) $ 0.022430
  • wormholeWormhole (W) $ 0.547979
  • axie-infinityAxie Infinity (AXS) $ 6.74
  • singularitynetSingularityNET (AGIX) $ 0.746911
  • tezosTezos (XTZ) $ 0.978324
  • ordinalsORDI (ORDI) $ 45.38
  • gatechain-tokenGate (GT) $ 6.98
  • the-sandboxThe Sandbox (SAND) $ 0.406908
  • jasmycoinJasmyCoin (JASMY) $ 0.018980
  • dydx-chaindYdX (DYDX) $ 1.95
  • roninRonin (RON) $ 2.88
  • havvenSynthetix Network (SNX) $ 2.71
  • cheeleeCheelee (CHEEL) $ 15.59
  • chilizChiliz (CHZ) $ 0.095628
  • conflux-tokenConflux (CFX) $ 0.213998
  • msolMarinade staked SOL (MSOL) $ 158.39
  • eosEOS (EOS) $ 0.724880
  • pyth-networkPyth Network (PYTH) $ 0.550150
  • worldcoin-wldWorldcoin (WLD) $ 4.46
  • kucoin-sharesKuCoin (KCS) $ 8.59
  • gnosisGnosis (GNO) $ 317.39
  • mina-protocolMina Protocol (MINA) $ 0.717032
  • decentralandDecentraland (MANA) $ 0.410047
  • akash-networkAkash Network (AKT) $ 3.30
  • aerodrome-financeAerodrome Finance (AERO) $ 1.87
  • usddUSDD (USDD) $ 0.998146
  • heliumHelium (HNT) $ 4.40
  • echelon-primeEchelon Prime (PRIME) $ 19.16
  • apecoinApeCoin (APE) $ 1.13
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,987.95
  • iotaIOTA (IOTA) $ 0.218753
  • nexoNEXO (NEXO) $ 1.24
  • frax-etherFrax Ether (FRXETH) $ 2,940.86
  • kavaKava (KAVA) $ 0.619713
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.63
  • dexeDeXe (DEXE) $ 11.47
  • fraxFrax (FRAX) $ 0.997872
  • axelarAxelar (AXL) $ 1.02
  • swethSwell Ethereum (SWETH) $ 3,118.56
  • klay-tokenKlaytn (KLAY) $ 0.173742
  • corgiaiCorgiAI (CORGIAI) $ 0.001818
  • lido-staked-solLido Staked SOL (STSOL) $ 158.05
  • aioz-networkAIOZ Network (AIOZ) $ 0.564338
  • osmosisOsmosis (OSMO) $ 0.928007
  • dydxdYdX (ETHDYDX) $ 1.96
  • bitcoin-goldBitcoin Gold (BTG) $ 34.75
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000029
  • blurBlur (BLUR) $ 0.388250
  • oasis-networkOasis Network (ROSE) $ 0.087279
  • tether-goldTether Gold (XAUT) $ 2,357.01
  • radixRadix (XRD) $ 0.055859
  • dymensionDymension (DYM) $ 3.56
  • illuviumIlluvium (ILV) $ 89.87
  • pups-ordinalsPUPS (Ordinals) (PUPS) $ 74.31
  • mantra-daoMANTRA (OM) $ 0.693774
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,160.49
  • fasttokenFasttoken (FTN) $ 1.77
  • based-brettBrett (BRETT) $ 0.063668
  • pendlePendle (PENDLE) $ 5.54
  • astarAstar (ASTR) $ 0.093927
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000090
  • wemix-tokenWEMIX (WEMIX) $ 1.44
  • true-usdTrueUSD (TUSD) $ 1.00
  • mx-tokenMX (MX) $ 5.11
  • altlayerAltLayer (ALT) $ 0.400982
  • curve-dao-tokenCurve DAO (CRV) $ 0.425105
  • xdce-crowd-saleXDC Network (XDC) $ 0.035999
  • woo-networkWOO (WOO) $ 0.269494
  • theta-fuelTheta Fuel (TFUEL) $ 0.076088
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,197.07
  • iotexIoTeX (IOTX) $ 0.050455
  • manta-networkManta Network (MANTA) $ 1.86
  • ocean-protocolOcean Protocol (OCEAN) $ 0.763864
  • pax-goldPAX Gold (PAXG) $ 2,501.75
  • stepnGMT (GMT) $ 0.235174
  • apenftAPENFT (NFT) $ 0.00000046
  • ether-fiEther.fi (ETHFI) $ 3.92
  • book-of-memeBOOK OF MEME (BOME) $ 0.008142
  • 1inch1inch (1INCH) $ 0.387347
  • skaleSKALE (SKL) $ 0.084406
  • enjincoinEnjin Coin (ENJ) $ 0.302115
  • zilliqaZilliqa (ZIL) $ 0.022988
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.995208
  • polymeshPolymesh (POLYX) $ 0.397905
  • terra-luna-2Terra (LUNA) $ 0.580075
  • compound-wrapped-btccWBTC (CWBTC) $ 1,276.51
  • celoCelo (CELO) $ 0.738319
  • ankrAnkr Network (ANKR) $ 0.039414
  • ravencoinRavencoin (RVN) $ 0.028630
  • project-galaxyGalxe (GAL) $ 3.71
  • ethereum-name-serviceEthereum Name Service (ENS) $ 12.46
  • 0x0x Protocol (ZRX) $ 0.457290
  • rocket-poolRocket Pool (RPL) $ 19.00
  • biconomyBiconomy (BICO) $ 0.514753
  • memecoin-2Memecoin (MEME) $ 0.024775
  • superfarmSuperVerse (SUPER) $ 0.845065
  • siacoinSiacoin (SC) $ 0.006674
  • jeo-bodenJeo Boden (BODEN) $ 0.550613
  • qtumQtum (QTUM) $ 3.60
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.47
  • holotokenHolo (HOT) $ 0.002123
  • aelfaelf (ELF) $ 0.509987
  • stader-ethxStader ETHx (ETHX) $ 3,033.99
  • frax-shareFrax Share (FXS) $ 4.62
  • origintrailOriginTrail (TRAC) $ 0.900194
  • amp-tokenAmp (AMP) $ 0.006393
  • casper-networkCasper Network (CSPR) $ 0.029829
  • raydiumRaydium (RAY) $ 1.35
  • basic-attention-tokenBasic Attention (BAT) $ 0.236047
  • safepalSafePal (SFP) $ 0.753333
  • compound-governance-tokenCompound (COMP) $ 50.36
  • golemGolem (GLM) $ 0.344548
  • livepeerLivepeer (LPT) $ 10.83

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

0 31

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

  coinedition.com 25 m

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

Recent reports highlighted a malicious javascript code present in the two-month-old governance proposal introduced by the Tornado Cash community developer Butterfly Effects. According to the findings, the funds deposited since January 1, 2024, are at risk, posing a potential exploit.

Chinese crypto reporter Colin Wu shared an X post on his official page known as Wu Blockchain, providing insights on the vulnerability identified in the malicious proposal. According to his post, the governance proposal might have resulted in the leakage of the deposit notes of Tornado Cash to a private malicious server owned by the alleged developer since January 1.

The community has found that a malicious javascript code was hidden from the 2-month-old governance proposal made by the alleged Tornado Cash community developer Butterfly Effects from the previous governance proposal 44 and thus we estimate that since Jan 1st the deposit notes…

— Wu Blockchain (@WuBlockchain) February 25, 2024

Notably, the vulnerability is identified in the IPFS version of Tornado Cash. While Tornado Cash is a decentralized privacy solution for crypto transactions maintaining anonymity, the IPFS version is resistant to censorship and surveillance. Thus, the malicious code has become a “hidden trap” for the scammer, as the version would easily track them.

According to the SlowMist Founder Yu Xian, the malicious code in the IPFS version of Tornado Cash allows for the hijacking of deposit certificates. Though there are hints for some funds to be stolen since the approval of the proposal, it is unclear how many users are affected.

The community urges users to change their notes using the recommended IPFS ContextHash deployment which was previously used for tornadocash.eth. In addition, the community asked the users to vote to veto the previously deployed proposals to restrict any possible malicious exploit hidden on the proposal contract.

Last year, a hacker stole more than $1 million through a malicious governance proposal. Allegedly granting 1.2 million votes to the malevolent proposal, they gained control over Tornado Cash’s decentralized finance (DeFi) protocol, leading to the embezzlement of funds.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source

Leave A Reply

Your email address will not be published.