• bitcoinBitcoin (BTC) $ 96,828.00
  • ethereumEthereum (ETH) $ 3,213.51
  • xrpXRP (XRP) $ 2.79
  • tetherTether (USDT) $ 0.999528
  • bnbBNB (BNB) $ 697.86
  • solanaSolana (SOL) $ 187.29
  • dogecoinDogecoin (DOGE) $ 0.360710
  • usd-coinUSDC (USDC) $ 0.999999
  • cardanoCardano (ADA) $ 1.02
  • staked-etherLido Staked Ether (STETH) $ 3,210.33
  • tronTRON (TRX) $ 0.221528
  • avalanche-2Avalanche (AVAX) $ 36.57
  • stellarStellar (XLM) $ 0.461130
  • suiSui (SUI) $ 4.52
  • the-open-networkToncoin (TON) $ 5.33
  • wrapped-stethWrapped stETH (WSTETH) $ 3,833.22
  • chainlinkChainlink (LINK) $ 20.38
  • shiba-inuShiba Inu (SHIB) $ 0.000022
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 96,665.00
  • content-bitcoinContent Bitcoin (CTB) $ 23.81
  • hedera-hashgraphHedera (HBAR) $ 0.297970
  • polkadotPolkadot (DOT) $ 6.66
  • wethWETH (WETH) $ 3,216.73
  • bitcoin-cashBitcoin Cash (BCH) $ 438.50
  • leo-tokenLEO Token (LEO) $ 9.28
  • uniswapUniswap (UNI) $ 13.19
  • bitget-tokenBitget Token (BGB) $ 6.49
  • litecoinLitecoin (LTC) $ 102.34
  • hyperliquidHyperliquid (HYPE) $ 22.58
  • pepePepe (PEPE) $ 0.000017
  • wrapped-eethWrapped eETH (WEETH) $ 3,403.12
  • usdsUSDS (USDS) $ 0.999370
  • nearNEAR Protocol (NEAR) $ 4.98
  • ethena-usdeEthena USDe (USDE) $ 0.998400
  • aptosAptos (APT) $ 8.93
  • internet-computerInternet Computer (ICP) $ 10.22
  • aaveAave (AAVE) $ 295.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.456040
  • ethereum-classicEthereum Classic (ETC) $ 25.34
  • moneroMonero (XMR) $ 206.58
  • crypto-com-chainCronos (CRO) $ 0.136520
  • mantleMantle (MNT) $ 1.10
  • vechainVeChain (VET) $ 0.044815
  • render-tokenRender (RENDER) $ 6.91
  • mantra-daoMANTRA (OM) $ 3.71
  • kaspaKaspa (KAS) $ 0.137570
  • daiDai (DAI) $ 0.999953
  • bittensorBittensor (TAO) $ 414.39
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.29
  • algorandAlgorand (ALGO) $ 0.387887
  • filecoinFilecoin (FIL) $ 5.20
  • arbitrumArbitrum (ARB) $ 0.734359
  • okbOKB (OKB) $ 49.04
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.89
  • tokenize-xchangeTokenize Xchange (TKX) $ 34.93
  • cosmosCosmos Hub (ATOM) $ 6.27
  • ethenaEthena (ENA) $ 0.814904
  • optimismOptimism (OP) $ 1.77
  • gatechain-tokenGate (GT) $ 18.65
  • celestiaCelestia (TIA) $ 4.72
  • sonic-3Sonic (prev. FTM) (S) $ 0.719215
  • blockstackStacks (STX) $ 1.50
  • theta-tokenTheta Network (THETA) $ 2.17
  • injective-protocolInjective (INJ) $ 21.35
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 96,858.00
  • bonkBonk (BONK) $ 0.000027
  • immutable-xImmutable (IMX) $ 1.20
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.031435
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,214.91
  • the-graphThe Graph (GRT) $ 0.201779
  • movementMovement (MOVE) $ 0.822002
  • worldcoin-wldWorldcoin (WLD) $ 2.02
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997678
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,322.98
  • sei-networkSei (SEI) $ 0.378712
  • xdce-crowd-saleXDC Network (XDC) $ 0.110525
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,604.32
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 96,693.00
  • ondo-financeOndo (ONDO) $ 1.14
  • fasttokenFasttoken (FTN) $ 3.82
  • lido-daoLido DAO (LDO) $ 1.81
  • raydiumRaydium (RAY) $ 5.38
  • flokiFLOKI (FLOKI) $ 0.000161
  • galaGALA (GALA) $ 0.036255
  • dogwifcoindogwifhat (WIF) $ 1.53
  • usual-usdUsual USD (USD0) $ 0.998155
  • binance-staked-solBinance Staked SOL (BNSOL) $ 191.85
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,382.76
  • jasmycoinJasmyCoin (JASMY) $ 0.030138
  • ai16zai16z (AI16Z) $ 1.33
  • flare-networksFlare (FLR) $ 0.024761
  • the-sandboxThe Sandbox (SAND) $ 0.568430
  • susdssUSDS (SUSDS) $ 1.03
  • jupiter-exchange-solanaJupiter (JUP) $ 0.798650
  • kucoin-sharesKuCoin (KCS) $ 10.68
  • tezosTezos (XTZ) $ 1.28
  • iotaIOTA (IOTA) $ 0.355387
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 96,427.00
  • nexoNEXO (NEXO) $ 1.28
  • kaiaKaia (KAIA) $ 0.216900
  • makerMaker (MKR) $ 1,382.33
  • eosEOS (EOS) $ 0.802366
  • beam-2Beam (BEAM) $ 0.022340
  • pyth-networkPyth Network (PYTH) $ 0.320597
  • based-brettBrett (BRETT) $ 0.114348
  • flowFlow (FLOW) $ 0.726991
  • thorchainTHORChain (RUNE) $ 3.19
  • aioz-networkAIOZ Network (AIOZ) $ 0.966536
  • curve-dao-tokenCurve DAO (CRV) $ 0.860305
  • bittorrentBitTorrent (BTT) $ 0.000001
  • bitcoin-svBitcoin SV (BSV) $ 54.60
  • ethereum-name-serviceEthereum Name Service (ENS) $ 31.52
  • neoNEO (NEO) $ 14.81
  • starknetStarknet (STRK) $ 0.424964
  • arweaveArweave (AR) $ 15.65
  • msolMarinade Staked SOL (MSOL) $ 234.76
  • fartcoinFartcoin (FARTCOIN) $ 1.00
  • spx6900SPX6900 (SPX) $ 1.06
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 95,601.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,321.28
  • axie-infinityAxie Infinity (AXS) $ 6.18
  • decentralandDecentraland (MANA) $ 0.494934
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.360559
  • dexeDeXe (DEXE) $ 16.04
  • dydx-chaindYdX (DYDX) $ 1.26
  • elrond-erd-2MultiversX (EGLD) $ 32.36
  • coredaoorgCore (CORE) $ 0.952919
  • aerodrome-financeAerodrome Finance (AERO) $ 1.18
  • matic-networkPolygon (MATIC) $ 0.455864
  • zcashZcash (ZEC) $ 52.58
  • wbnbWrapped BNB (WBNB) $ 698.17
  • heliumHelium (HNT) $ 4.68
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 96,504.00
  • apecoinApeCoin (APE) $ 1.06
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,217.18
  • chilizChiliz (CHZ) $ 0.080753
  • echelon-primeEchelon Prime (PRIME) $ 14.12
  • usddUSDD (USDD) $ 0.998817
  • akash-networkAkash Network (AKT) $ 3.01
  • mog-coinMog Coin (MOG) $ 0.000002
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 200.72
  • conflux-tokenConflux (CFX) $ 0.148524
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,213.90
  • reserve-rights-tokenReserve Rights (RSR) $ 0.013123
  • roninRonin (RON) $ 1.85
  • ecasheCash (XEC) $ 0.000035
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,219.84
  • jito-governance-tokenJito (JTO) $ 2.46
  • wormholeWormhole (W) $ 0.244430
  • grassGrass (GRASS) $ 2.81
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.33
  • mina-protocolMina Protocol (MINA) $ 0.559990
  • compound-governance-tokenCompound (COMP) $ 75.86
  • bio-protocolBio Protocol (BIO) $ 0.402629
  • tether-goldTether Gold (XAUT) $ 2,634.30
  • eigenlayerEigenlayer (EIGEN) $ 3.07
  • zksyncZKsync (ZK) $ 0.175657
  • fraxFrax (FRAX) $ 0.995027
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,383.11
  • notcoinNotcoin (NOT) $ 0.006275
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 95,761.00
  • gnosisGnosis (GNO) $ 242.21
  • usdx-money-usdxusdx.money USDX (USDX) $ 0.997491
  • pendlePendle (PENDLE) $ 3.76
  • gigachad-2Gigachad (GIGA) $ 0.063611
  • havvenSynthetix Network (SNX) $ 1.78
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.591526
  • dydxdYdX (ETHDYDX) $ 1.26
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000102
  • turboTurbo (TURBO) $ 0.008060
  • freysa-aiFreysa AI (FAI) $ 0.067003
  • beldexBeldex (BDX) $ 0.079228
  • axelarAxelar (AXL) $ 0.604713
  • amp-tokenAmp (AMP) $ 0.006414
  • aixbtaixbt by Virtuals (AIXBT) $ 0.626695
  • superfarmSuperVerse (SUPER) $ 1.19
  • ordinalsORDI (ORDI) $ 25.52
  • pax-goldPAX Gold (PAXG) $ 2,668.47
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,078.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,497.69
  • paypal-usdPayPal USD (PYUSD) $ 0.998715
  • popcatPopcat (POPCAT) $ 0.531173
  • 1inch1inch (1INCH) $ 0.371956
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.005162
  • pumpbtcpumpBTC (PUMPBTC) $ 92,647.00
  • oasis-networkOasis (ROSE) $ 0.075604
  • kavaKava (KAVA) $ 0.468223
  • livepeerLivepeer (LPT) $ 13.53
  • resolv-usrResolv USR (USR) $ 0.999553
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.005696
  • kusamaKusama (KSM) $ 31.48
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.20
  • safeSafe (SAFE) $ 0.947468
  • true-usdTrueUSD (TUSD) $ 0.997774
  • layerzeroLayerZero (ZRO) $ 4.38
  • nervos-networkNervos Network (CKB) $ 0.010562
  • apenftAPENFT (NFT) $ 0.00000048
  • frax-etherFrax Ether (FRXETH) $ 3,206.19
  • snekSnek (SNEK) $ 0.006228
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,216.42

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

0 138

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

  coinedition.com 25 m

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

Recent reports highlighted a malicious javascript code present in the two-month-old governance proposal introduced by the Tornado Cash community developer Butterfly Effects. According to the findings, the funds deposited since January 1, 2024, are at risk, posing a potential exploit.

Chinese crypto reporter Colin Wu shared an X post on his official page known as Wu Blockchain, providing insights on the vulnerability identified in the malicious proposal. According to his post, the governance proposal might have resulted in the leakage of the deposit notes of Tornado Cash to a private malicious server owned by the alleged developer since January 1.

The community has found that a malicious javascript code was hidden from the 2-month-old governance proposal made by the alleged Tornado Cash community developer Butterfly Effects from the previous governance proposal 44 and thus we estimate that since Jan 1st the deposit notes…

— Wu Blockchain (@WuBlockchain) February 25, 2024

Notably, the vulnerability is identified in the IPFS version of Tornado Cash. While Tornado Cash is a decentralized privacy solution for crypto transactions maintaining anonymity, the IPFS version is resistant to censorship and surveillance. Thus, the malicious code has become a “hidden trap” for the scammer, as the version would easily track them.

According to the SlowMist Founder Yu Xian, the malicious code in the IPFS version of Tornado Cash allows for the hijacking of deposit certificates. Though there are hints for some funds to be stolen since the approval of the proposal, it is unclear how many users are affected.

The community urges users to change their notes using the recommended IPFS ContextHash deployment which was previously used for tornadocash.eth. In addition, the community asked the users to vote to veto the previously deployed proposals to restrict any possible malicious exploit hidden on the proposal contract.

Last year, a hacker stole more than $1 million through a malicious governance proposal. Allegedly granting 1.2 million votes to the malevolent proposal, they gained control over Tornado Cash’s decentralized finance (DeFi) protocol, leading to the embezzlement of funds.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source

Leave A Reply

Your email address will not be published.