• bitcoinBitcoin (BTC) $ 69,832.00
  • ethereumEthereum (ETH) $ 3,746.92
  • tetherTether (USDT) $ 0.999996
  • bnbBNB (BNB) $ 616.36
  • solanaSolana (SOL) $ 177.42
  • staked-etherLido Staked Ether (STETH) $ 3,743.31
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.545364
  • dogecoinDogecoin (DOGE) $ 0.168800
  • the-open-networkToncoin (TON) $ 6.42
  • cardanoCardano (ADA) $ 0.503226
  • avalanche-2Avalanche (AVAX) $ 41.13
  • shiba-inuShiba Inu (SHIB) $ 0.000026
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 69,843.00
  • tronTRON (TRX) $ 0.123758
  • polkadotPolkadot (DOT) $ 7.62
  • bitcoin-cashBitcoin Cash (BCH) $ 518.35
  • chainlinkChainlink (LINK) $ 16.76
  • nearNEAR Protocol (NEAR) $ 7.89
  • uniswapUniswap (UNI) $ 9.40
  • matic-networkPolygon (MATIC) $ 0.736868
  • litecoinLitecoin (LTC) $ 88.94
  • internet-computerInternet Computer (ICP) $ 13.60
  • fetch-aiFetch.ai (FET) $ 2.49
  • leo-tokenLEO Token (LEO) $ 6.00
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000013
  • ethereum-classicEthereum Classic (ETC) $ 31.72
  • wrapped-eethWrapped eETH (WEETH) $ 3,879.20
  • render-tokenRender (RNDR) $ 10.94
  • hedera-hashgraphHedera (HBAR) $ 0.115834
  • aptosAptos (APT) $ 9.32
  • immutable-xImmutable (IMX) $ 2.51
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,673.80
  • cosmosCosmos Hub (ATOM) $ 8.89
  • filecoinFilecoin (FIL) $ 6.24
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998548
  • mantleMantle (MNT) $ 1.04
  • crypto-com-chainCronos (CRO) $ 0.125865
  • stellarStellar (XLM) $ 0.113522
  • the-graphThe Graph (GRT) $ 0.342527
  • blockstackStacks (STX) $ 2.20
  • arbitrumArbitrum (ARB) $ 1.19
  • kaspaKaspa (KAS) $ 0.132194
  • optimismOptimism (OP) $ 2.85
  • okbOKB (OKB) $ 51.44
  • arweaveArweave (AR) $ 44.66
  • bittensorBittensor (TAO) $ 422.15
  • makerMaker (MKR) $ 3,076.49
  • dogwifcoindogwifhat (WIF) $ 2.74
  • suiSui (SUI) $ 1.14
  • vechainVeChain (VET) $ 0.036645
  • injective-protocolInjective (INJ) $ 27.95
  • fantomFantom (FTM) $ 0.908632
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • theta-tokenTheta Network (THETA) $ 2.52
  • moneroMonero (XMR) $ 136.60
  • thorchainTHORChain (RUNE) $ 6.76
  • flokiFLOKI (FLOKI) $ 0.000220
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,137.11
  • bonkBonk (BONK) $ 0.000031
  • lido-daoLido DAO (LDO) $ 2.22
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,856.88
  • celestiaCelestia (TIA) $ 9.75
  • galaGALA (GALA) $ 0.043355
  • sei-networkSei (SEI) $ 0.573996
  • pyth-networkPyth Network (PYTH) $ 0.458074
  • coredaoorgCore (CORE) $ 1.83
  • jupiter-exchange-solanaJupiter (JUP) $ 1.19
  • bitget-tokenBitget Token (BGB) $ 1.13
  • algorandAlgorand (ALGO) $ 0.190126
  • flowFlow (FLOW) $ 0.972661
  • whitebitWhiteBIT Coin (WBT) $ 10.04
  • aaveAave (AAVE) $ 97.58
  • quant-networkQuant (QNT) $ 99.36
  • starknetStarknet (STRK) $ 1.23
  • beam-2Beam (BEAM) $ 0.028252
  • bitcoin-svBitcoin SV (BSV) $ 70.97
  • akash-networkAkash Network (AKT) $ 5.84
  • ondo-financeOndo (ONDO) $ 0.930096
  • singularitynetSingularityNET (AGIX) $ 1.04
  • ethenaEthena (ENA) $ 0.883631
  • bittorrentBitTorrent (BTT) $ 0.000001
  • dydx-chaindYdX (DYDX) $ 2.15
  • flare-networksFlare (FLR) $ 0.028491
  • tokenize-xchangeTokenize Xchange (TKX) $ 14.51
  • cheeleeCheelee (CHEEL) $ 20.37
  • axie-infinityAxie Infinity (AXS) $ 7.97
  • neoNEO (NEO) $ 16.10
  • elrond-erd-2MultiversX (EGLD) $ 41.82
  • chilizChiliz (CHZ) $ 0.125756
  • worldcoin-wldWorldcoin (WLD) $ 5.04
  • msolMarinade Staked SOL (MSOL) $ 211.09
  • gatechain-tokenGate (GT) $ 8.19
  • the-sandboxThe Sandbox (SAND) $ 0.471404
  • ecasheCash (XEC) $ 0.000053
  • wormholeWormhole (W) $ 0.577898
  • zebec-protocolZebec Protocol (ZBC) $ 0.020169
  • eosEOS (EOS) $ 0.875445
  • roninRonin (RON) $ 3.06
  • jasmycoinJasmyCoin (JASMY) $ 0.020433
  • kucoin-sharesKuCoin (KCS) $ 10.22
  • tezosTezos (XTZ) $ 1.00
  • pendlePendle (PENDLE) $ 6.35
  • conflux-tokenConflux (CFX) $ 0.240969
  • havvenSynthetix Network (SNX) $ 2.97
  • safeSafe (SAFE) $ 2.26
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,755.27
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,727.29
  • mina-protocolMina Protocol (MINA) $ 0.842733
  • aioz-networkAIOZ Network (AIOZ) $ 0.846431
  • ordinalsORDI (ORDI) $ 43.22
  • gnosisGnosis (GNO) $ 346.64
  • decentralandDecentraland (MANA) $ 0.471906
  • ribbon-financeRibbon Finance (RBN) $ 0.902521
  • book-of-memeBOOK OF MEME (BOME) $ 0.012331
  • apecoinApeCoin (APE) $ 1.32
  • heliumHelium (HNT) $ 5.01
  • lido-staked-solLido Staked SOL (STSOL) $ 210.54
  • nexoNEXO (NEXO) $ 1.45
  • echelon-primeEchelon Prime (PRIME) $ 19.72
  • iotaIOTA (IOTA) $ 0.233964
  • nervos-networkNervos Network (CKB) $ 0.017221
  • kavaKava (KAVA) $ 0.702083
  • frax-etherFrax Ether (FRXETH) $ 3,733.92
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.86
  • usddUSDD (USDD) $ 0.997679
  • theta-fuelTheta Fuel (TFUEL) $ 0.109844
  • dexeDeXe (DEXE) $ 12.23
  • klay-tokenKlaytn (KLAY) $ 0.188790
  • swethSwell Ethereum (SWETH) $ 3,934.45
  • livepeerLivepeer (LPT) $ 21.23
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,996.81
  • ocean-protocolOcean Protocol (OCEAN) $ 1.04
  • blurBlur (BLUR) $ 0.418219
  • bitcoin-goldBitcoin Gold (BTG) $ 38.39
  • axelarAxelar (AXL) $ 1.00
  • ethereum-name-serviceEthereum Name Service (ENS) $ 20.97
  • fraxFrax (FRAX) $ 0.998944
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000031
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000111
  • woo-networkWOO (WOO) $ 0.342635
  • oasis-networkOasis Network (ROSE) $ 0.093339
  • fasttokenFasttoken (FTN) $ 1.97
  • illuviumIlluvium (ILV) $ 95.46
  • notcoinNotcoin (NOT) $ 0.005885
  • mantra-daoMANTRA (OM) $ 0.746055
  • dydxdYdX (ETHDYDX) $ 2.15
  • pepecoin-2PepeCoin (PEPECOIN) $ 5.14
  • tether-goldTether Gold (XAUT) $ 2,423.28
  • curve-dao-tokenCurve DAO (CRV) $ 0.491059
  • osmosisOsmosis (OSMO) $ 0.897794
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 4,048.94
  • golemGolem (GLM) $ 0.568375
  • arkhamArkham (ARKM) $ 2.52
  • astarAstar (ASTR) $ 0.095908
  • xdce-crowd-saleXDC Network (XDC) $ 0.036099
  • wemix-tokenWEMIX (WEMIX) $ 1.49
  • enjincoinEnjin Coin (ENJ) $ 0.359416
  • aerodrome-financeAerodrome Finance (AERO) $ 1.15
  • jito-governance-tokenJito (JTO) $ 4.24
  • iotexIoTeX (IOTX) $ 0.054139
  • true-usdTrueUSD (TUSD) $ 1.00
  • memecoin-2Memecoin (MEME) $ 0.027463
  • superfarmSuperVerse (SUPER) $ 1.13
  • raydiumRaydium (RAY) $ 1.92
  • 1inch1inch (1INCH) $ 0.433511
  • celoCelo (CELO) $ 0.915362
  • ether-fiEther.fi (ETHFI) $ 4.24
  • 0x0x Protocol (ZRX) $ 0.574084
  • apenftAPENFT (NFT) $ 0.00000049
  • dymensionDymension (DYM) $ 2.81
  • stader-ethxStader ETHx (ETHX) $ 3,832.34
  • radixRadix (XRD) $ 0.045560
  • ankrAnkr Network (ANKR) $ 0.047046
  • stepnGMT (GMT) $ 0.232532
  • skaleSKALE (SKL) $ 0.091663
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.12
  • polymeshPolymesh (POLYX) $ 0.439723
  • mx-tokenMX (MX) $ 4.69
  • zilliqaZilliqa (ZIL) $ 0.024876
  • altlayerAltLayer (ALT) $ 0.335708
  • reserve-rights-tokenReserve Rights (RSR) $ 0.008980
  • venomVenom (VENOM) $ 0.271652
  • metis-tokenMetis (METIS) $ 79.18
  • compound-ethercETH (CETH) $ 75.08
  • based-brettBrett (BRETT) $ 0.053068
  • pax-goldPAX Gold (PAXG) $ 2,411.30
  • arcblockArcblock (ABT) $ 4.46
  • ravencoinRavencoin (RVN) $ 0.031718
  • zetachainZetaChain (ZETA) $ 1.65
  • nosanaNosana (NOS) $ 5.22
  • holotokenHolo (HOT) $ 0.002429
  • rocket-poolRocket Pool (RPL) $ 21.13
  • compound-governance-tokenCompound (COMP) $ 62.71
  • project-galaxyGalxe (GAL) $ 3.70
  • siacoinSiacoin (SC) $ 0.007448
  • terra-luna-2Terra (LUNA) $ 0.612127
  • biconomyBiconomy (BICO) $ 0.538590
  • qtumQtum (QTUM) $ 3.96

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

0 43

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

  coinedition.com 25 m

Malicious Code in Tornado Cash’s Governance Proposal Poses Risks 

Recent reports highlighted a malicious javascript code present in the two-month-old governance proposal introduced by the Tornado Cash community developer Butterfly Effects. According to the findings, the funds deposited since January 1, 2024, are at risk, posing a potential exploit.

Chinese crypto reporter Colin Wu shared an X post on his official page known as Wu Blockchain, providing insights on the vulnerability identified in the malicious proposal. According to his post, the governance proposal might have resulted in the leakage of the deposit notes of Tornado Cash to a private malicious server owned by the alleged developer since January 1.

The community has found that a malicious javascript code was hidden from the 2-month-old governance proposal made by the alleged Tornado Cash community developer Butterfly Effects from the previous governance proposal 44 and thus we estimate that since Jan 1st the deposit notes…

— Wu Blockchain (@WuBlockchain) February 25, 2024

Notably, the vulnerability is identified in the IPFS version of Tornado Cash. While Tornado Cash is a decentralized privacy solution for crypto transactions maintaining anonymity, the IPFS version is resistant to censorship and surveillance. Thus, the malicious code has become a “hidden trap” for the scammer, as the version would easily track them.

According to the SlowMist Founder Yu Xian, the malicious code in the IPFS version of Tornado Cash allows for the hijacking of deposit certificates. Though there are hints for some funds to be stolen since the approval of the proposal, it is unclear how many users are affected.

The community urges users to change their notes using the recommended IPFS ContextHash deployment which was previously used for tornadocash.eth. In addition, the community asked the users to vote to veto the previously deployed proposals to restrict any possible malicious exploit hidden on the proposal contract.

Last year, a hacker stole more than $1 million through a malicious governance proposal. Allegedly granting 1.2 million votes to the malevolent proposal, they gained control over Tornado Cash’s decentralized finance (DeFi) protocol, leading to the embezzlement of funds.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source

Leave A Reply

Your email address will not be published.