• bitcoinBitcoin (BTC) $ 61,245.00
  • ethereumEthereum (ETH) $ 3,387.68
  • tetherTether (USDT) $ 0.998810
  • bnbBNB (BNB) $ 573.92
  • solanaSolana (SOL) $ 136.32
  • staked-etherLido Staked Ether (STETH) $ 3,386.86
  • usd-coinUSDC (USDC) $ 0.999384
  • xrpXRP (XRP) $ 0.477647
  • the-open-networkToncoin (TON) $ 7.56
  • dogecoinDogecoin (DOGE) $ 0.123484
  • cardanoCardano (ADA) $ 0.386611
  • tronTRON (TRX) $ 0.120004
  • shiba-inuShiba Inu (SHIB) $ 0.000017
  • avalanche-2Avalanche (AVAX) $ 25.17
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,362.00
  • chainlinkChainlink (LINK) $ 14.07
  • polkadotPolkadot (DOT) $ 5.79
  • bitcoin-cashBitcoin Cash (BCH) $ 376.53
  • uniswapUniswap (UNI) $ 9.47
  • nearNEAR Protocol (NEAR) $ 5.60
  • wrapped-eethWrapped eETH (WEETH) $ 3,518.29
  • leo-tokenLEO Token (LEO) $ 5.75
  • matic-networkPolygon (MATIC) $ 0.569019
  • litecoinLitecoin (LTC) $ 70.72
  • daiDai (DAI) $ 0.998689
  • pepePepe (PEPE) $ 0.000012
  • fetch-aiFetch.ai (FET) $ 1.69
  • internet-computerInternet Computer (ICP) $ 8.16
  • kaspaKaspa (KAS) $ 0.155750
  • ethena-usdeEthena USDe (USDE) $ 0.999004
  • ethereum-classicEthereum Classic (ETC) $ 23.43
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,418.51
  • aptosAptos (APT) $ 6.95
  • render-tokenRender (RNDR) $ 7.77
  • moneroMonero (XMR) $ 162.73
  • hedera-hashgraphHedera (HBAR) $ 0.078977
  • cosmosCosmos Hub (ATOM) $ 6.97
  • arbitrumArbitrum (ARB) $ 0.826001
  • stellarStellar (XLM) $ 0.090240
  • filecoinFilecoin (FIL) $ 4.42
  • mantleMantle (MNT) $ 0.761917
  • okbOKB (OKB) $ 41.38
  • crypto-com-chainCronos (CRO) $ 0.090651
  • immutable-xImmutable (IMX) $ 1.57
  • blockstackStacks (STX) $ 1.61
  • injective-protocolInjective (INJ) $ 23.08
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999378
  • suiSui (SUI) $ 0.900681
  • lido-daoLido DAO (LDO) $ 2.43
  • the-graphThe Graph (GRT) $ 0.222320
  • vechainVeChain (VET) $ 0.025736
  • makerMaker (MKR) $ 2,204.18
  • optimismOptimism (OP) $ 1.78
  • bittensorBittensor (TAO) $ 282.82
  • arweaveArweave (AR) $ 29.58
  • dogwifcoindogwifhat (WIF) $ 1.90
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,759.67
  • ondo-financeOndo (ONDO) $ 1.22
  • flokiFLOKI (FLOKI) $ 0.000176
  • fantomFantom (FTM) $ 0.603076
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,512.83
  • theta-tokenTheta Network (THETA) $ 1.56
  • bitget-tokenBitget Token (BGB) $ 1.10
  • jasmycoinJasmyCoin (JASMY) $ 0.031409
  • based-brettBrett (BRETT) $ 0.153447
  • bonkBonk (BONK) $ 0.000023
  • notcoinNotcoin (NOT) $ 0.014463
  • thorchainTHORChain (RUNE) $ 4.17
  • aaveAave (AAVE) $ 91.35
  • whitebitWhiteBIT Coin (WBT) $ 9.31
  • celestiaCelestia (TIA) $ 6.90
  • coredaoorgCore (CORE) $ 1.37
  • eosEOS (EOS) $ 0.573961
  • pyth-networkPyth Network (PYTH) $ 0.325714
  • sei-networkSei (SEI) $ 0.376942
  • algorandAlgorand (ALGO) $ 0.138545
  • quant-networkQuant (QNT) $ 75.13
  • jupiter-exchange-solanaJupiter (JUP) $ 0.791251
  • galaGALA (GALA) $ 0.028375
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,418.54
  • flare-networksFlare (FLR) $ 0.023559
  • gatechain-tokenGate (GT) $ 7.62
  • ethenaEthena (ENA) $ 0.566455
  • flowFlow (FLOW) $ 0.631539
  • starknetStarknet (STRK) $ 0.723225
  • pendlePendle (PENDLE) $ 5.96
  • kucoin-sharesKuCoin (KCS) $ 9.52
  • axie-infinityAxie Infinity (AXS) $ 6.15
  • zebec-protocolZebec Protocol (ZBC) $ 0.017756
  • singularitynetSingularityNET (AGIX) $ 0.697643
  • bitcoin-svBitcoin SV (BSV) $ 44.74
  • tokenize-xchangeTokenize Xchange (TKX) $ 10.55
  • bittorrentBitTorrent (BTT) $ 0.00000086
  • dydx-chaindYdX (DYDX) $ 1.41
  • beam-2Beam (BEAM) $ 0.016658
  • elrond-erd-2MultiversX (EGLD) $ 29.69
  • neoNEO (NEO) $ 11.33
  • tezosTezos (XTZ) $ 0.783088
  • ordinalsORDI (ORDI) $ 36.63
  • gnosisGnosis (GNO) $ 296.43
  • the-sandboxThe Sandbox (SAND) $ 0.330822
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,445.98
  • worldcoin-wldWorldcoin (WLD) $ 2.97
  • msolMarinade Staked SOL (MSOL) $ 162.69
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.40
  • roninRonin (RON) $ 2.20
  • akash-networkAkash Network (AKT) $ 3.03
  • usddUSDD (USDD) $ 0.994305
  • layerzeroLayerZero (ZRO) $ 2.81
  • fasttokenFasttoken (FTN) $ 2.21
  • chilizChiliz (CHZ) $ 0.078088
  • havvenSynthetix Network (SNX) $ 2.07
  • frax-etherFrax Ether (FRXETH) $ 3,378.37
  • nexoNEXO (NEXO) $ 1.16
  • fraxFrax (FRAX) $ 0.996216
  • conflux-tokenConflux (CFX) $ 0.155755
  • ecasheCash (XEC) $ 0.000032
  • wormholeWormhole (W) $ 0.354512
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,636.63
  • dexeDeXe (DEXE) $ 11.13
  • book-of-memeBOOK OF MEME (BOME) $ 0.009108
  • zksyncZKsync (ZK) $ 0.169550
  • decentralandDecentraland (MANA) $ 0.336731
  • lido-staked-solLido Staked SOL (STSOL) $ 160.74
  • oasis-networkOasis Network (ROSE) $ 0.092226
  • apecoinApeCoin (APE) $ 0.984174
  • mina-protocolMina Protocol (MINA) $ 0.546823
  • safeSafe (SAFE) $ 1.41
  • mantra-daoMANTRA (OM) $ 0.716288
  • iotaIOTA (IOTA) $ 0.178961
  • swethSwell Ethereum (SWETH) $ 3,587.87
  • klay-tokenKlaytn (KLAY) $ 0.157779
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.16
  • tether-goldTether Gold (XAUT) $ 2,326.89
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.005670
  • livepeerLivepeer (LPT) $ 16.84
  • heliumHelium (HNT) $ 3.29
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,689.89
  • nervos-networkNervos Network (CKB) $ 0.011593
  • mog-coinMog Coin (MOG) $ 0.000001
  • 1inch1inch (1INCH) $ 0.400863
  • kavaKava (KAVA) $ 0.461173
  • true-usdTrueUSD (TUSD) $ 0.997577
  • theta-fuelTheta Fuel (TFUEL) $ 0.074429
  • aioz-networkAIOZ Network (AIOZ) $ 0.442847
  • xdce-crowd-saleXDC Network (XDC) $ 0.031925
  • rocket-poolRocket Pool (RPL) $ 23.22
  • arkhamArkham (ARKM) $ 2.02
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.092985
  • bitcoin-goldBitcoin Gold (BTG) $ 26.27
  • ocean-protocolOcean Protocol (OCEAN) $ 0.699455
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000081
  • apenftAPENFT (NFT) $ 0.00000045
  • stader-ethxStader ETHx (ETHX) $ 3,479.93
  • illuviumIlluvium (ILV) $ 65.00
  • pax-goldPAX Gold (PAXG) $ 2,313.83
  • aevo-exchangeAevo (AEVO) $ 0.510702
  • blurBlur (BLUR) $ 0.252040
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.02
  • turboTurbo (TURBO) $ 0.005951
  • memecoin-2Memecoin (MEME) $ 0.020063
  • woo-networkWOO (WOO) $ 0.215566
  • curve-dao-tokenCurve DAO (CRV) $ 0.324877
  • usdbUSDB (USDB) $ 0.999917
  • paypal-usdPayPal USD (PYUSD) $ 0.998235
  • axelarAxelar (AXL) $ 0.574929
  • corgiaiCorgiAI (CORGIAI) $ 0.001164
  • raydiumRaydium (RAY) $ 1.51
  • magaMAGA (TRUMP) $ 8.45
  • popcatPopcat (POPCAT) $ 0.389984
  • astarAstar (ASTR) $ 0.068081
  • echelon-primeEchelon Prime (PRIME) $ 9.47
  • iotexIoTeX (IOTX) $ 0.040778
  • wemix-tokenWEMIX (WEMIX) $ 1.05
  • ether-fiEther.fi (ETHFI) $ 3.31
  • dydxdYdX (ETHDYDX) $ 1.41
  • mx-tokenMX (MX) $ 3.82
  • aerodrome-financeAerodrome Finance (AERO) $ 0.729630
  • osmosisOsmosis (OSMO) $ 0.548192
  • pepecoin-2PepeCoin (PEPECOIN) $ 3.11
  • golemGolem (GLM) $ 0.363361
  • compound-ethercETH (CETH) $ 68.06
  • kusamaKusama (KSM) $ 23.88
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000017
  • stepnGMT (GMT) $ 0.165416
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.003931
  • safepalSafePal (SFP) $ 0.751678
  • aragonAragon (ANT) $ 8.68
  • compound-governance-tokenCompound (COMP) $ 49.44
  • manta-networkManta Network (MANTA) $ 1.03
  • holotokenHolo (HOT) $ 0.001846
  • polymeshPolymesh (POLYX) $ 0.306262
  • zilliqaZilliqa (ZIL) $ 0.017504
  • ioio.net (IO) $ 3.38
  • celoCelo (CELO) $ 0.596757
  • 0x0x Protocol (ZRX) $ 0.370958
  • ankrAnkr Network (ANKR) $ 0.031124
  • biconomyBiconomy (BICO) $ 0.383840
  • compound-wrapped-btccWBTC (CWBTC) $ 1,230.06
  • superfarmSuperVerse (SUPER) $ 0.678292

Resonance Security flags concerns over potential metadata misuse in Runes

0 27

Resonance Security flags concerns over potential metadata misuse in Runes

  crypto.news 1 h

Resonance Security flags concerns over potential metadata misuse in Runes

Resonance Security analysts uncovered a potential vulnerability in the Runes protocol, highlighting concerns of exploitation by bad actors in the crypto space.

The Runes protocol, which operates as a native Bitcoin protocol aiming to streamline the creation of fungible tokens on the Bitcoin network, appears to have a significant red flag in its functionality, opening doors for potential misuse, according to a research report conducted by Resonance Security and seen by crypto.news.

Unlike its counterpart, the Ordinals protocol, which inscribes data to individual satoshis on the chain, Runes focuses on creating interchangeable tokens through the use of the Unspent Transaction Output (UTXO) model.

Resonance Security flags concerns over potential metadata misuse in Runes

An example Runestone struct capable of inputting a URL into the token’s metadata | Source: Resonance Security

Despite its promising functionality, the protocol apparently allows the inclusion of URLs in the metadata of Runes tokens, making it possible for potential exploitation by malicious actors, the security experts warn.

“[…] malicious URLs are often involved in phishing attacks, malware infections, and many other cyber violations. So, what’s stopping the bad guys from using this metadata allowance for their own nefarious purposes? Nothing.”

Resonance Security

You might also like: Runes is making Bitcoin fun and accessible again | Opinion

The experts said that because of blockchain’s unchangeable and clear way of recording data, malicious URL links can stay around forever, making the problem worse.

Illustrating the potential threat, the Resonance Security team outlined a hypothetical scenario where an attacker could embed a malicious URL within a Runes token and initiate an airdrop campaign to distribute the token widely. Unsuspecting users, enticed by promised rewards, could fall victim to phishing sites upon clicking the URL, compromising their sensitive information.

“While the emergence of protocols like Runes brings exciting opportunities for expanding the functionality, development, and ecosystems of Bitcoin, and blockchain technology as a whole, it also underscores the importance of remaining vigilant in the face of potential cybersecurity risks.”

Resonance Security

Although the Resonance Security team didn’t attribute any malicious intent to the creators of the Runes protocol, they highlighted the critical importance of identifying and addressing potential cybersecurity risks in developing blockchain protocols.

Read more: Bitcoin Runes activity drops significantly, weeks after generating $135m in fees

Source

Leave A Reply

Your email address will not be published.