• bitcoinBitcoin (BTC) $ 96,659.00
  • ethereumEthereum (ETH) $ 2,718.16
  • xrpXRP (XRP) $ 2.71
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 199.43
  • bnbBNB (BNB) $ 664.39
  • usd-coinUSDC (USDC) $ 0.999898
  • dogecoinDogecoin (DOGE) $ 0.270842
  • cardanoCardano (ADA) $ 0.803009
  • staked-etherLido Staked Ether (STETH) $ 2,718.01
  • tronTRON (TRX) $ 0.231610
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 96,561.00
  • chainlinkChainlink (LINK) $ 19.30
  • suiSui (SUI) $ 3.60
  • avalanche-2Avalanche (AVAX) $ 26.40
  • wrapped-stethWrapped stETH (WSTETH) $ 3,236.86
  • stellarStellar (XLM) $ 0.347871
  • shiba-inuShiba Inu (SHIB) $ 0.000017
  • hedera-hashgraphHedera (HBAR) $ 0.229106
  • litecoinLitecoin (LTC) $ 125.99
  • the-open-networkToncoin (TON) $ 3.82
  • hyperliquidHyperliquid (HYPE) $ 27.45
  • leo-tokenLEO Token (LEO) $ 9.82
  • usdsUSDS (USDS) $ 0.999997
  • wethWETH (WETH) $ 2,718.17
  • polkadotPolkadot (DOT) $ 5.21
  • bitcoin-cashBitcoin Cash (BCH) $ 342.58
  • bitget-tokenBitget Token (BGB) $ 5.48
  • uniswapUniswap (UNI) $ 10.05
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • wrapped-eethWrapped eETH (WEETH) $ 2,878.92
  • mantra-daoMANTRA (OM) $ 5.47
  • pepePepe (PEPE) $ 0.000010
  • official-trumpOfficial Trump (TRUMP) $ 21.22
  • moneroMonero (XMR) $ 231.60
  • ondo-financeOndo (ONDO) $ 1.34
  • nearNEAR Protocol (NEAR) $ 3.50
  • aaveAave (AAVE) $ 261.66
  • whitebitWhiteBIT Coin (WBT) $ 27.07
  • aptosAptos (APT) $ 6.09
  • daiDai (DAI) $ 1.00
  • internet-computerInternet Computer (ICP) $ 7.24
  • mantleMantle (MNT) $ 1.03
  • bittensorBittensor (TAO) $ 392.03
  • susdssUSDS (SUSDS) $ 1.03
  • ethereum-classicEthereum Classic (ETC) $ 21.40
  • okbOKB (OKB) $ 52.21
  • gatechain-tokenGate (GT) $ 23.42
  • vechainVeChain (VET) $ 0.035297
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.318555
  • kaspaKaspa (KAS) $ 0.105677
  • jupiter-exchange-solanaJupiter (JUP) $ 0.959636
  • algorandAlgorand (ALGO) $ 0.298589
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 96,613.00
  • crypto-com-chainCronos (CRO) $ 0.091133
  • render-tokenRender (RENDER) $ 4.68
  • tokenize-xchangeTokenize Xchange (TKX) $ 29.82
  • filecoinFilecoin (FIL) $ 3.49
  • arbitrumArbitrum (ARB) $ 0.499805
  • cosmosCosmos Hub (ATOM) $ 4.92
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.809156
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998529
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 96,726.00
  • sonic-3Sonic (prev. FTM) (S) $ 0.543834
  • fasttokenFasttoken (FTN) $ 3.95
  • celestiaCelestia (TIA) $ 3.20
  • lido-daoLido DAO (LDO) $ 1.88
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,722.13
  • binance-staked-solBinance Staked SOL (BNSOL) $ 206.85
  • optimismOptimism (OP) $ 1.17
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,821.22
  • raydiumRaydium (RAY) $ 5.37
  • xdce-crowd-saleXDC Network (XDC) $ 0.097455
  • kucoin-sharesKuCoin (KCS) $ 12.19
  • injective-protocolInjective (INJ) $ 15.27
  • blockstackStacks (STX) $ 0.986078
  • ethenaEthena (ENA) $ 0.472656
  • bonkBonk (BONK) $ 0.000019
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 96,671.00
  • immutable-xImmutable (IMX) $ 0.812984
  • theta-tokenTheta Network (THETA) $ 1.42
  • nexoNEXO (NEXO) $ 1.38
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,052.90
  • the-graphThe Graph (GRT) $ 0.142898
  • movementMovement (MOVE) $ 0.564881
  • worldcoin-wldWorldcoin (WLD) $ 1.27
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,872.01
  • flare-networksFlare (FLR) $ 0.021209
  • usual-usdUsual USD (USD0) $ 0.997907
  • jasmycoinJasmyCoin (JASMY) $ 0.022991
  • sei-networkSei (SEI) $ 0.242853
  • galaGALA (GALA) $ 0.024069
  • dexeDeXe (DEXE) $ 18.16
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 95,996.00
  • msolMarinade Staked SOL (MSOL) $ 253.22
  • jito-governance-tokenJito (JTO) $ 3.38
  • eosEOS (EOS) $ 0.654514
  • the-sandboxThe Sandbox (SAND) $ 0.402785
  • flokiFLOKI (FLOKI) $ 0.000100
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.44
  • tezosTezos (XTZ) $ 0.902141
  • ethereum-name-serviceEthereum Name Service (ENS) $ 27.26
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,815.30
  • iotaIOTA (IOTA) $ 0.242436
  • bittorrentBitTorrent (BTT) $ 0.00000088
  • makerMaker (MKR) $ 1,009.16
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 216.60
  • flowFlow (FLOW) $ 0.529632
  • ultimaUltima (ULTIMA) $ 19,251.14
  • wbnbWrapped BNB (WBNB) $ 665.75
  • neoNEO (NEO) $ 11.41
  • bitcoin-svBitcoin SV (BSV) $ 40.12
  • kaiaKaia (KAIA) $ 0.133326
  • spx6900SPX6900 (SPX) $ 0.827848
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 96,466.00
  • roninRonin (RON) $ 1.24
  • pyth-networkPyth Network (PYTH) $ 0.210680
  • dogwifcoindogwifhat (WIF) $ 0.736965
  • usddUSDD (USDD) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.55
  • chain-2Onyxcoin (XCN) $ 0.022297
  • tether-goldTether Gold (XAUT) $ 2,898.41
  • axie-infinityAxie Infinity (AXS) $ 4.49
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.271504
  • heliumHelium (HNT) $ 3.91
  • curve-dao-tokenCurve DAO (CRV) $ 0.534929
  • telcoinTelcoin (TEL) $ 0.008704
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 2,871.88
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010731
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,717.08
  • elrond-erd-2MultiversX (EGLD) $ 23.46
  • aerodrome-financeAerodrome Finance (AERO) $ 0.832493
  • berachain-beraBerachain (BERA) $ 5.87
  • fraxFrax (FRAX) $ 0.995427
  • decentralandDecentraland (MANA) $ 0.337880
  • usdx-money-usdxusdx.money USDX (USDX) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999074
  • starknetStarknet (STRK) $ 0.237641
  • arweaveArweave (AR) $ 9.33
  • pax-goldPAX Gold (PAXG) $ 2,922.21
  • beam-2Beam (BEAM) $ 0.011290
  • chilizChiliz (CHZ) $ 0.062523
  • pendlePendle (PENDLE) $ 3.56
  • conflux-tokenConflux (CFX) $ 0.119082
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,728.87
  • dydx-chaindYdX (DYDX) $ 0.797369
  • matic-networkPolygon (MATIC) $ 0.318515
  • resolv-usrResolv USR (USR) $ 0.999936
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,714.71
  • pumpbtcpumpBTC (PUMPBTC) $ 94,482.00
  • coredaoorgCore (CORE) $ 0.571252
  • meowMEOW (MEOW) $ 0.006144
  • insurance-2INSURANCE (INSURANCE) $ 29.21
  • fartcoinFartcoin (FARTCOIN) $ 0.541265
  • apecoinApeCoin (APE) $ 0.747590
  • ai16zai16z (AI16Z) $ 0.489184
  • ecasheCash (XEC) $ 0.000027
  • zcashZcash (ZEC) $ 33.17
  • wormholeWormhole (W) $ 0.183289
  • kavaKava (KAVA) $ 0.484989
  • beldexBeldex (BDX) $ 0.075094
  • compound-governance-tokenCompound (COMP) $ 57.73
  • aioz-networkAIOZ Network (AIOZ) $ 0.440257
  • thorchainTHORChain (RUNE) $ 1.41
  • true-usdTrueUSD (TUSD) $ 0.997643
  • morphoMorpho (MORPHO) $ 2.18
  • newton-projectAB DAO (AB) $ 0.011071
  • amp-tokenAmp (AMP) $ 0.005822
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,120.00
  • reserve-rights-tokenReserve Rights (RSR) $ 0.008826
  • clbtcclBTC (CLBTC) $ 96,744.00
  • akash-networkAkash Network (AKT) $ 1.92
  • story-2Story (IP) $ 1.87
  • based-brettBrett (BRETT) $ 0.046083
  • gnosisGnosis (GNO) $ 174.98
  • chex-tokenCHEX Token (CHEX) $ 0.449419
  • tbtctBTC (TBTC) $ 96,500.00
  • quantixaiQuantixAI (QAI) $ 84.84
  • mina-protocolMina Protocol (MINA) $ 0.360107
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000080
  • stakestone-berachain-vault-tokenStakeStone Berachain Vault Token (BERASTONE) $ 2,703.04
  • axelarAxelar (AXL) $ 0.477363
  • apenftAPENFT (NFT) $ 0.00000044
  • eigenlayerEigenlayer (EIGEN) $ 1.74
  • deepDeepBook (DEEP) $ 0.170909
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 1.00
  • olympusOlympus (OHM) $ 25.53
  • zksyncZKsync (ZK) $ 0.111949
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 2,965.08
  • grassGrass (GRASS) $ 1.69
  • super-oethSuper OETH (SUPEROETHB) $ 2,719.32
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • hashnote-usycHashnote USYC (USYC) $ 1.08
  • usdbUSDB (USDB) $ 0.991957
  • verus-coinVerus (VRSC) $ 5.04
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.949098
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 2,721.30
  • 1inch1inch (1INCH) $ 0.271240
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • echelon-primeEchelon Prime (PRIME) $ 6.78

Some white hat hacker behavior is ‘weird,’ Ledger CTO says

0 97

Some white hat hacker behavior is ‘weird,’ Ledger CTO says

  blockworks.co 5 h

Some white hat hacker behavior is ‘weird,’ Ledger CTO says

The back and forth between CertiK and Kraken this week left more questions than answers.

So to get some potential answers — and to pick his brain — Blockworks chatted with Ledger Chief Technology Officer Charles Guillemet.

Outside of the use of Tornado Cash by the US-based CertiK, he also highlighted the withdrawal of XMR — a privacy coin on Monero, in case you’ve skipped some of Empire’s previous segments — as suspicious because, well, it’s a privacy coin.

Add ChangeNow, a self-styled non-custodial exchange, into the mix. In Guillemet’s experience, ChangeNow is generally one of the top picks for attackers who are trying to hide crypto. It’s often used by bad actors because it doesn’t require proper KYC checks before facilitating swaps from one token to another.

It was also weird that there were video calls between CertiK and Kraken. And don’t even get him started on the millions withdrawn (he maintains you can exploit as little as $5 to prove the bug and then report it for a bounty).

However, the five-day time period in which the researchers were testing the exploit isn’t that strange.

“So the five day period is not suspicious, per se. But what is suspicious is what they did during the meantime,” he told Blockworks.

The silver lining in this is the speed in which Kraken assessed the issue (47 minutes, according to Kraken’s Chief Security Officer Nick Percoco) and investigated the issue.

“Kraken had everything in place in order to verify what happened on their platform and to find out that the vulnerability was actually exploited several times, by three accounts and not only by one,” he added.

Guillemet was in the security world before swapping over to crypto in 2017.

With that experience, he said that the “behavior that we see in blockchain and crypto when it comes to white hat [hacking] is really weird from my standpoint.”

Read more from our opinion section: We need to talk about the dangers of custody on exchanges

“Sometimes you have a white hat, supposedly, who finds a vulnerability on some smart contract. It completely drains the smart contract and then gives back like 90%, choosing its reward [of] 10%. This kind of behavior, for me, is extortion. It seems to be okay. It seems to be white hat behavior,” Guillemet continued.“But I completely disagree with this. When you do security research, you don’t choose your reward.”

“In crypto, it’s not always the case, and it’s a bit disturbing for me, and it’s also disturbing for other security guys in the field.”

CertiK said it wasn’t trying to exploit or “extort” funds from the exchange, unlike claims made by Percoco. On Thursday, Kraken confirmed it received the funds back sans a bit lost to fees.

The simplest way to improve the space is obviously investing in security, but the more difficult path forward is for security teams to stay humble, Guillemet said.

“Attackers will get better and better and we as an ecosystem must be humble and always raise the bar for security because this is a cat-and-mouse game and the stakes are getting higher.”

A shorter version of this article appeared in Friday’s Empire Newsletter. Sign up here to never miss an issue.

Source

Leave A Reply

Your email address will not be published.