BTC $76,695.52 -0.73%
ETH $2,477.07 -1.90%
BNB $716.97 -1.41%
XRP $1.35 -1.45%
SOL $99.63 -1.96%
TRX $0.3378 -0.65%
DOGE $0.0824 -2.79%
ADA $0.2038 -1.88%
BCH $221.61 -2.08%
LINK $11.22 -2.44%
HYPE $77.58 -2.41%
AAVE $124.44 -1.18%
SUI $0.7020 -3.38%
XLM $0.1776 -1.32%
ZEC $1,059.54 -5.50%
AAPL $330.52 -0.73%
AMZN $254.67 -0.87%
GOOGL $335.78 -1.30%
MSFT $492.85 -0.59%
META $641.70 -1.04%
NVDA $214.61 -1.77%
TSLA $360.26 -2.00%
SNDK $1,557.82 -4.42%
INTC $98.96 -2.82%
SPCX $148.63 -1.04%
MU $939.11 -2.91%
AMD $501.57 -2.56%
BTC $76,695.52 -0.73%
ETH $2,477.07 -1.90%
BNB $716.97 -1.41%
XRP $1.35 -1.45%
SOL $99.63 -1.96%
TRX $0.3378 -0.65%
DOGE $0.0824 -2.79%
ADA $0.2038 -1.88%
BCH $221.61 -2.08%
LINK $11.22 -2.44%
HYPE $77.58 -2.41%
AAVE $124.44 -1.18%
SUI $0.7020 -3.38%
XLM $0.1776 -1.32%
ZEC $1,059.54 -5.50%
AAPL $330.52 -0.73%
AMZN $254.67 -0.87%
GOOGL $335.78 -1.30%
MSFT $492.85 -0.59%
META $641.70 -1.04%
NVDA $214.61 -1.77%
TSLA $360.26 -2.00%
SNDK $1,557.82 -4.42%
INTC $98.96 -2.82%
SPCX $148.63 -1.04%
MU $939.11 -2.91%
AMD $501.57 -2.56%

frozen

All
Article
Flash

MANTRA announces the review of the attack incident: A down-scaling vulnerability led to the transfer of over 720 million tokens, with approximately 37.96 million tokens frozen

On August 20, MANTRA Chain released a complete review report of the security incident, confirming that the attacker exploited an unsigned integer underflow vulnerability in the balance accounting layer of the upstream dependency cosmos/evm, unauthorizedly transferring a total of 720,923,967.99 MANTRA from two addresses, valued at approximately 3.6 million dollars based on the price before the attack. Among them, the attacker transferred 600,000,035.56 MANTRA from the on-chain burn address and 120,923,932.44 MANTRA from a genesis-era multi-signature address related to an early incentive program.MANTRA stated that this incident did not involve the leakage of validator keys, administrator privileges, governance control, or multi-signature signers; the attacker did not require privileged access and could complete the attack solely through unauthorized contract deployment and self-funded wallets. The first abnormal transfer occurred at 19:06 UTC on August 20, when the attacker transferred approximately 600 million MANTRA from the burn address; subsequently, at 22:59 UTC, another transfer of approximately 120.9 million MANTRA was made. The chain subsequently stopped operating at 23:13 UTC and resumed after upgrading to v8.4.0. The entire network interruption lasted for 30 hours and 13 minutes.This vulnerability was not an issue with MANTRA's self-developed code but originated from the cosmos/evm module, which is responsible for providing EVM functionality on the Cosmos SDK. The vulnerability allowed the attacker to execute unsigned balance deductions without checking if the balance was sufficient, causing an overflow of values and bypassing normal account authorization logic. MANTRA stated that as of today, no funds have been recovered, with approximately 37.96 million MANTRA (accounting for 5.27% of the total transferred) still remaining in the attacker's address, which has been frozen due to the chain's suspension and v8.4.0 restrictions. The remaining funds have flowed to related trading platforms, and the recovery efforts have entered the law enforcement investigation stage. In the future, monitoring of accounts that cannot normally authorize transfers, burn addresses, and other historically "non-transferable" addresses will be strengthened, and efforts will be made to promote improvements in the security vulnerability disclosure process within the Cosmos ecosystem.

Vietnamese police report on the progress of the ONUS cryptocurrency fraud case: over 350 kilograms of gold and silver have been seized and more than 300 bank accounts frozen

According to Vietnam's Youth Newspaper, the Ministry of Public Security of Vietnam recently held a press conference to report the latest investigation results of the ONUS cryptocurrency platform fraud case. More than 350 kilograms of gold and silver have been seized, transactions involving 8 properties valued at 20 trillion Vietnamese dong have been frozen, and transactions of over 300 involved bank accounts have been suspended.On March 23 of this year, the police filed criminal charges against 8 defendants, accusing them of using computer networks and telecommunications networks to commit property appropriation and money laundering. Since 2018, the individuals involved have taken advantage of the public's lack of understanding of cryptocurrency, creating digital accounts through applications and packaging them as virtual currency. They established trust and attracted investment through circular buying and selling among affiliated companies, thereby committing fund appropriation, with a total sale of cryptocurrency valued at over 70 trillion Vietnamese dong from 2018 to 2021.The case involves numerous individuals and users, with approximately 5 million user accounts opened. The police have received over 2000 reports from citizens. The public security authorities are investigating the possible accomplice responsibilities of KOLs and other internet celebrities and continue to make every effort to recover the embezzled funds.

Sovright launches Argos wallet recovery tool to help early Zcash users retrieve "frozen" funds

According to The Block, Sovright (the nonprofit successor organization related to Electric Coin Company for Zcash development) has officially released a wallet recovery tool named "Argos," aimed at helping early Zcash users recover funds that have been "stuck" due to the discontinuation of the old version of ZEC Wallet Lite in 2022.Sovright's Executive Board Chair Michelle Lai stated that Argos can recover affected assets as long as users still hold the old wallet mnemonic phrases, but since it only involves specific shielded addresses, the scale of the impact cannot be precisely estimated. However, it is estimated that the "amount is considerable," primarily concentrated among early long-term holders.She referred to the issue as a "technical pitfall" that the community has long failed to address, which, although not prominent, continues to erode user trust. Sovright currently consists of only three core members, all from the former Bootstrap system. The team is also testing a privacy-focused Zcash mining pool to reduce hash power centralization and enhance network decentralization.The governance structure of the organization has undergone significant adjustments, with Electric Coin Company employees collectively leaving to establish a new entity, Zcash Open Development Lab (ZODL), which has received support from institutions such as Paradigm and a16z, focusing on the development of Zcash-related products.Sovright emphasizes that there is no antagonistic relationship with ZODL and states that it will continue to focus on solving "long-standing issues" in the Zcash ecosystem, including key pain points such as wallet usability and infrastructure stability.
app_icon
ChainCatcher Building the Web3 world with innovations.