Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Ethereum platform. Show all posts

MetaMask Takes Precautionary Action After Infrastructure Security Incident

 

Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences surrounding Ethereum staking. The company has remained silent on the details concerning the systems that were compromised or whether information or infrastructure was at risk as the breach occurred. A spokesperson for MetaMask directed queries towards the company’s public statement on the issue. 

The company announced that it is addressing the matter internally with the help of external partners and security advisers while noting that there are no immediate risks to MetaMask wallets. The response to the incident involved changes to the non-custodial staking operations at MetaMask as the firm continues to remove the affected validators in collaboration with partners and clients while mitigating any further risks that may arise. 

The company is quick to note that its staking service is non-custodial meaning that it does not possess the withdrawal keys to the stakes deposited by clients. This is an important observation as the response to the security incident only involves the staking infrastructure and not the management of the deposits by clients. Part of the precautions being taken are affecting the validators through the Lido protocol as the firm announced that MetaMask Staking, previously known as Consensys Staking, had initiated protective measures for the clients’ assets on the Ethereum blockchain. 

The procedure involved transitioning the Ethereum validators operated by Lido Finance to the exit process. The changes to the validators through the Lido protocol will cause disruptions to the staking processes and may result in economic losses to the clients who have chosen to use the staking services. This occurs as the validators are being exited to mitigate the risks posed by the security incident affecting the Ethereum network. The Lido protocol further noted that the affected validators had begun exiting the protocol while also stating that the last validator would exit by October 7th. 

However, the date does not signify the day when the validators will have exited completely as some of them might be offline as of the 7th . Validators are critical to the operations of the Ethereum network as they propose new blocks, verify transactions and secure the network through their specialized software. As such, it will require significant efforts to ensure the adjustments made to the validators do not cause disruptions to staking processes while eliminating risks to the stakeholders who utilize the MetaMask services. 

MetaMask has not released further details concerning the security incident and its impact on the infrastructures that support its operations. For now, the company is focusing on addressing the effects of the incident while collaborating with external security advisers and partners. MetaMask is a crypto wallet provider whose products are developed by blockchain software company Consensys. It offers non-custodial crypto wallet solutions for individuals and organizations while allowing them to store their digital assets on the Ethereum network and other compatible blockchains.

Hacker Generates 1 Billion CGT Tokens Valued at $40 Million within Curio Ecosystem

 

The Curio decentralized finance (DeFi) initiative encountered a breach, with experts from Cyvers Alerts approximating the incurred losses to be around $16 million. The breach appears to have been orchestrated through an exploitation of vulnerabilities within the permissioned access logic, allowing the attacker to generate an additional 1 billion CGT tokens, as per analysts at Cyvers Alerts. 

This breach consequently enabled the hacker to gain control over CGT tokens valued at close to $40 million. These findings from Cyvers Alerts come in the wake of a prior warning issued by Curio regarding a potential smart contract exploit.

Cyvers Alerts further highlighted that the compromised smart contract, which was based on MakerDAO, was a component of the ecosystem operating on the Ethereum platform. This revelation underscores the significance of ensuring robust security measures within smart contracts to mitigate such risks effectively.

Reassuringly, the Curio Ecosystem team has promptly responded to the breach, affirming their active engagement in addressing the situation. They have pledged to keep the community informed with updates on the progress of their efforts. Additionally, they emphasized that despite this incident, all contracts on the Polkadot side and within the Curio Chain ecosystem remain secure, aiming to instill confidence among users regarding the integrity of their platform.

In a broader context, the crypto industry witnessed a decline in losses attributed to hacks and scams during February, amounting to approximately $67 million, representing a notable decrease from the figures reported in January. Notably, all reported breaches during February were linked to the decentralized finance (defi) sector, with centralized platforms notably avoiding any significant incidents.

Delving into the specifics, the majority of losses incurred during February were attributed to breaches affecting platforms such as the gaming platform PlayDapp, which suffered.