Crypto Paycheck
Photo by Mario Gogh on UnsplashEmployees will receive their paycheck in the period as a reward for their work. However, the employer wants to pay less to employees so that they can have maximum profits. The tension between working and anti-working has increased ever since. TL;DR Nobody wants to work unless they can pay fairly. Fiat payment may not be sustainable to satisfy what workers can contribute if the employer continues paying less and gaining more from profits. Employees will want thei...

Stablecoin Crisis
Stablecoin is in the crisis mode. The most reputable stablecoin USDC is depegged. It is all triggered by the traditional bank collapse - Silicon Valley Bank or SVB collapse. Why traditional bank collapse impacts crypto stablecoin? Let's sort this out and reveal how stablecoin operates. First, why SVB collapse? The short answer is overleveraged. SVB is one of the 20 largest commercial banking in the United States. Some even estimate the bank owned half of startup assets. Bank operated in ...

The only way
Technology isn't always directly translate to what we desire it to become. For example, we wish social media to become a place to keep in touch of others but it created another whole new level of distrust and misinformation that spread like a Pandemic. Be careful of your wishes! Like AI we think they can bring up a new level of the game in the creative industry and possibly to replace writers like you and me, but can they? It seems they are very powerful to execute what we want them to, ...
Crypto Paycheck
Photo by Mario Gogh on UnsplashEmployees will receive their paycheck in the period as a reward for their work. However, the employer wants to pay less to employees so that they can have maximum profits. The tension between working and anti-working has increased ever since. TL;DR Nobody wants to work unless they can pay fairly. Fiat payment may not be sustainable to satisfy what workers can contribute if the employer continues paying less and gaining more from profits. Employees will want thei...

Stablecoin Crisis
Stablecoin is in the crisis mode. The most reputable stablecoin USDC is depegged. It is all triggered by the traditional bank collapse - Silicon Valley Bank or SVB collapse. Why traditional bank collapse impacts crypto stablecoin? Let's sort this out and reveal how stablecoin operates. First, why SVB collapse? The short answer is overleveraged. SVB is one of the 20 largest commercial banking in the United States. Some even estimate the bank owned half of startup assets. Bank operated in ...

The only way
Technology isn't always directly translate to what we desire it to become. For example, we wish social media to become a place to keep in touch of others but it created another whole new level of distrust and misinformation that spread like a Pandemic. Be careful of your wishes! Like AI we think they can bring up a new level of the game in the creative industry and possibly to replace writers like you and me, but can they? It seems they are very powerful to execute what we want them to, ...
Share Dialog
Share Dialog

Subscribe to xuanling11

Subscribe to xuanling11

The phishing attack was rigged BadgerDao. As a result, the Defi solution that runs on the top of the Ethereum blockchain has lost more than $130M.
Here is a 1 min summary of the article if you want to skip the reading.
Type of Phishing Attack
Cloudflare Workers had a weak point where it allowed users to create accounts and view global API keys before email verification was completed. Unfortunately, this creates a loophole that allows attackers to gain API access for specific users.
On-Chain Malicious Approval
The attacker used their API access to inject malicious code through Cloudflare Workers, intercepted web3 transactions, and allowed a foreign address approval to operate on ERC-20 tokens in their wallet.
Undetected Mechanics
Attackers had several anti-detection techniques, applied and removed their scrip periodically, and used multiply proxy and VPN IP addresses to hide their true identities.
What Has Really Happened
In plaint English, attackers could create a fake account but without needing to verify their email addresses. And they were able to access users’ data from the database. They can even create their own applications to intercept users’ transactions and create a fake address to execute code and send their funds into the address without letting the administrator to aware of any suspicious activities.
Layer 2 Is Unsecured
The problem of any Defi projects is they launch as quickly without ever letting security audit. When the platform connects to the internet, there are possibilities of attacking from everywhere, 24/7. There is a need for the security protocol of each transaction to execute within the blockchain than moving actual funds on layer 2.
In Conclusion
Many hacking incidents caused multiple million dollars to lose. So when can people learn a lesson without losing their clients’ money?

The phishing attack was rigged BadgerDao. As a result, the Defi solution that runs on the top of the Ethereum blockchain has lost more than $130M.
Here is a 1 min summary of the article if you want to skip the reading.
Type of Phishing Attack
Cloudflare Workers had a weak point where it allowed users to create accounts and view global API keys before email verification was completed. Unfortunately, this creates a loophole that allows attackers to gain API access for specific users.
On-Chain Malicious Approval
The attacker used their API access to inject malicious code through Cloudflare Workers, intercepted web3 transactions, and allowed a foreign address approval to operate on ERC-20 tokens in their wallet.
Undetected Mechanics
Attackers had several anti-detection techniques, applied and removed their scrip periodically, and used multiply proxy and VPN IP addresses to hide their true identities.
What Has Really Happened
In plaint English, attackers could create a fake account but without needing to verify their email addresses. And they were able to access users’ data from the database. They can even create their own applications to intercept users’ transactions and create a fake address to execute code and send their funds into the address without letting the administrator to aware of any suspicious activities.
Layer 2 Is Unsecured
The problem of any Defi projects is they launch as quickly without ever letting security audit. When the platform connects to the internet, there are possibilities of attacking from everywhere, 24/7. There is a need for the security protocol of each transaction to execute within the blockchain than moving actual funds on layer 2.
In Conclusion
Many hacking incidents caused multiple million dollars to lose. So when can people learn a lesson without losing their clients’ money?
<100 subscribers
<100 subscribers
No activity yet