Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

No link to story available

Blockchain Startup Hacked Itself to ‘save’ $13M of its Users’ Cryptocurrency

Accepted submission by upstart at 2019-06-09 00:49:52
/dev/random

████ This a bot sub and needs many a editing, ████

Submitted via IRC for SoyCow4463

Blockchain startup hacked itself to ‘save’ $13M of its users’ cryptocurrency [thenextweb.com]

A blockchain startup hacked its users’ wallets to save $13 million in Bitcoin and other cryptocurrency from being stolen, ZDNet [zdnet.com] reports.

Security researchers advised the Komodo Platform of a ‘backdoor‘ in Agama, one of its older wallet apps, that would have allowed hackers to siphon any and all digital assets held inside.

Before that could happen, devs made use of the the flaw themselvesto extract at-risk cryptocurrency to wallets under their control.

In total, Komodo’s team says it ‘saved’ 96 BTC ($742K) and 8 million Komodo ($11.92M) from potential theft. The controlled funds can be viewed here [blockchain.com] and here [kmdexplorer.io].

Bad actors are said to have smuggled the backdoor into Agama by contributing useful code and updating it to include security vulnerabilities at a later date.

“The attack was carried out by using a pattern that is becoming more and more popular; publishing a ‘useful’ package […], waiting until it was in use by the target, and then updating it to include a malicious payload,” explained [npmjs.org] the firm that discovered the flaw.

A blog post [komodoplatform.com] advised affected Komodo users to reclaim their swept cryptocurrency by visiting its support page [komodoplatform.com]. The team also urged anyone who may have used its old wallet, Agama, to move any stored funds to an alternate (and safe wallet) as soon as possible.

Internet baddies regularly target cryptocurrency wallet apps. Indeed, popular Bitcoin wallet Electrum has been under siege for months [thenextweb.com], which estimates suggest has amounted to at least 771 BTC ($5.9M) in lost cryptocurrency.

Read more


Original Submission