Polygon CSO blames Web2 security gaps for recent spate of hacks

0

[ad_1]

Polygon Chief Security Officer Mudit Gupta has urged Web3 companies to hire traditional security experts to put an end to easily preventable hacks, arguing that perfect code and cryptography are not enough. 

Speaking to Cointelegraph, Gupta outlined that several of the recent hacks in crypto were ultimately a result of Web2 security vulnerabilities such as private key management and phishing attacks to gain logins, rather than poorly designed blockchain tech.

Adding to his point, Gupta emphasized that getting a certified smart contract security audit without adopting standard Web2 cybersecurity practices is not sufficient to protect a protocol and user’s wallets from being exploited:

“I’ve been pushing at least all of the major companies to get a dedicated security person who actually knows that key management is important.”

“You have API keys that are used for decades and decades. So there are proper best practices and procedures one should be following. To keep these keys secure. There should be proper audit trail logging and proper risk management around these things. But as we’ve seen these crypto companies just ignored all of it,” he added.

While blockchains are often decentralized on the backend, “users interact with [applications] through a centralized website,” so implementing traditional cybersecurity measures around factors such as Domain Name System (DNS), web hosting and email security should always “be taken care of,” said Gupta.

Gupta also emphasized the importance of private key management, citing the $600 million Ronin bridge hack and $100 million Horizon bridge hack as textbook examples of the need to tighten private key security procedures:

“Those hacks had nothing to do with blockchain security, the code was fine. The cryptography was fine, everything was fine. Except the key management was not. The private keys […] were not securely kept, and the way the architecture worked was if the keys got compromised, the whole protocol got compromised.”

Gupta suggested that the current sentiment from blockchain and Web3 firms is that if “you fall for a phishing attack, it’s your problem,” but argued that “if we want mass adoption,” Web3 companies have to take more responsibility rather than doing the bare minimum.

“For us […] we don’t want just the minimum safety that keeps the liability away. We want our product to be actually safe for users to use it […] so we think about what traps they might fall into and try to protect users against them.”

Polygon is an interoperability and scaling framework for building Ethereum-compatible blockchains, which enables developers to build scalable and user-friendly decentralized applications.

Related: Cross-chains in the crosshairs: Hacks call for better defense mechanisms

With a team of 10 security experts now employed at Polygon, Mudit now wants all Web3 companies to take the same approach.

Following the $190 million Nomad bridge hack in August, crypto hacks have now surpassed the $2 billion mark, according to blockchain analytics firm Chainalysis.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 88,516.00
ethereum
Ethereum (ETH) $ 2,978.13
tether
Tether (USDT) $ 0.999068
bnb
BNB (BNB) $ 860.38
xrp
XRP (XRP) $ 1.88
usd-coin
USDC (USDC) $ 0.999776
tron
TRON (TRX) $ 0.285203
staked-ether
Lido Staked Ether (STETH) $ 2,976.37
dogecoin
Dogecoin (DOGE) $ 0.123970
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
cardano
Cardano (ADA) $ 0.353118
whitebit
WhiteBIT Coin (WBT) $ 57.09
bitcoin-cash
Bitcoin Cash (BCH) $ 598.04
wrapped-steth
Wrapped stETH (WSTETH) $ 3,643.56
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 88,424.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,236.15
usds
USDS (USDS) $ 0.999417
wrapped-eeth
Wrapped eETH (WEETH) $ 3,229.75
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998981
chainlink
Chainlink (LINK) $ 12.46
zcash
Zcash (ZEC) $ 528.59
leo-token
LEO Token (LEO) $ 8.84
monero
Monero (XMR) $ 436.93
weth
WETH (WETH) $ 2,978.37
stellar
Stellar (XLM) $ 0.212113
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 88,587.00
ethena-usde
Ethena USDe (USDE) $ 0.998663
hyperliquid
Hyperliquid (HYPE) $ 25.69
litecoin
Litecoin (LTC) $ 78.17
avalanche-2
Avalanche (AVAX) $ 12.58
sui
Sui (SUI) $ 1.44
canton-network
Canton (CC) $ 0.138184
hedera-hashgraph
Hedera (HBAR) $ 0.111757
usdt0
USDT0 (USDT0) $ 0.998711
dai
Dai (DAI) $ 0.999803
shiba-inu
Shiba Inu (SHIB) $ 0.000007
susds
sUSDS (SUSDS) $ 1.08
the-open-network
Toncoin (TON) $ 1.62
world-liberty-financial
World Liberty Financial (WLFI) $ 0.143487
uniswap
Uniswap (UNI) $ 5.99
crypto-com-chain
Cronos (CRO) $ 0.092400
paypal-usd
PayPal USD (PYUSD) $ 0.999839
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
usd1-wlfi
USD1 (USD1) $ 0.999532
mantle
Mantle (MNT) $ 0.980629
polkadot
Polkadot (DOT) $ 1.83
rain
Rain (RAIN) $ 0.008049
memecore
MemeCore (M) $ 1.44
bitget-token
Bitget Token (BGB) $ 3.49
aave
Aave (AAVE) $ 150.74
Shares