Profanity tool vulnerability drains $3.3M despite 1Inch warning

0

[ad_1]

Decentralized exchange aggregator 1inch Network issued a warning to crypto investors after identifying a vulnerability in Profanity, an Ethereum (ETH) vanity address generating tool. Despite the proactive warning, apparently, hackers were able to make away with $3.3 million worth of cryptocurrencies.

On Sept. 15, 1Inch revealed the lack of safety in using Profanity as it used a random 32-bit vector to seed 256-bit private keys. Further investigations pointed out the ambiguity in the creation of vanity addresses, suggesting that Profanity wallets were secretly hacked. The warning came in the form of a tweet, as shown below.

A subsequent investigation by blockchain investigator ZachXBT showed that a successful exploit of the vulnerability allowed hackers to drain $3.3 million in crypto.

Moreover, ZachXBT helped a user save over $1.2 million in crypto and nonfungible tokens (NFTs) after alerting them about the hacker who had access to the user’s wallet. Following the revelation, numerous users confirmed that their funds were safe, as one stated:

“Wtf 6h after the attack my addresses was still vuln but the attacker didnt drained me? had 55k at risk lol”

However, hackers tend to attack the bigger wallets before moving over to wallets with lesser value. Users owning wallet addresses generated with the Profanity tool have been advised to “Transfer all of your assets to a different wallet ASAP!” by 1Inch.

Related: Law enforcement recovers $30 million from Ronin Bridge hack with the help of Chainalysis

While some hackers prefer the traditional method of draining users’ funds after illegally accessing the crypto wallets, others try out new ways to fool investors into sharing their private keys.

One of the recent innovative scams involved the hacking of a YouTube channel for playing fabricated videos of Elon Musk discussing cryptocurrencies. On Sept. 3, the South Korean government’s YouTube channel was momentarily hacked and renamed for sharing live broadcasts of crypto-related videos.

The compromised ID and password of the YouTube channel were identified as the root cause of the hack.



[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,781.00
ethereum
Ethereum (ETH) $ 2,975.38
tether
Tether (USDT) $ 0.998797
bnb
BNB (BNB) $ 862.18
xrp
XRP (XRP) $ 1.84
usd-coin
USDC (USDC) $ 0.999967
solana
Wrapped SOL (SOL) $ 125.18
tron
TRON (TRX) $ 0.282716
staked-ether
Lido Staked Ether (STETH) $ 2,974.62
dogecoin
Dogecoin (DOGE) $ 0.117846
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
cardano
Cardano (ADA) $ 0.333832
whitebit
WhiteBIT Coin (WBT) $ 56.58
bitcoin-cash
Bitcoin Cash (BCH) $ 598.67
wrapped-steth
Wrapped stETH (WSTETH) $ 3,641.40
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,377.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,235.72
usds
USDS (USDS) $ 0.999771
wrapped-eeth
Wrapped eETH (WEETH) $ 3,228.46
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998644
chainlink
Chainlink (LINK) $ 12.31
leo-token
LEO Token (LEO) $ 9.33
zcash
Zcash (ZEC) $ 511.28
monero
Monero (XMR) $ 441.91
weth
WETH (WETH) $ 2,976.96
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,827.00
stellar
Stellar (XLM) $ 0.199667
ethena-usde
Ethena USDe (USDE) $ 0.998573
hyperliquid
Hyperliquid (HYPE) $ 25.73
litecoin
Litecoin (LTC) $ 76.82
canton-network
Canton (CC) $ 0.147506
avalanche-2
Avalanche (AVAX) $ 12.34
sui
Sui (SUI) $ 1.41
hedera-hashgraph
Hedera (HBAR) $ 0.106349
usdt0
USDT0 (USDT0) $ 0.998746
dai
Dai (DAI) $ 0.999285
susds
sUSDS (SUSDS) $ 1.09
shiba-inu
Shiba Inu (SHIB) $ 0.000007
the-open-network
Toncoin (TON) $ 1.64
world-liberty-financial
World Liberty Financial (WLFI) $ 0.142390
paypal-usd
PayPal USD (PYUSD) $ 1.00
uniswap
Uniswap (UNI) $ 5.71
crypto-com-chain
Cronos (CRO) $ 0.090308
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
usd1-wlfi
USD1 (USD1) $ 0.999103
mantle
Mantle (MNT) $ 0.951263
polkadot
Polkadot (DOT) $ 1.77
rain
Rain (RAIN) $ 0.007998
memecore
MemeCore (M) $ 1.57
bitget-token
Bitget Token (BGB) $ 3.48
Shares