TRUMP(特朗普币)芝麻开门交易所

Analysis of the incident where 1400 Bitcoins were stolen from G

Date:2024-04-16 18:47:10 Channel:Wallet Read:
In today's digital age, with the rise of cryptocurrencies, cybersecurity issues have attracted much attention. The recent incident of the theft of 1,400 Bitcoins from a Github user has once again attracted widespread attention. This article will analyze this incident in depth, explore the reasons and lessons behind it, and present readers with a realistic warning about network security and cryptocurrency.
Event review: Github user suffered 1,400 Bitcoins being stolen

The four most famous international exchanges:

Binance INTL
OKX INTL
Gate.io INTL
Huobi INTL
Binance International Line OKX International Line Gate.io International Line Huobi International Line
China Line APP DL China Line APP DL
China Line APP DL
China Line APP DL

Note: The above exchange logo is the official website registration link, and the text is the APP download link.

The core of this incident is that a Github user's Bitcoin wallet was stolen, and a total of 1,400 Bitcoins were transferred. The user posted a message for help on social media, but soon discovered that there was no way to trace and recover the stolen cryptocurrency. This incident not only sparked heated discussions in the community, but also raised concerns about the security of cryptocurrency.
Security Vulnerability Investigation: Potential Risks in the Github Platform
As the world's largest open source code hosting platform, Github provides services to millions of developers. However, precisely because of its openness and decentralization, it also provides opportunities for hackers to take advantage of it. Security experts pointed out that the Github platform has some potential security vulnerabilities, such as uncensored code submission, malware injection, etc., which may lead to losses of user assets.
Community response: Users call for strengthening network security awareness and preventive measures
This incident triggered extensive discussions in the Github community, and many users expressed concerns about the security of their accounts. Some senior developers put forward suggestions such as strengthening network security awareness training, regularly updating passwords and keys, and using multi-factor authentication. At the same time, some users have called on the Github platform to strengthen security review and monitoring to improve the overall security level.
Cryptocurrency Security: A Required Course for Digital Asset Management
As the cryptocurrency market booms, digital asset management has become increasingly important. Users need to be wary of cyber attacks targeting personal information and assets, learn to allocate assets appropriately, and choose safe and reliable wallets and trading platforms. Only by strengthening security awareness can we better protect our digital wealth from loss.
Lessons and reflections: Network security is always on the road
This incident of the theft of 1,400 Bitcoins from a Github user has taught us a profound lesson: network security is always on the road, and absolute security does not exist. Users need to remain vigilant at all times and constantly learn and improve their awareness of network security. Only through joint efforts can we build a more secure and reliable digital world.
Conclusion: Together we will protect the future of network security

One day, when you are transferring money on Alipay, a pop-up window prompts you that the transfer failed because the version is too low. If the pop-up window not only prompts you that the transaction failed, but also includes an Alipay update link, most people will probably click on the link to proceed. renew.

If this link is a phishing link and directly obtains your transfer permission, it means that the money in your account will also be ruthlessly transferred. This time, a user encountered a similar situation.

On August 31, Beijing time, CertiK Skynet system (Skynet)
It was detected that the 1,400 Bitcoin tokens stolen by Github user "1400BitcoinStolen" have begun to be transferred to multiple different addresses.

The victim told electrum's Github issue that he lost 1,400 Bitcoins and posted his Bitcoin wallet address.

In the blockchain browser (reference link 3), you can see that a total of 1,404 BTC (worth $16.7 million) was withdrawn from his wallet on August 30 and deposited into the hacker's wallet.

Event restoration and analysis

The user is using the Electrum Bitcoin wallet, which was last used in 2017. Electrum has since released security updates, but the user has not installed them.

When a user uses Electrum to conduct a transaction, the wallet will broadcast a transaction to the server. If there is a problem with the transaction, the server will return an error message and display it to the user in the form of a pop-up window.

Electrum wallets before version 3.3.2 will not verify the error information returned by the server, and will even render the returned information in HTML (refer to link 4).

It is worth mentioning that anyone can build an Electrum node server. If a user connects to an attacker's server and initiates a transaction, the server can return any designed error message. For example, an error message is returned asking the user to update the Electrum wallet, as shown in the figure below.

However, the link in the picture points to malware written by the attacker himself. Once the user downloads and installs the software and imports his wallet into it, all the Bitcoins in the wallet will be transferred by the attacker.

This is essentially a phishing attack, but because the phishing information sent by the attacker is displayed through the official Electrum wallet, many people will believe it to be true.

In this incident, the victim's wallet was connected to a server controlled by the attacker, which caused the victim to receive a phishing message from the server, and all his Bitcoins were transferred by the attacker.

This problem with the Electrum wallet caused widespread discussion as early as the end of 2018 (refer to link 4).

Electrum officially fixed this problem in wallet version 3.3.4 in 2019. Subsequent versions of Electrum wallet will no longer directly display the content returned by the server to the user, nor will it perform html rendering.

In addition, because old versions of wallets still have this problem, all normal servers will conduct denial-of-service (DoS) attacks on wallets before version 3.3 to force users to update (refer to link 5).

CertiK Security Team Recommendations

When using a wallet for transactions, users need to ensure that the wallet is the latest version. Wallets that have been protected from old versions may have vulnerabilities that can be exploited by hackers.

When downloading wallet updates, users should pay attention to verify whether the download URL is consistent with the official one. After the download is completed, the signature of the wallet must be verified. For the wallet development team, it is necessary to find a professional team to do testing work to avoid loopholes in the project that may bring problems to users. Come to loss.

I'll answer.

2480

Ask

968K+

reading

0

Answer

3H+

Upvote

2H+

Downvote