Autor Cointelegraph By Brayden Lindrea

Ethereum community splits over solutions for transaction censorship

The Ethereum (ETH) community has been divided over how to best respond to the threat of protocol-level transaction censorship in the wake of the United States government sanctions on Tornado Cash-linked addresses. Over the last week, Ethereum community members have proposed social slashing or even a user-activated soft fork (UASF) as possible responses to transaction-level censorship on Ethereum, with some calling it a “trap” that will do more harm than good and others stating its necessary to provide “credible neutrality and censorship resistance properties” on Ethereum.The heated debate comes after Ethereum miner Ethermine elected not to process transactions from the now U.S. sanctioned Ethereum-based privacy tool Tornado Cash, which has prompted members of the Ethereum community to worry about what would happen if other centralized validators did the sameThe Ethereum community is also debating the effectiveness of social slashing to combat censorship on the Ethereum network, as the strategy could lead to a chain split with some validators processing transactions on the censorship-less chain and the others validating only the OFAC-compliant chain. Social slashing is the process whereby validators have a percentage of their stake slashed if they don’t correctly validate the incoming transactions or otherwise act dishonestly.This may become a significant issue if regulators require major centralized staking services like Coinbase and other major centralized pools, which together stake more than 50% of ETH in the Ethereum Beacon 2.0 chain to only validate OFAC-compliant chains. Founder of Cyber Capital Justin Bons argues that slashing “is a trap” that “represents a greater risk than the OFAC regulation” and will not be a viable solution to tackle censorship at the protocol level.1/21) We are now at a critical crossroads for EthereumWith OFAC regulation looming over ETH; threatening censorshipHowever, the greatest threat comes from withinDiscussions of “social slashing,” multiple forks & unclear governanceHeralds the potential for disaster in ETH:— Justin Bons (@Justin_Bons) August 22, 2022In a 21-part Twitter thread on Aug. 22, Bons said that social slashing exchanges may “deprive innocent users of their deposits,” which would “violate their property rights.”Bons also said that too many validators complying with law enforcement on Ethereum would “lead to a chain split,” at the point at which “censors start ignoring or do not attest blocks that contain OFAC violating TXs.” Founder of Ethereum podcast The Daily Gwei Anthony Sassano wrote on Twitter on Aug. 20 that “collateral damage is inevitable in social slashing […] it’s worth it to protect Ethereum’s credible neutrality and censorship resistance properties.”That’s a less bearish outcome than the Ethereum network engaging in permanent censorship.Collateral damage is inevitable with social slashing – but at some point it’s worth it to protect Ethereum’s credible neutrality and censorship-resistance properties.— sassal.eth (@sassal0x) August 20, 2022

Meanwhile, Geth developer Marius Van Der Wijgen shared a similar sentiment stating that preserving censorship on the Ethereum network should be the Ethereum community’s highest priority:“If we allow censorship of user transactions on the network, then we basically failed. This is *the* hill that I’m willing to die on. “If we start allowing users to be censored on Ethereum then this whole thing doesn’t make sense and I will be leaving the ecosystem. […] I think censorship resistance is the highest goal of Ethereum and of the blockchain space in general, so if we compromise on that, there’s not much else to do, in my opinion,” he added. Related: Tornado Cash ban could spell disaster for other privacy protocols — Manta co-founderCrypto researcher Erica Wall added that to date, censorship resistance has served as a core property on the Ethereum network and that while we’re seeing some censorship on the front end, “it’ll only get bad if censorship starts happening side Ethereum itself.”The Tornado Cash sparked censorship debacle has plagued the Ethereum community for over a week now.

Čítaj viac

Crypto security experts raking in $430K salaries amid spike in hacks

The rise of crypto hacks over 2022 has skyrocketed demand for blockchain security experts, with some auditors making upwards of $430,000 per year.Speaking with Cointelegraph, blockchain recruitment firm CryptoRecruit founder Neil Dundon said that while security audit services have long been in demand, the rise of decentralized-finance (DeFi) protocols has opened up opportunities for auditors to review potentially vulnerable smart contracts:“There’s always been a demand for security auditors […] But since DeFi apps have been out there, there has been quite a big increase in demand for security audits across the space because one small vulnerability in the protocol can potentially lead to the loss of hundreds of millions of dollars.”A report from Chainalysis earlier this month revealed that hackers extracted more than $2 billion from cross-chain bridge protocols alone this year. In a Bloomberg report on Aug. 22, CEO of decentralized lending service Morpho Labs Paul Frambot said that crypto security audits have moved from a “nice to have” business expense to a “must have” one.“Security is, in my opinion, not taken sufficiently seriously in DeFi,” he said. The rise in demand for crypto security auditors has seen a plethora of “for hire” ads across the industry. According to job advertisements posted on Cryptocurrency Jobs, blockchain audit companies mostly look for experienced programmers with an understanding of blockchain technology, cybersecurity, and cryptography. While most security audit salaries fall within the $100,000 – $250,000 range, some companies are willing to pay upwards of $430,000 per year, according to Web3.career’s job board.Crypto recruitment firm Plexus Resource Solutions Zeth Couceiro made a similar comment to Bloomberg, noting that in some cases, blockchain security auditors have been raking up to $400,000 annually.Couceiro added that these auditors tend to make about 20% more than Solidity-focused developers, which is the most popular programming language used to deploy smart contracts on Ethereum and other Ethereum Virtual Machine (EVM) compatible blockchains.Related: What is a smart contract security audit? A beginner’s guideAmong the top vulnerabilities that security auditors look for in smart contracts include timestamp dependency, reentrancy attacks, random number vulnerability, and spelling mistakes.The Bloomberg report noted that venture capital firms have already poured $257 million into crypto security audit companies this year, which is up 38.9% from all of 2021, according to CB insights.

Čítaj viac

What's going on with Cardano testnet and Vasil hard fork?

Cardano founder Charles Hoskinson has continued to refute claims that the Cardano’s testnet is “catastrophically broken,” implying the need to finally move forward with the long-delayed Vasil hard fork.In a Twitter thread on Aug. 21, Hoskinson shared his frustration concerning some of the videos claiming Cardano’s testnet has a “catastrophic” issue, which stems from an Aug. 19 thread from Cardano ecosystem developer Adam Dean.The developer claimed that the testnet is “catastrophically broken” due to an undiscovered bug in Cardano’s Node v 1.35.2 that creates incompatible forks — which had managed to slip under the radar of the previous testing.Following the bug, Cardano released its new client software, Cardano Node v1.35.3, on two separate testnets. However, Dean noted that because the majority of operators upgraded to v1.35.2 to simulate the Vasil hard fork, v1.35.3 is also “incompatible and incapable of syncing” with the original testnet, and the two testnets are “without a block history.”Hoskinson has, however, argued that the coding issue found on that node version had been removed in the 1.35.3 update, sharing his frustration that further testing would lead to further delays of the hard fork. “We of course could as a community delay the launch of Vasil for a few months to retest code that’s already been tested a dozen times and is already running. Is that worth it to all the DApp developers who have been waiting for this update for almost a year now?”During an “Ask-Me-Anything” on Aug. 19, Hoskinson also said that there’s been an “unfair narrative” floating around Cardano and its testnet issues, which he called “incredibly corrosive and damaging.” “You can’t conflate a failed testnet with the mainnet because testnets are constructed and destroyed all the time in this industry. That’s their point. […] They are in no way, in any way harm Cardano itself.”On Sunday, Hoskinson noted that “the realities of something this large and complex is that one can be easily trapped by the things that aren’t working well and forget the things that are.”He added that one of the results of the Vasil hard fork will be a new governance process and more inclusive structures that will lead to “more useful code” and “faster developments.”“Moments that give us a chance to change and grow. Let’s get Vasil done together and then let’s move on to higher ground and fix some of the original sins of the project so Cardano can also grow to its next level.”Related: Sell the news? Cardano price risks 20% drop despite Vasil hard fork euphoriaThe Vasil hard fork has already been delayed several times this year, with the most recent being at the end of July due to issues identified on the testnet. However, Hoskinson said during the AMA that he is optimistic that the Vasil hard fork will ship “imminently.” “The features are there, they’ve worked, they’ve been tested thoroughly, and there’s a high degree of confidence in them. There’s no reason for it not to get over the finish line imminently.”Cardano’s ADA token is priced at $0.45 on Monday, having dropped 18.5% over the last week.

Čítaj viac

Ronin hackers transferred stolen funds from ETH to BTC and used sanctioned mixers

The hackers behind the $625 million Ronin bridge attack in March have since transferred most of their funds from ETH into BTC using renBTC and Bitcoin privacy tools Blender and ChipMixer. The hacker’s activity has been tracked by on-chain investigator ‘₿liteZero’, who works for SlowMist and contributed to the company’s 2022 Mid-Year Blockchain Security report. They outlined the transaction pathway of the stolen funds since the Mar. 23 attack.The majority of the stolen funds were originally converted into ETH and sent to now sanctioned Ethereum crypto mixer Tornado Cash before being bridged over to the Bitcoin network and converted into BTC via the Ren protocol.I’ve been tracking the stolen funds on Ronin Bridge.I’ve noticed that Ronin hackers have transferred all of their funds to the bitcoin network. Most of the funds have been deposited to mixers(ChipMixer, Blender).This thread will illustrate the tracking analysis procedures. pic.twitter.com/yrazcJ22xF— ₿liteZero (@blitezero) August 20, 2022According to the report, the hackers, who are believed to be North Korean cybercrime organization Lazarus Group, initially transferred  just a portion of the fund (6,249 ETH) to centralized exchanges including Huobi (5,028 ETH) and FTX (1,219 ETH) on Mar. 28. From the centralized exchanges, the 6249 ETH appeared to have been converted into BTC. The hackers then transferred 439 BTC ($20.5 million) to Bitcoin privacy tool Blender, which was also sanctioned by the U.S. Treasury on May. 6. The analyst wrote: “I’ve found the answer in Blender sanction addresses. Most Blender sanction addresses are Blender’s deposit addresses used by Ronin hackers. They have deposited all their withdrawal funds to Blender after withdrawing from the exchanges.”However the overwhelming majority of stolen funds — 175,000 ETH — was transferred Tornado Cash incrementally between April 4 and May 19.Related: The aftermath of Axie Infinity’s $650M Ronin Bridge hackThe hackers subsequently used decentralized exchanges Uniswap and 1inch to convert around 113,000 ETH to renBTC (a wrapped version of BTC), and used Ren’s decentralized cross-chain bridge to transfer the assets from Ethereum to the Bitcoin network and unwrap the renBTC into BTC.From there, approximately 6,631 BTC was distributed to a variety of centralized exchanges and decentralized protocols:Platforms the hackers used to transfer BTC to. Source: SlowMist.The report also stated that the Ronin hackers withdrew 2,871 BTC (of the 3,460 BTC) ($61.6 million as of Aug. 22) via Bitcoin privacy tool ChipMixer.BTC balance on platforms after the hackers withdrew funds. Source: SlowMist.₿liteZero concluded the Twitter thread by stating that the Ronin hack remains a “mystery to be investigated” and that more progress is to be made.

Čítaj viac

Hackers exploit zero day bug to steal from General Bytes Bitcoin ATMs

Bitcoin ATM manufacturer General Bytes had its servers compromised via a zero-day attack on Aug. 18, which enabled the hackers to make themselves the default admins and modify settings so that all funds would be transferred to their wallet address. The amount of funds stolen and number of ATMs compromised has not been disclosed but the company has urgently advised ATM operators to update their software.The hack was confirmed by General Bytes on Aug. 18, which owns and operates 8827 Bitcoin ATMs that are accessible in over 120 countries. The company is headquartered in Prague, Czech Republic, which is also where the ATMs are manufactured. ATM customers can buy or sell over 40 coins.The vulnerability has been present since the hacker’s modifications updated the CAS software to version 20201208 on Aug. 18.General Bytes has urged customers to refrain from using their General Bytes ATM servers until they update their server to patch release 20220725.22, and 20220531.38 for customers running on 20220531.Customers have also been advised to modify their server firewall settings so that the CAS admin interface can only be accessed from authorized IP addresses, among other things. Before reactivating the terminals, General Bytes also reminded customers to review their ‘SELL Crypto Setting’ to ensure that the hackers didn’t modify the settings such that any received funds would instead be transferred to them (and not the customers).General Bytes stated that several security audits had been conducted since its inception in 2020, none of which identified this vulnerability. How the attack happenedGeneral Bytes’ security advisory team stated in the blog that the hackers conducted a zero-day vulnerability attack to gain access to the company’s Crypto Application Server (CAS) and extract the funds.The CAS server manages the ATM’s entire operation, which includes the execution of buying and selling of crypto on exchanges and which coins are supported. Related: Vulnerable: Kraken reveals many US Bitcoin ATMs still use default admin QR codesThe company believes the hackers “scanned for exposed servers running on TCP ports 7777 or 443, including servers hosted on General Bytes’ own cloud service.”From there, the hackers added themselves as a default admin on the CAS, named ‘gb’, and then proceeded to modify the ‘buy’ and ‘sell’ settings such that any crypto received by the Bitcoin ATM would instead be transferred to the hacker’s wallet address:”The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user.”

Čítaj viac

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy