According to ChainCatcher, Web3 infrastructure provider Ankr released an attack report and announced the results of its investigation into the aBNBc Token vulnerability. Ankr said that the attack was caused by a former team member who maliciously attacked the supply chain and inserted a malicious code package that could destroy the private key once a legitimate update was made. Currently, Ankr is working with law enforcement to prosecute the former team member and bring him to justice.
Ankr said that this could affect any protocol, and the team is supporting internal human resources processes and security measures to strengthen future security posture. Ankr is making a number of improvements to its security posture, including requiring multi-signature authentication and time locks for all updates, improving internal security measures, implementing a new monitoring and notification system, and refining the process of using DeFi protocols. (Source link)
