Binance Square
#frontendexploit

frontendexploit

37 vues
2 mentions
0xr1
·
--
Article
When the smart contract was perfectly secure but the website UI was compromisedIn December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit . Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks . They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself . By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens . Users signed the transactions with their hardware wallets trusting what they saw on their screens . Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation . Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted . Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization . #BadgerDAO #Web3Safety #FrontEndExploit

When the smart contract was perfectly secure but the website UI was compromised

In December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit .
Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks .
They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself .
By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens .
Users signed the transactions with their hardware wallets trusting what they saw on their screens .
Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation .
Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted .
Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization .
#BadgerDAO #Web3Safety #FrontEndExploit
Connectez-vous pour découvrir plus de contenu
Rejoignez la communauté mondiale des adeptes de cryptomonnaies sur Binance Square
⚡️ Suviez les dernières informations importantes sur les cryptomonnaies.
💬 Jugé digne de confiance par la plus grande plateforme d’échange de cryptomonnaies au monde.
👍 Découvrez les connaissances que partagent les créateurs vérifiés.
Adresse e-mail/Nº de téléphone