Binance Square
#frontendexploit

frontendexploit

Просмотров: 36
2 обсуждают
0xr1
·
--
Статья
When the smart contract was perfectly secure but the website UI was compromisedIn December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit . Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks . They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself . By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens . Users signed the transactions with their hardware wallets trusting what they saw on their screens . Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation . Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted . Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization . #BadgerDAO #Web3Safety #FrontEndExploit

When the smart contract was perfectly secure but the website UI was compromised

In December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit .
Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks .
They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself .
By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens .
Users signed the transactions with their hardware wallets trusting what they saw on their screens .
Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation .
Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted .
Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization .
#BadgerDAO #Web3Safety #FrontEndExploit
Войдите, чтобы посмотреть больше материала
Присоединяйтесь к пользователям криптовалют по всему миру на Binance Square
⚡️ Получайте новейшую и полезную информацию о криптоактивах.
💬 Нам доверяет крупнейшая в мире криптобиржа.
👍 Получите достоверные аналитические данные от верифицированных создателей контента.
Эл. почта/номер телефона