Binance Square
#frontendexploit

frontendexploit

36 views
2 සාකච්ඡා කරමින්
0xr1
·
--
ලිපිය
When the smart contract was perfectly secure but the website UI was compromisedIn December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit . Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks . They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself . By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens . Users signed the transactions with their hardware wallets trusting what they saw on their screens . Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation . Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted . Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization . #BadgerDAO #Web3Safety #FrontEndExploit

When the smart contract was perfectly secure but the website UI was compromised

In December 2021 a decentralized finance protocol called BadgerDAO suffered a massive $120 million security exploit .
Security researchers immediately rushed to inspect the smart contract code looking for algorithmic flaws or missing validation checks .
They found nothing wrong with the code on the blockchain .The attackers had not touched the smart contracts at all . Instead they targeted the front-end infrastructure of the website itself .
By obtaining an API key for a script injected into the website interface the hackers silently altered the user interactions . Whenever a user tried to approve a standard token transaction the modified front-end secretly requested permission for the attacker's address to spend their tokens .
Users signed the transactions with their hardware wallets trusting what they saw on their screens .
Over several weeks the hackers collected approvals from high-value wallets before executing a single massive drain operation .
Even the most secure smart contract is completely useless if the interface presenting it to the user cannot be trusted .
Does relying on traditional web servers for Web3 user interfaces defeat the entire purpose of decentralization .
#BadgerDAO #Web3Safety #FrontEndExploit
තවත් අන්තර්ගතයන් ගවේෂණය කිරීමට ඇතුල් වන්න
Binance චතුරශ්‍රය හි ගෝලීය ක්‍රිප්ටෝ පරිශීලකයින් හා එක්වන්න
⚡️ ක්‍රිප්ටෝ පිළිබඳ නවතම සහ ප්‍රයෝජනවත් තොරතුරු ලබා ගන්න.
💬 ලොව විශාලතම ක්‍රිප්ටෝ හුවමාරුව මගින් විශ්වාස කෙරේ.
👍 සත්‍යායනය කරන ලද නිර්මාණකරුවන්ගෙන් සැබෑ විදසුන් සොයා ගන්න.
විද්‍යුත් තැපෑල / දුරකථන අංකය