Early warning: wavefield dapp may become a new target for hackers

Early warning: wavefield dapp may become a new target for hackers

Wavefield DApp tronbank was attacked by a counterfeit currency at 1 am on April 11. On the morning of the 11th, the Beosin Chengdu Chain Security technical team made a preliminary analysis to determine that the main reason for the counterfeit currency attack was that the contract did not strictly verify the unique identifier token ID of the token, and incorrectly identified the attacker’s own valueless token as The BTT token worth 850,000 yuan caused losses. When checking other open source project code on Github, I found that there are other project parties with this security issue: the following is the problematic contract address: TF3YXXXXXXXXXXXXXXXXXXXXXXXWt3hx; TKHNXXXXXXXXXXXXXXXXXXXXXXXAEzx5;

TK8NXXXXXXXXXXXXXXXXXXXXXXXZkQy;

TUvUXXXXXXXXXXXXXXXXXXXXXXXxLETV;

TG17XXXXXXXXXXXXXXXXXXXXXXXkQ9i.

According to the analysis of the Beosin Chengdu Chain Security technical team, there are two reasons for the above problems: 1) The developer's research on the use mechanism of the wave field token is insufficient, and the use of the tokens in Ethereum may be applied; 2) The attacker The attack mode that exists on other public links, such as the counterfeit currency attack mode that EOS already exists. Remedy: In this regard, the Beosin Chengdu Chain Security technical team suggested that the project side should simultaneously determine whether msg.tokenvalue and msg.tokenid meet expectations when receiving the replacement currency. And give the vulnerability code repair method, as follows: Invest function to increase the code; require (msg.tokenid == 1002000); require (msg.tokenvalue >= minimum); minimum is the minimum investment amount.

We will continue to update Blocking; if you have any questions or suggestions, please contact us!

Share:

Was this article helpful?

93 out of 132 found this helpful

Discover more

Blockchain

The Bitcoin Mining Index has continued to grow in recent years. What is the trend of 2019?

Mine Pool & ASIC changes game rules In general, miners in large mining pools come from all over the world. Before...

Blockchain

Bitcoin has risen by 40% in two months. How is this time different from the 2017 high?

The price of bitcoin has risen sharply in the past few weeks-the price of bitcoin has increased by 40% since the begi...

Blockchain

Analysis: halving is coming, Bitcoin may face greater volatility

Although few people attribute the sharp fluctuations in the price of bitcoin to a fixed supply of bitcoin, many peopl...

Blockchain

CME executives' proposal to expand the group's business to the bitcoin mining sector, is it good for the crypto industry?

The cryptocurrency space is always full of surprises. The latest unexpected news came from the CME Group's elect...

Bitcoin

Breaking News ARK 21 Shares spot Bitcoin ETF snubbed by DTCC website – But Don't Panic!

Despite rumors on social media, the Bitcoin ETF collaboration between ARK Invest and 21 Shares has not yet been liste...

Blockchain

Trading volume may be fake, but the value of Bitcoin is real.

Bitwise said in a recent report that 95% of Bitcoin transactions are fraudulent. Unsurprisingly, the mainstream world...