Early warning: wavefield dapp may become a new target for hackers

Early warning: wavefield dapp may become a new target for hackers

Wavefield DApp tronbank was attacked by a counterfeit currency at 1 am on April 11. On the morning of the 11th, the Beosin Chengdu Chain Security technical team made a preliminary analysis to determine that the main reason for the counterfeit currency attack was that the contract did not strictly verify the unique identifier token ID of the token, and incorrectly identified the attacker’s own valueless token as The BTT token worth 850,000 yuan caused losses. When checking other open source project code on Github, I found that there are other project parties with this security issue: the following is the problematic contract address: TF3YXXXXXXXXXXXXXXXXXXXXXXXWt3hx; TKHNXXXXXXXXXXXXXXXXXXXXXXXAEzx5;

TK8NXXXXXXXXXXXXXXXXXXXXXXXZkQy;

TUvUXXXXXXXXXXXXXXXXXXXXXXXxLETV;

TG17XXXXXXXXXXXXXXXXXXXXXXXkQ9i.

According to the analysis of the Beosin Chengdu Chain Security technical team, there are two reasons for the above problems: 1) The developer's research on the use mechanism of the wave field token is insufficient, and the use of the tokens in Ethereum may be applied; 2) The attacker The attack mode that exists on other public links, such as the counterfeit currency attack mode that EOS already exists. Remedy: In this regard, the Beosin Chengdu Chain Security technical team suggested that the project side should simultaneously determine whether msg.tokenvalue and msg.tokenid meet expectations when receiving the replacement currency. And give the vulnerability code repair method, as follows: Invest function to increase the code; require (msg.tokenid == 1002000); require (msg.tokenvalue >= minimum); minimum is the minimum investment amount.

We will continue to update Blocking; if you have any questions or suggestions, please contact us!

Share:

Was this article helpful?

93 out of 132 found this helpful

Discover more

Blockchain

What experience did NASA send to Apollo's computer mining 50 years ago? It takes 10^18 years for a block...

How hard is bitcoin mining? A foreign geek made a bold experiment with the NASA antiques that had sent the spaceship ...

Blockchain

Analysis | Bitcoin's dual structure breaks at the same time, and $ 8,000 has become a thing in the bag?

The mainstream currencies represented by BTC rebounded quickly in the short term. Almost all the currencies covered b...

Market

Bitcoin Gravity - The Nature of Bitcoin and the Reasons Why It Is More and More Popular

Bitcoin has different meanings for different people. No matter what it is for you, it undoubtedly triggers a phenomen...

Blockchain

Seed CX tests physical settlement of bitcoin swap contracts, scheduled to launch within three months

According to Coindesk's August 14 report, Bitcoin derivatives supplier Seed CX announced on Tuesday that it has ...

Market

Inventory of Bitcoin's technology development in 2019 (1)

From March 27th to 28th next year, the world's largest Bitcoin summit will be held in SVN West, San Francisco, U...

Policy

Unleashing the Power of Bitcoin: Edward Snowden’s Plea for Freedom

Edward Snowden stresses the importance of focusing on the core principles of Bitcoin rather than its value in dollars...