Ultimate magazine theme for WordPress.

The FBI issues a warning about DeFi exploits and open-source development

  • The FBI has detailed various DeFi hacks and exploits that the cryptocurrency industry has faced over the past year
  • Due diligence was urgently required to ensure investors understand the logs and verify that code audits have taken place

Criminals are stepping up efforts to exploit DeFi (decentralized finance) vulnerabilities to steal crypto, the US Federal Bureau of Investigation (FBI) has warned.

The agency said it has seen a rise in smart contract hacks and is urging investors who have been victims of a related theft to come forward.

“Cybercriminals are attempting to exploit investors’ increased interest in cryptocurrencies, as well as the complexities of cross-chain functionality and the open-source nature of DeFi platforms,” ​​the agency said in a statement.

In the first quarter of this year alone, more than $1.8 billion in digital assets were stolen from DeFi protocols – a nearly eightfold increase over the corresponding period of 2021.

The FBI has identified multiple attack vectors specific to DeFi protocols over the past 12 months, including flash loans, token bridges, and oracle price pairs.

In fact, token bridges in particular were important targets this year. Harmony’s cross-chain Horizon Bridge was hacked for $100 million in June, while Ronin Network, the Ethereum-connected sidechain for blockchain game Axie Infinity, lost a whopping $625 million three months earlier — the biggest exploit to date crypto industry.

Authorities believe North Korean hacking entity Lazarus Group was behind the Horizon and Ronin Bridge incidents.

Some of the stolen funds were traced to Ethereum-powered cryptomixer Tornado Cash. Tornado Cash was blacklisted by the US earlier this month, barring citizens from engaging with the protocol — and technically even interacting with digital assets that have gone through it.

The FBI says open-source code allows “unhindered access” for bad actors

The FBI issued four recommendations for crypto investors; Take precautions to reduce their susceptibility to theft on the blockchain.

These include the usual caveats of seeking professional financial advice and conducting proper research, while ensuring their investments have verifiable code audits.

Investors should also be aware of DeFi liquidity pools with “extremely limited time frames” to join. The FBI also warned of potential risks associated with open-source development, which much of the crypto ecosystem relies on.

“Open-source code repositories allow unrestricted access for anyone, including those with nefarious intentions,” the agency said.

It should be noted that several protocols that have undergone code audits have fallen victim to exploits outside of their control, although security “seems to be getting better,” Immunefi CEO Mitchell Amador told Blockworks in a July interview.

As for the platforms themselves, the FBI advised setting up real-time analytics and monitoring while continuously testing their code.

Developing an incident response plan to alert investors when an exploit has occurred should also be a priority, it said.

Attend Europe’s premier institutional crypto conference at a discount. Only 3 days left to save £250 on tickets – Use code LONDON250.

  • Sebastian Sinclair

    blocks

    Senior Reporter, Asia News Desk

    Sebastian Sinclair is a senior news reporter for Blockworks, which operates in Southeast Asia. He has experience covering the crypto market as well as specific developments affecting the industry including regulation, economics and mergers and acquisitions. He currently holds no cryptocurrencies. Contact Sebastian by email at [email protected]

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: