In late August, the FBI issued a public statement regarding cybercrime vulnerabilities in DeFi (decentralized finance), the growing crypto segment of financial applications powered by blockchain technology. Of the $1.3 billion stolen in cryptocurrencies in the first three months of 2022, 97% came from DeFi platforms.
The warning did not deter cybercriminals, who over the following week launched flash lending attacks on the Avalanche blockchain and the New Free DAO protocol – in which someone borrows money and then manipulates the asset’s price before quickly reselling it – with a Total value of nearly $2 million. According to data from investment platform DeFiYield, $211 million was lost to decentralized finance hacks in August alone.
Cybersecurity experts say the timing of the FBI alert — several years after DeFi exploits began — illustrates how slow government agencies and technological solutions have been to catch up to ecosystem vulnerabilities.
“Law enforcement is responding to what’s happening out there,” said Chris Tarbell, the co-founder of cybersecurity firm NAXO and a former FBI special agent who was instrumental in taking down the notorious Silk Road marketplace. “It takes time because it’s such an advanced technology.”
‘Logical Target’
As the apocryphal story goes, a reporter once asked Willie Sutton why he robbed banks. “Because that’s where the money is,” he replied.
Michael Rosmer, co-founder of DeFiYield, said the same logic is pulling cybercriminals into the world of decentralized finance, where transactions are irreversible – unlike traditional banking – and law enforcement has yet to figure out how the platforms work.
“Where else can you go where you can steal really large amounts of money without recourse?” Rosmer told Fortune. “That makes crypto a logical target until we can somehow turn around and build better systems to address this.”
According to data from DeFiYield, last month’s $211 million loss still pales in comparison to August 2021, when cybercriminals stole an estimated $827 million. Rosmer clarified that the decline does not mean the threat is less, attributing the number to the far lower market cap of the cryptocurrency industry as well as the changing nature of DeFi hacks.
Previous exploits took advantage of targeted lending protocols — like the Binance Smart Chain-based protocol Meerkat Finance, which lost $31 million in user funds the day after its launch in 2021 — as well as other complex DeFi tools like liquidity pools and automated market makers.
Rosmer said the main goal in 2022 was bridges, a type of technology that connects different blockchains and allows users to move cryptocurrencies between chains. The biggest example from 2022 was the attack on popular play-to-earn game Axie Infinity, which lost an estimated $620 million in March when cybercriminals targeted the bridge to its Ethereum-connected sidechain.
The attacks continued. Just last month, hackers exploited the Nomad Bridge — which connected blockchains like Ethereum and Avalanche — for $190 million.
“This is a tough technical issue,” Rosmer told Fortune. “The more value exchanged between two chains, the more attractive the pot is, making you want to grab it.”
Possible “state of hell”
Ryan Kalember, an executive vice president of cybersecurity firm Proofpoint, said that DeFi is in a difficult position where it’s attractive for cybercriminals to attack, but not necessarily valuable enough for companies to develop sufficient defenses.
“You could end up in this state of hell where it’s not worth backing up, but it’s still worth enough for cybercriminals to take on,” he said.
The problem is compounded by the international nature of cybercrime, making it difficult for US-based law enforcement agencies to take action. “If you can’t get Edward Snowden in Russia,” Rosmer said, “how are you going to get a guy who just stole $10 million from a DeFi protocol in Russia?”
Government agencies are beginning to strategize, like the US Treasury sanctioning open-source cryptocurrency mixer Tornado Cash, which cybercriminal organizations like North Korea’s Lazarus Group used to launder hundreds of millions of dollars, including August’s Nomad robbery.
Despite this, officers are just beginning to become aware of the threat. “It’s complicated, it’s new and it’s poorly understood, especially by law enforcement,” Kalember said.
While Rosmer said the FBI alert was a step in the right direction, he was skeptical that it would have much of an impact. For him, the responsibility lies with technology companies like DeFiYield to increase security.
“It’s like the jungle,” he told Fortune. “We are working to make the jungle safe and turn it into a zoo.”
Sign up for the Fortune Features email list so you don’t miss our biggest features, exclusive interviews and investigations.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.