[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 9 KB, 758x177, exploit.png [View same] [iqdb] [saucenao] [google]
21428626 No.21428626 [Reply] [Original]

Watch out anons, there's a super nasty HW wallet exploit that blackhats are actively using to drain wallets of LINK tokens.

Pic related

>> No.21428675

I'm fucking sweating right now, lost 4000 LINK on one of my hardware wallets

Trying to transfer everything off the other two before it's too late

>> No.21428680

>>21428626
Holy shit..they are selling the exploits on deepweb too. This is really bad bros

>> No.21428718
File: 72 KB, 600x600, 1561348730279.jpg [View same] [iqdb] [saucenao] [google]
21428718

>What is this exploit?
There's a security layer in LINK's source code that deals with storage ticks. Basically, even in cold storage where they're untouched, there's a cache protocol that will occasionally ping public wallet addresses to verify their contents. Unfortunately, LINK has a slightly different version of this protocol in order to make micro-pings for staking purposes. Most staking rewards are going to be really small transfers, so the LINK devs lowered the tick rate for these pings. However, if you're using a hardware wallet, your storage is operating at the NORMAL tick rate, creating a cache gap where someone can use an SLQ% injection to gain access to your wallet. There's already been many posts of Anons opening up their wallets to find all their tokens transferred out to mysterious addresses, losing tens if not hundreds of thousands of dollars.

>Does this affect other tokens in my hardware wallet?
No, as this isn't a vulnerability with the wallet so much as Chainlink specifically. Other tokens, even on wallets that have been affected by the exploit, are safe.

>I haven't touch my wallet in years! Can someone really randomly gain access and steal my LINK?
Sadly, yes. This affects PUBLIC addresses, and these are most likely being chosen at random.

>I have my LINK on a hardware wallet! What do I do?
Either transfer them to a paper wallet (safest), an exchange, or trade for fiat.

>Can this be patched?
Yes, but it will take time. This isn't something that can be done in one week, as it's tied to the security layers focused on staking. These have to be rewritten very cautiously, else other major functions of the LINK source code can break.

>> No.21428719

>>21428626
link to that thread op?

>> No.21428741

>>21428626
this is not real

>> No.21428743

>>21428719
No can do. This site encodes the user's IP into the URL to identify leaks. Sorry.

>> No.21428751

>>21428680
Thanks, just bought 100k exploits

>> No.21428774

>>21428626
>Phil mabags
>Fill by bags
God us linkies sure are bored as shit waiting for the singularity aren't we?

>> No.21428778
File: 437 KB, 2029x2048, 1591667402972.jpg [View same] [iqdb] [saucenao] [google]
21428778

>>21428626
>Phil Mabags

>> No.21428819
File: 124 KB, 680x680, 56453546.png [View same] [iqdb] [saucenao] [google]
21428819

>>21428626
This is not true.

>> No.21428834

>>21428743
lying sack of shit lol.

>> No.21428871

Holy fuck HOLYFUCK what the fuck are we gonand DO?

>> No.21428882

>>21428743
You could've sent a tor link leading to a cp central site instead you do this low effort shit 0/10 made me reply

>> No.21428890
File: 349 KB, 600x477, EA24DC46-272F-4E45-B740-632DB6642D25.jpg [View same] [iqdb] [saucenao] [google]
21428890

>>21428778

>> No.21428892

Fuck, im devastated, just lost 100k links recently because that shit, probably they're going tovtarget Sergey or another Link Whale wallet. And dump this shit to 1$ or less, gtfo of this bugged shit

>> No.21428903

>>21428882
Why would I send people I care about to a dangerous website?