[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 79 KB, 1500x361, sub-hero-chainlink-diagram-3fb7d8e9.png [View same] [iqdb] [saucenao] [google]
21426792 No.21426792 [Reply] [Original]

So as Anons found in the previous threads, there is in fact at least one private group that is using the code storage vulnerability to transfer out Chainlink from hardware wallets.

>What is this exploit?
There's a security layer in LINK's source code that deals with storage ticks. Basically, even in cold storage where they're untouched, there's a cache protocol that will occasionally ping public wallet addresses to verify their contents. Unfortunately, LINK has a slightly different version of this protocol in order to make micro-pings for staking purposes. Most staking rewards are going to be really small transfers, so the LINK devs lowered the tick rate for these pings. However, if you're using a hardware wallet, your storage is operating at the NORMAL tick rate, creating a cache gap where someone can use an SLQ% injection to gain access to your wallet. There's already been many posts of Anons opening up their wallets to find all their tokens transferred out to mysterious addresses, losing tens if not hundreds of thousands of dollars.

>Does this affect other tokens in my hardware wallet?
No, as this isn't a vulnerability with the wallet so much as Chainlink specifically. Other tokens, even on wallets that have been affected by the exploit, are safe.

>I haven't touch my wallet in years! Can someone really randomly gain access and steal my LINK?
Sadly, yes. This affects PUBLIC addresses, and these are most likely being chosen at random.

>I have my LINK on a hardware wallet! What do I do?
Either transfer them to a paper wallet (safest), an exchange, or trade for fiat.

>Can this be patched?
Yes, but it will take time. This isn't something that can be done in one week, as it's tied to the security layers focused on staking. These have to be rewritten very cautiously, else other major functions of the LINK source code can break.

>> No.21426834

>>21426792
Oh man this is good

>> No.21426859

not a single word you just said is true

>> No.21426897

>>21426792
bumping this for visibility

>> No.21426927

The pattern noticed in the last thread was that cold storage wallets are more likely to be stolen from than hot wallets. Rule of thumb is that the longer it's been since you've accessed your LINK, the more likely you'll need to transfer to a paper wallet.

>> No.21426939

>>21426792
liar liar pants on fire

>> No.21426945

> SLQ% injection
weak bait

>> No.21426962

>>21426792
Imagine writing all of this. Fuck off idiot

>> No.21427009

>>21426792
How does this remotely make sense? In order to take the LINk tokens you need the private key to the wallet, and once you have the private key it works for all of the tokens and Ether. What does SQL database stuff have to do with anything? But actually I'm the stupid one for even responding to this.

>> No.21427020

>>21426939
>>21426962
Literally just need to transfer until this gets patched, if you're vulnerable. There's no need to be this defensive.

>> No.21427028

Not technical but I don't see why we think he's lying.

He LITTERALLY gave alternatives to make sure you don't sell.

>> No.21427034

>>21426962
fckin THIS
OP kys

>> No.21427036
File: 343 KB, 913x608, 1589209531817.jpg [View same] [iqdb] [saucenao] [google]
21427036

>>21426792
>>I haven't touch my wallet in years! Can someone really randomly gain access and steal my LINK?
>Sadly, yes. This affects PUBLIC addresses, and these are most likely being chosen at random.
These 2 sentences are hilariously bad.

>> No.21427064

Is OP trying to bring down the price so he can buy in? a couple autists on /biz/ aren't gonna effect the price of a 5 billion dollar asset, retard.

>> No.21427079

kek someone spam this on reddit

>> No.21427084

>>21427028
Really hope they're just assuming it's FUD and not part of some raid discouraging safe storage practices.

>> No.21427117

Is this a way to data mine dumb LINK whales ?

>> No.21427129

>>21426792
truly kys

>> No.21427171
File: 574 KB, 295x221, 1567774412654.gif [View same] [iqdb] [saucenao] [google]
21427171

>>21426792
New FUD, finally and an intricate one. You should take this to reddit though as they are more likely to believe it than the retards that populate this place. They bought at 20c you know? I seriously doubt they would sell even if this FUD was true.

>> No.21427187

>>21427084

Is myetherwalletconnect also at risk here?

>> No.21427188

>>21427020
>>21427084
transparently psychopathic behavior
seek help

>> No.21427207

itt: 90% newfags. go along with it, retards

>> No.21427216
File: 1.66 MB, 1085x1217, 1585307759263.png [View same] [iqdb] [saucenao] [google]
21427216

>>21427187
Yes, send all your linkies to my address. I promise to keep them safe from the quantum thieves.

>> No.21427220
File: 398 KB, 840x704, file.png [View same] [iqdb] [saucenao] [google]
21427220

>>21426792
>SLQ% injection
HOLY SHIT NO WAY?
SHIT LINK QUEER PERCENTAGE INJECTIONS!
THIS IS LITERALLY SPREADING DIGITAL AIDS ONTO HARDWARE WALLETS MAKING THEIR DIGITAL IMMUNE SYSTEM OR "SECURITY" WEAKER, THUS EASIER FOR A SIMPLE VIRUS TO INFECT AND KILL YOUR HARDWARE WALLET!!!!!!!!!!!!!!!!!

>> No.21427236

Finally some exciting new fud

>> No.21427275
File: 220 KB, 846x890, 1596934758364.jpg [View same] [iqdb] [saucenao] [google]
21427275

>> No.21427277

>>21427187
Only if you connect to it with a hardware wallet. But again, it's not the hardware wallets themselves that are vulnerable, just the security layer that Chainlink uses to interact with them.

>> No.21427324
File: 483 KB, 2448x3264, 1597377206519.jpg [View same] [iqdb] [saucenao] [google]
21427324

>>21426792
Huh. This is some new FUD. Wonder how many people will fall for it?

Ooh, I bet we could get plebbit to bite this hook line and sinker. I'm gonna start pushing it on /r/crypto or wherever those fuckers reside.

>> No.21427350

>>21427324
post the threads here i'll vote them up

>> No.21427381
File: 578 KB, 1242x2208, 1597114574570.png [View same] [iqdb] [saucenao] [google]
21427381

>>21427350
I lied. I forgot that I deleted my reddit account after their latest rule update fiasco where everyone threw a hissy fit. Couldn't stand it anymore. Do it in my stead, Marine.

Holy shit. We could really get them to bite this. This is really good FUD.

>> No.21427393

>>21426792
Jesus Christ the level of autism OP
Even a first year CS student could write a more realistic bullshit sounding FUD

>> No.21427422

>>21426792
I lost 100k usd. Fucking hell. OG from 2017 here. It's over for me

>> No.21427464

>>21427393
Listen, retard, this is the one bit of FUD we can get reddit to believe. We need to push it on reddit and on the twitter fags.

>> No.21427484
File: 216 KB, 181x179, 1596841795786.gif [View same] [iqdb] [saucenao] [google]
21427484

>>21426792
lmao this is really good goddamn 10/10 for even making it a pseudo-reddit post hahahah

>> No.21427536
File: 87 KB, 750x1334, 0856FB6C-6BC6-4ADE-8A0B-D42836B403E1.jpg [View same] [iqdb] [saucenao] [google]
21427536

>>21426859
Kek

>> No.21427543
File: 150 KB, 686x571, 1570846769261.jpg [View same] [iqdb] [saucenao] [google]
21427543

>>21426792
this fud is getting weirder and weirder

1000 eoy confirmed

>> No.21427545

>>21427381


https://old.reddit.com/r/CryptoCurrency/comments/i9zgc4/warning_chainlink_hw_wallet_vulnerability_being/

>> No.21427558

>>21427545
It got removed?

>> No.21427574

>>21427545
damn they deleted it already, guess my account doesn't meet requirements to post

>> No.21427586

>>21426792

>>21375370
Press F to pay respects

>> No.21427600

>>21427545
Holy fuck these hackers removed this post too, its real, they dont want people to know about the exploits yet

>> No.21427627

>>21427600
DO you think the reddit moderators are in on it???

This Could Be Really Big guys.

I'm Scared

>> No.21427661

>>21426792
Everyone post this to reddit please

>> No.21427834

holy fuck we really thought they were going to let a bunch of nazi incel neets get financial freedom.

>> No.21427972

>>21427834
This is by no means the end of LINK, there's no need for hyperbole. We just need to collectively improve our storage patterns until the patch. We've already had too many Anons lose everything they've saved by not taking the time to transfer their tokens out of cold storage.

>> No.21428200

This is almost as good as that one that was like, “then the nodes turn off one by one in a cascade failure.”

>> No.21428235

>>21426792
woah, a link wallet flew over my house!

>> No.21428258

>>21427545
>proof
>link to reddit

you gotta be fucking kidding me. this is some desperately retarded fud

>> No.21428273

>>21426792
Holy shit. So you're saying I should keep all my link on coinbase to be safe?

>> No.21428303

dude i literally have mm only dont fucj w us

>> No.21428324

Omg guys I'm so scared... I think I'm just going to sell everything.

>> No.21428341

"please put all your linkies back into the exchanges goy. they aren't safe in your hands anymore"

>> No.21428353

>>21428273
>>21428303
As I said, a paper wallet is the safest method if you just want to continue to use cold storage. If you just need somewhere to hold until the patch, then use whatever exchange you're most comfortable with.

>> No.21428367

>>21426792
>t. Zeus Capital

>> No.21428371

How do you protect yourself from this op? Would moving all of my link to an exchange and market selling help at all.

>> No.21428379
File: 38 KB, 742x483, received_943744009397903.jpg [View same] [iqdb] [saucenao] [google]
21428379

>>21426792

>> No.21428386

>>21428258
stick to lurking

>> No.21428422

>>21428353
1) this is nonsense fud and lies
2) you can use an Argent wallet to set daily withdrawal limits on your wallet if you’re so worried

>> No.21428427

I'm starting to think it might be safest to just sell everything, I've been in link since 2017 but this exploit is very concerning, I might just take profits and enjoy my life with less stress

>> No.21428432

>>21426792
Just checked all my wallets and found OP was a faggot.

>> No.21428458

>SLQ% injection
larp.

>> No.21428489

sneed

>> No.21428509
File: 172 KB, 432x391, 1485218594944.png [View same] [iqdb] [saucenao] [google]
21428509

>>21426792
Who's going to be the first one to post this to reddit? They could use some fresh FUD over there.

>> No.21428522

It’s Friday night how can you faggettes not have something better to do? Go play Nintendo or something.

>> No.21428539

>>21428427
I would be happy to hold your link for you. I am a doctorate of internet security. The fee is 0.5% of your account per year.

>> No.21428553

>>21428509
>>21427545
Didn't see this. Damn that was taken down fast.

>> No.21428580

SIMEON is this how far are you willing to go???

>> No.21428594
File: 118 KB, 500x498, ahh the sweet smell of stinky.jpg [View same] [iqdb] [saucenao] [google]
21428594

>>21426792
PANIC INTO XRP
FLARE = LINK 2.0
FLARE.GHOST.IO

STINKY LINKIES GET THE ROPE

>> No.21428633

>>21427545
>LINK is about to mega pump again thanks to le meme dorito
>spreading midwit oriented fud to get them to sell early
Nice.

>> No.21428673

>>21428458
This lol, its called a sql injection and that literally has nothing to do with crypto. SQL is a database medium.

>> No.21428685

>>21428673
wow you're pretty smart

>> No.21428694

>>21427207
I swear to god it’s like they don’t understand how to play along. Everything is 0 or 1, one or the other black/white to them. No nuance. Fuckin niggærs

>> No.21428745

>>21428673
SLQ% has absolutely nothing to do with SQL databases. That's like mistaking Java for Javascript because they sound similar.

>> No.21428784

>>21428685
No I have above 90 IQ

>> No.21428803

>>21428745
There is literally no such thing as a slq% injection. You even made me fucking google it, you bastard.

>> No.21428848
File: 196 KB, 620x398, 1558308534984.png [View same] [iqdb] [saucenao] [google]
21428848

>>21428803
ill show you a slq% injection

>*unzips dick*

>> No.21428858
File: 241 KB, 932x944, 1524715912434.png [View same] [iqdb] [saucenao] [google]
21428858

>>21428803
>It doesn't exist, I know because I googled it!

>> No.21428967

>>21428858
This is the worst fucking FUD I have ever seen. I am literally a fucking cryptography graduate in his 2nd year of graduate school and a big part of that includes being up to date with current attack vectors and encryption methods. I don't really know jack shit about how crypto works on the backend but there is LITERALLY no such thing as a SLQ% injection, google literally has ZERO results, and how funny that your made up name sounds similar to one of the most common attacks on SQL databases. What the FUCK does the percent stand for? What does SLQ stand for? SQL stands for "structured query language".

>> No.21429056

>>21428967
yeah well my dad works at nintendo and he said they use slq all the time

>> No.21429096

>>21426792
Can you tell me if my seed phrase is effected by this exploit?
It's seek fine drum grape thumb bar remove together exhibit then giraffe mountain own slim crime play illegal multiply fold boring axis bamboo youth answer

>> No.21429127

>>21429096
I checked it out you’re fine

>> No.21429155

>>21429127
Thanks fren

>> No.21429218

>>21429096
sorry anon, you probably don't realize this but when you type a seed phrase on /biz/ it shows up as all asterisks. it's a security feature of /biz/ to protect you from revealing your wallet.

for example here's mine:
**** *** ****** *** ********* ****** ** ******* ***** ***** **** ******

>> No.21429230

>>21428967
THEN WHY ARE MY LINK GONE YOU TOTAL FAGGOT
ARE YOU THE HACKER? TRYING TO STOP PEOPLE FROM SAVING THEIR STACKS?
I HOPE YOU FUCKING ROT IN HELL YOU PIECE OF SHIT YOUVE ENDED MY LIFE

>> No.21429236

>>21428967
>I don't really know jack shit about how crypto works on the backend
The only sentence you really needed to type. SLQ% is part of the protocol security layer of lots of ERC20s, open up any ETH based token whitepaper and you'll find it. This injection is based on a mismatch of the tick rate for pinging public addresses, which you haven't even mentioned because you don't know anything about how crypto-code is structured. But I guess being a 2nd year grad student gives you a sense of superiority on topics you aren't familiar with, so you yab about SQL, which is unrelated, like a redditor. Bet you get a lot of upvotes over there with this dribble.

>> No.21429475

>>21426792
>SLQ% injection
>>21429236
>SLQ% is part of the protocol security layer of lots of ERC20s

Hey, next time you FUD try to at least make use of a real thing. The problem with using something fake is that any non-expert can google it and figure out it's not a real thing. HTH!

>> No.21429525
File: 597 KB, 1000x1000, 1573914454993.jpg [View same] [iqdb] [saucenao] [google]
21429525

HOLY FUCKING SHIT WHAT HAPPENED TO MY LINK
MY 16K STACK ISN'T IN MY HARDWARE WALLET WHAT THE ACTUAL FUCK IS GOING ON GUYS

I THOUGHT THIS WAS LEGIT FUD BUT IT'S FUCKING REAL PLEASE GOD TELL ME THERE'S A WAY TO BRING THEM BACK I'M GONNA FUCKING HAVE A MENTAL BREAKDOWN

>> No.21429533
File: 9 KB, 758x177, 1597460490222.png [View same] [iqdb] [saucenao] [google]
21429533

>>21429475
the obviously fake stuff is what makes it funny. you don't think it's meant to be a completely serious fud campaign do you? it's mostly just people having a laugh

>> No.21429614

>>21429525
there is currently a Kleros court case in the "investigation" stage to see whether the Link can be refunded. It's only available to people with minimum 20k stack of PNK though.

>> No.21429615

is this from a "discord tranny" you fags always talk about?

>> No.21429714
File: 89 KB, 657x422, 1573015886912.jpg [View same] [iqdb] [saucenao] [google]
21429714

I just checked my wallet. I'm still rich.

>> No.21429764

>>21427020
KYS faggot

>> No.21429800

>>21427028
The best FUD is not to sell but suggest cracks

>> No.21430124

>>21429475
>any non-expert can google it
So we're back to this again. Guess what, if you google up most crypto-security protocols they won't pop up in google. Not even the open source ones. Just because it's too obscure to return a google search doesn't mean it's not real.

>> No.21430376

>>21430124
lol

>> No.21430437

what a shit tier fud

>> No.21430855

SELL SELL SELL SIRS!!!! SELLLLLLL THIS IS NOT A DRILL

>> No.21430938

>>21430437
>what a shit tier fud

SIR YOUR MOTHER IS A GOAT!!! NO FUD, VERY TRUTH

>> No.21430965

is this real?

i'm tethering now until we get some confirmation.

>> No.21430994

>>21427036
>hilariously bad.
gb2r

>> No.21431243

>>21426792
OMFGOOOOOOOODDDD go fuck yourself you had 3 years

>> No.21431643

The better the fud, the more bullish I get on link

>> No.21431878

>>21427020
No, I will not move a massive amount of Link so you fucks can track 4chan users. Poor effort, glow harder faggot

>> No.21432028

I can’t believe this is this real ??

>> No.21433184

>>21426792
Holy shit fragile hand resistors just flew over my house.