WazirX Hack Most Likely Linked to Its Custodian’s Systems Failing

Source Livebitcoinnews

Wazir X issued a report on Thursday, with new revelations of the $235 million hack, stating all indicators point to the custody service provider it relies on, Liminal Custody. According to the report, the custodian may have suffered a security breach, causing it to approve a transaction to a fraudulent wallet address. Nothing seemed suspicious at the surface level.

“In this cyber attack, the malicious transactions involved signatures from three WazirX signers and one from Liminal, confirming the use of Liminal’s infrastructure,” the report read. Liminal’s MPC (multi-party computation) wallet comprises one key controlled by it, which must sign transactions for them to occur. This feature ensures the custodian keeps an eye out for illicit transaction requests, only signing transactions to whitelisted wallets that fall within pre-approved amounts.

However, it seems Liminal’s interface experienced a hack, as the attacker manipulated the wallet address displayed. So, all WazirX key holders, three of whom signed this transaction, and Liminal’s key holder saw a whitelisted address when, in fact, the transfer happened to a completely different one belonging to the hacker.

Moreover, the HSMs (hardware security modules), commonly called hardware wallets, used to sign these transactions do not display the receiver’s address. That means the hacker’s attempt at manipulating Liminal’s interface was the only thing needed.

“In Ethereum, when signing an ERC20 transaction, the hardware device involved in signing does not display the token or the destination address. This blind signing is a standard procedure for anyone using such a multisig wallet on Ethereum.”

The exchange elaborated, “To ensure that the WazirX signers knew what they were signing, they relied on the transfer details displayed on the Liminal website, which shows the token being signed and the destination address.”

Furthermore, WazirX brought a concerning fact to light. “The malicious transaction which got signed, upgraded the contract to transfer the control to the attacker.” It claimed that it received “representation” from Liminal stating otherwise.

Liminal previously claimed that the hack did not occur due to breaches at their end. It is yet to respond to these new developments.

 

 

The post WazirX Hack Most Likely Linked to Its Custodian’s Systems Failing appeared first on Live Bitcoin News.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Ethereum Price at Risk of Extended Decline as Bears Regain ControlEthereum price started a downside correction below the $1,850 zone. ETH is now consolidating and might drop further below the $1,785 support zone.
Author  NewsBTC
May 06, Tue
Ethereum price started a downside correction below the $1,850 zone. ETH is now consolidating and might drop further below the $1,785 support zone.
placeholder
Solana (SOL) Faces Continued Downside Risk—More Losses LikelySolana started a fresh decline from the $155 zone. SOL price is now consolidating near $145 and might extend losses below the $142 support.
Author  NewsBTC
May 06, Tue
Solana started a fresh decline from the $155 zone. SOL price is now consolidating near $145 and might extend losses below the $142 support.
placeholder
XRP Price Dips Further: Key Support Levels In JeopardyXRP price started a downside correction below the $2.20 zone. The price is now declining and might extend losses toward the $2.020 level. XRP price started a fresh decline below the $2.20 zone.
Author  NewsBTC
May 06, Tue
XRP price started a downside correction below the $2.20 zone. The price is now declining and might extend losses toward the $2.020 level. XRP price started a fresh decline below the $2.20 zone.
placeholder
Analysts Highlight 4 Reasons Why ETH Price Could Rebound Strongly in MayEthereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
Author  Beincrypto
Yesterday 01: 34
Ethereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
placeholder
Ethereum Price Regains Traction—Can Bulls Break Through the Barrier?Ethereum price started a downside correction and tested the $1,750 zone. ETH is now rising and attempting a move above the $1,850 resistance.
Author  NewsBTC
Yesterday 03: 31
Ethereum price started a downside correction and tested the $1,750 zone. ETH is now rising and attempting a move above the $1,850 resistance.
goTop
quote