Cointime

Download App
iOS & Android

A Recap of Defi Hacks in Jan 2023

Validated Individual Expert

As far as DeFi hacks go, January 2023 was a pretty calm beginning to the year. A few significant attacks on DeFi protocols did occur, although the majority of the most important hackers targeted specific people.

Media attention is typically drawn to attacks on important DeFi projects. However, people were the main targets of the majority of the most serious attacks in 2023 rather than projects. The following people working in the cryptocurrency sector were targeted in January 2023:

  • NFT God
  • CryptoNovo
  • Luke Dashjr
  • Nikhil Gopalani
  • Kevin Rose

Major DeFi hacks were less common in January 2023, but they were still there. When a deprecated IBSC token contract was replaced, it was not disabled, which led to two versions of the token being operational at once. This vulnerability was exploited by an attack against LendHub. The attacker stole around $6 million from the project by taking advantage of inconsistencies in the liability calculations of the two tokens.

Smart contract weaknesses are frequently used in the most common DeFi attacks. But every notable attack that occurred in January 2023 either went after the privacy and security of a user’s digital wallet or exploited weak security measures when upgrading smart contracts.

An effective cybersecurity strategy is one that considers all potential areas of risk to a project and its users. If you’re planning to release or upgrade a DeFi project, reach out to our Web3 security experts at [email protected] for help with ensuring a secure rollout.

Why Are Smart Contracts Prey to Cyberattacks?

Transparent, autonomous, distributed, immutable, and trustless are among the key characteristics of smart contracts. Ironically, it’s because of these characteristics that hackers are so interested in hacking smart contracts.

Smart contracts with flaws are like low-hanging fruit that are just waiting to be picked since they can carry so much value at any given moment. Hackers have recently focused their attention on cross-chain bridges, which are protocols that let users exchange tokens from other blockchains. In just 2022, these cross-bridge attacks cost hackers over $1 billion in revenue.

Upgradability

There are numerous methods for attaining “upgradability” even though smart contracts are immutable. A new smart contract is deployed, and dependents are directed to the newly deployed contract, which is how it operates. Numerous smart contracts, the bulk of which may be modified, make up a standard DeFi protocol.

This type of decentralized protocol is vulnerable to a number of threats because it has the capacity to be upgraded, which hackers may use against it. In the event that a hacker succeeds in attacking one of the protocol contracts, they may be able to modify the protocol code in some way, either entirely or partially, to meet their requirements. And as long as there is money to be gained, hackers will keep developing new strategies to take advantage of smart contract loopholes.

Bugs

The existence of defects in the codes of smart contracts creates a vulnerability that can be exploited even in the absence of intentional attacks. Additionally, because the majority of these protocols are open source, it is easier for an attacker to look through the source code for potential security holes. It won’t take long for someone to identify a flaw in the code that will allow them to gain access to the system.

Code: Garbage In, Garbage Out

Coding errors in smart contracts are one of the main reasons for hacking. Smart contract audits are frequently conducted quickly, and the audit teams may not even have a complete understanding of the source code at the outset. It does not offer any security guarantees, despite the fact that smart contracts must go through several rounds of auditing.

Incompetence

Hackers may also use team ineptitude, or egregiously careless use of secret keys, as an attack vector. Most likely, you’ve heard of private key hacks or breaches. But how, in the first place, can a private key be “hacked”?

It is recommended as good security practice to save private keys, access keys, passwords, and other sensitive information in a secrets manager rather than in environment variables if you’re talking about programmatically signing transactions using a private key. A poorly constructed application will willingly reveal all application secrets, even when a secrets manager is used. There have been costly breaches that could have been easily prevented if only “basic cybersecurity hygiene” had been followed.

The “principle of least privilege” should be followed when it comes to access in smart contracts, and RBAC (role-based access control) should be used to establish them. When using your signer key in a “hosted” environment that isn’t secure, make sure the wallet has very little access to your application.

Comments

All Comments

Recommended for you

  • US Spot Bitcoin ETF Sees $101.79M Net Inflow Yesterday

    On August 8, according to Trader T's monitoring, US spot bitcoin ETFs saw a net inflow of $101.79 million yesterday.

  • US Official: Ukraine Agrees to Avoid Strikes on Non-Russian Tankers and Black Sea Oil Facilities

    On August 8, according to a US official, Ukraine has agreed not to target certain non-Russian tankers and Black Sea infrastructure vital to Kazakhstan's crude oil exports. This follows ship attacks last month that caused loading disruptions. The US official said Ukraine has set up contact points so commercial shipping companies can communicate information and ensure safe passage. The commitment was reached after meetings between senior US government leaders and Ukrainian leadership, marking a potentially significant step toward increasing regional oil shipments. Previously, activity in the region had cooled significantly due to several recent attacks near the Caspian Pipeline Consortium terminal in Russia's Novorossiysk. (Jin Shi)

  • U.S. July Nonfarm Payrolls Fall by 23,000, Missing Market Expectations

    On August 7, U.S. nonfarm payrolls decreased by 23,000 in July, compared with market expectations of an increase of 80,000, and the previous value was an increase of 57,000.

  • US May and June Nonfarm Payroll Additions Revised Down by 103,000 Combined

    On August 7, the US Bureau of Labor Statistics: May nonfarm payroll additions were revised down from 129,000 to 63,000; June nonfarm payroll additions were revised down from 57,000 to 20,000. After the revisions, the combined additions for May and June were 103,000 lower than previously reported.

  • U.S. Rate Futures Market Sees Lower Odds of Fed September Hike

    On August 7, the probability of a Fed rate hike in September as priced by U.S. interest rate futures declined.

  • New York Gold Futures Top $4,400 per Ounce

    New York gold futures topped $4,400 per ounce, up 2.36% on the day.

  • Japan Finance Minister: FX Market Affected by Moves Not Driven by Actual Demand

    Japanese Finance Minister Satsuki Katayama said she and U.S. Treasury Secretary Bessent agreed that the foreign exchange market has been affected by moves not driven by actual demand.

  • BTC Breaks Through $65,000

    Market data shows BTC has broken through $65,000, currently reported at $65,007.44, with a 24-hour increase of 0.6%. The market is highly volatile, please exercise risk control.

  • Brent Crude Drops 2.00% Intraday to $81.07/Barrel

    Brent crude oil fell 2.00% during the day, now at $81.07 per barrel. (Jin Shi)

  • Trump: Data Centers May Be More Important Than Oil

    August 7 news, U.S. President Trump said in an interview with Punchbowl News, "I saw the other day that Texas seems to be opposed to building data centers. I think that's a mistake. I'm not taking a position—I just think it's a mistake, because there are other communities that want to build data centers. When a community is willing to accept data centers, it means a lot of money will flow into that community. I don't think they're ugly. Some of the data centers I've seen are the most incredible buildings I've ever seen. They are very important to the economy. If Texas says no to data centers, that's a mistake, because data centers may be more important than oil."