Cointime

Download App
iOS & Android

OpenZeppelin Releases Top 10 Blockchain Hacking Techniques of 2022

Cointime Official

OpenZeppelin, a cryptocurrency cybersecurity firm offering an open-source framework for secure smart contract development, released a report of the top 10 blockchain hacking techniques in 2022.

According to the report, the year 2022 witnessed significant growth in blockchain development and the introduction of novel technologies. However, it also resulted in a rise in new hacking methods and exploits, which caused losses exceeding $3.7 billion.

Here is the list of Top 10 blockchain hacking techniques 2022:

10 - Compound-TUSD Integration Issue Retrospective

The double-entry point issue described in Compound-TUSD Integration Issue Retrospective is a perfect example of a bug that subtly breaks one thing and can lead to significant consequences.

9 - The “6.2 L2 DAI Allows Stealing” issue from the StarkNet-DAI-Bridge Smart Contracts Code Assessment

During the code assessment of the StarkNet-DAI-Bridge Smart Contracts audit, a security issue was discovered in a Cairo smart contract. As a relatively low-level language, Cairo has several potential pitfalls, and this issue is a prime example of one such problem.

8 - Avalanche’s $350M Risk Report

The Statemind team’s Avalanche Vulnerability Report: How We Discovered A $350M Risk and Avalanche Vulnerability Report: Technical overview revealed a clever exploit of seemingly innocuous behavior in the precompile which allowed for the sending of native assets and an optional call to the receiver. 

7 - Read-only Reentrancy – a Novel Vulnerability class responsible for 100m+ funds at risk

In a recent talk, blog post, and post-mortem, ChainSecurity demonstrated that reentrancy to view functions can result in devastating consequences. This work uncovered a new vulnerability type; unfortunately, it is not the last time we will see it.

6 - How to Steal $100M from Flawless Smart Contracts

One of the three research pieces by PwningEth in this year’s top ten highlights the difficulty of introducing a precompile that doesn’t break the security assumptions of applications.

5 - Phantom Functions and the Billion-Dollar No-op

This bug is deceptively simple and could have resulted in a loss of billions if not identified.

It serves as a reminder to exercise caution when calling functions that don’t return a value - especially the permit function - as they may not revert when expected.

4 - How did I Save 70000 ETH and Win 6 Million Bug Bounty

This entry in the Top 10 Hacking Techniques of 2022 underscores the importance of considering delegatecalls in smart contract development.

3 - Could Wrapped Tokens Like WETH Be (forced) Insolvent?

This vulnerability allowed an attacker to empty all wrapped token contracts, and not only take over the balance of the wrapped token, but also buy other tokens from the DEX by using the wrapped token as a rubber check.

2 - A vulnerability disclosed in Profanity, an Ethereum vanity address tool

Despite being publicly disclosed, this bug remained relatively unnoticed until it was exploited approximately six months later.

1 - Attacking an Ethereum L2 with Unbridled Optimism

Saurik found a peculiar bug even deeper than precompiles. Discovering an exploit at the node level earns top place for this finding.

Comments

All Comments

Recommended for you

  • BTC breaks through $69,000

     the market shows BTC breaking through $69,000, currently at $69,021.49, with a 24-hour increase of 1.15%. The market is highly volatile, please manage your risk accordingly.

  • Spanish Foreign Minister: Not worried about any consequences of refusing US access to military bases

     on March 3 local time, Spanish Foreign Minister Alvarez defended the Spanish government's refusal to provide the Rota and Moron military bases to the United States for participation in attacks on Iran. Alvarez stated that the operation initiated by the United States and Israel is not supported by the United Nations and is not part of the bilateral agreements allowing the use of the aforementioned Spanish sovereign military bases. Alvarez also said that the Spanish government is not concerned that this stance will have any consequences. Alvarez stated: "The position of the Spanish government represents the will of the vast majority of the Spanish people as well as the vast majority of people worldwide, which is to defend the UN Charter, respect international law, and believe that cooperation is always more powerful than confrontation."

  • Spot gold plunges nearly $100 in the short term.

     spot gold plunged nearly 100 dollars in a short time, spot gold fell below 5170 dollars/ounce, with a daily decline of 2.94%. 

  • BTC falls below $67,000

    the market shows BTC fell below $67,000, currently at $66,996.93, with a 24-hour increase of 1.18%. The market is highly volatile, please manage your risk accordingly.

  • ETH breaks $2,000

    the market shows ETH breaking through $2000, currently at $2001.64, with a 24-hour increase of 2.89%. The market is highly volatile, please manage your risks accordingly.

  • The US spot Bitcoin ETF saw a net inflow of $962.48 million yesterday.

    according to Trader T's monitoring, the US spot Bitcoin ETF had a net inflow of 962.48 million USD yesterday.

  • BTC falls below $66,000

     the market shows BTC fell below 66,000 USD, currently at 65,986.66 USD, with a 24-hour decline of 1.31%. The market is highly volatile, please manage your risks accordingly.

  • BTC falls below $66,000

     the market shows BTC fell below $66,000, currently at $65,973.16, a 24-hour drop of 2.66%. The market is highly volatile, please manage your risks accordingly.

  • ETH breaks $2,000

    market shows ETH breaking through $2000, currently at $2000.29, with a 24-hour increase of 3.73%. The market is volatile, please manage your risk accordingly.

  • The United States uses Anthropic's artificial intelligence technology in its airstrikes in the Middle East.

     United States used Anthropic's artificial intelligence technology in airstrikes in the Middle East, and just hours before the attack, Trump had just issued a ban against Anthropic.