Crypto-Sec: DeFi Saver ownership phish, iVest shuts down after attack, plus hackathon clipboard hijack
A DeFi Saver user fell victim to a novel phishing attack, and a clipboard hijacker discovered at hackathon, plus new windows vulnerability
Crypto scams, hacks and exploits and how to avoid them: Crypto-Sec
A user of decentralized finance management protocol DeFi Saver suffered an unusual style of phishing attack on Aug. 21. According to an X post from blockchain security firm Global Ledger, the attacker tricked the user into reassigning ownership of their DeFi Saver Proxy contract.
The victim reportedly attempted to perform a transaction soon afterward, but it failed. The attacker then changed ownership again and drained the smart contract wallet of all of its Dai (DAI) stablecoin, removing over $55 million worth in total.
Blockchain data shows that the DAI came from the null address rather than from the victims address, implying that the attacker must have minted the DAI using the victims collateral instead of directly draining it from the victims account.
Go to Source
Author: Christopher Roark
Related posts:
- Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec
- Shanghai Man: AscendEX reopened after $80m hack, Huobi suffers key personnel departures, and government officials punished for mining activities
- 6 Questions for John deVadoss of Neo and the Global Blockchain Business Council
- AI Eye: Get better results being nice to ChatGPT, AI fake child porn debate, Amazon’s AI reviews