AFX, a decentralized perpetual exchange operating on Arbitrum, reportedly lost $24.15 million on Wednesday, while the Verus Ethereum bridge was attacked hours later. Hackers stole more than $31.6 million across two unrelated crypto bridge exploits spaced just hours apart, targeting bridges operated by decentralized perpetual exchange AFX and Verus Protocol. According to Blockaid, AFX, a decentralized perpetual exchange operating on Arbitrum, reportedly lost $24.15 million on Wednesday through a hack targeting one of its crosschain bridges. Hours later, Blockaid said it detected an exploit targeting the Verus Ethereum Bridge that resulted in about $7.5 million in crypto being stolen. The back-to-back exploits highlight the continued security risks facing crosschain bridges, which hold large pools of assets and move funds between separate blockchains. Read more
The incident is significant for developers and applications that handle Injective wallet workflows, Socket researchers said. Hackers compromised a widely used Injective software package in a supply chain attack with malware designed to steal crypto wallet private keys, adding to a growing attack vector involving attackers using legitimate platforms to deliver malicious payloads. Security firm Socket discovered on Thursday that a popular npm (node package manager) package with around 50,000 weekly downloads used for building on the Injective blockchain was maliciously modified to steal wallet private keys and seed phrases. The large number of downloads makes the incident “significant for developers and applications that handle Injective wallet workflows,” Socket researchers said. The malicious code has since been removed. Read more
EasyDNS CEO Mark Jeftovic said the social engineering attack was highly sophisticated and the company is conducting further investigation to determine how the breach occurred. Ethereum Name Service gateway eth.limo has revealed that the domain hijacking on Friday was caused by a social engineering attack directed against EasyDNS, its domain name service provider. According to a postmortem published by eth.limo on Saturday, an attacker impersonated one of its team members to initiate an account recovery process with easyDNS, granting access to the eth.limo account and allowing them to alter domain settings. “The NS records were changed and directed to Cloudflare… Once we understood that a DNS hijack had taken place, we immediately notified the community as well as Vitalik Buterin and others. We then began contacting EasyDNS in an attempt to respond to the incident,” the company said. Read more