Hiding in Plain (Text) Sight

3
0.50
Bifrost releases the technical investigation of the abnormal movement of BNC on July 6th. They have determined that while their on-chain code has been rigorously audited and battle-tested, the security of their off-chain script code was overlooked. The multi-signature script private key was stored in plain text on a configuration file of the hacked script server. The automated fee replenishment script had a 100 BNC limit but no limit on call frequency, so it was easily circumvented by utilizing batch calls. The 3/5 multi-signature for the script is useless because it is not verified during an automated multi-signature. Bifrost is taking various steps to prevent future incidents from occurring, including comprehensively reviewing its off-chain code and moving its scripts on-chain where possible

Tags

Reactions

More from this author

Ramping Up Even Further
yay.oi 🥚
yay.oi 🥚
·July 1, 2025

Ramping Up Even Further

The Vortex on/off ramp, with the assistance of Pendulum infrastructure, has now recorded a transaction flow in excess of $1.5M.

Who’s the Next Astar dAppStar?
yay.oi 🥚
yay.oi 🥚
·July 1, 2025

Who’s the Next Astar dAppStar?

Astar dApp Staking Period 5 is open for voting until Monday July 7th. Stake ASTR with your favorite project now to support their growth and earn some staking and bonus rewards for yourself.

Flappin’ for the Summer
yay.oi 🥚
yay.oi 🥚
·July 1, 2025

Flappin’ for the Summer

The Summer Surge, Gavun Wud’s second N3mus Flappy Wud tournament, kicked off on June 30th. Flapper’s have thirty days to compete for a prize pool of $250 USDC.