BTC $62,600.54 -1.64%
ETH $1,867.09 -1.13%
BNB $603.60 -0.94%
XRP $1.00 -0.55%
SOL $75.27 -1.03%
TRX $0.3323 -0.55%
DOGE $0.0693 -1.06%
ADA $0.1792 -2.13%
BCH $202.75 -5.16%
LINK $8.80 +0.10%
HYPE $56.05 -2.62%
AAVE $85.71 -3.05%
SUI $0.6755 -2.03%
XLM $0.1598 -0.21%
ZEC $483.58 -1.35%
BTC $62,600.54 -1.64%
ETH $1,867.09 -1.13%
BNB $603.60 -0.94%
XRP $1.00 -0.55%
SOL $75.27 -1.03%
TRX $0.3323 -0.55%
DOGE $0.0693 -1.06%
ADA $0.1792 -2.13%
BCH $202.75 -5.16%
LINK $8.80 +0.10%
HYPE $56.05 -2.62%
AAVE $85.71 -3.05%
SUI $0.6755 -2.03%
XLM $0.1598 -0.21%
ZEC $483.58 -1.35%

attacks

All
Article
Flash

The Ethereum Foundation provides security funding to WEBCAT to assist in wallet verification front-end code to prevent phishing attacks

According to official news, the Ethereum Foundation's "Trillion Dollar Security" (1TS) has announced a special grant to the Freedom of the Press Foundation (FPF) to support the ongoing development of the open-source tool WEBCAT, aimed at addressing the long-standing front-end code verification security gap in Ethereum wallets and decentralized applications (DApps).WEBCAT (Web-based Code Assurance and Transparency) is an open-source tool designed to help browsers verify whether the code loaded by a website matches the version publicly released by the developer.This funding will promote the expansion of WEBCAT to Ethereum wallets and application scenarios, enabling users to verify whether the front-end pages they access have been tampered with.The Ethereum Foundation stated that while HTTPS can verify the website a user is connected to and encrypt communication, it cannot prove that the front-end code actually running on the website is the same version released by the developer. If an attacker controls the website's front-end code, they may modify the transaction receiving address without the user's knowledge or induce the user to sign transactions that do not match the content displayed on the page.The Ethereum Foundation noted that front-end attacks have become a significant security risk for blockchain infrastructure, with malicious modifications to web interfaces potentially leading to supply chain attacks, DNS hijacking subsequent attacks, and user interface deception.WEBCAT was initially developed by the Freedom of the Press Foundation to enhance the code credibility of secure communication systems like SecureDrop.With this expansion into the Ethereum ecosystem, it will complement security measures such as "Clear Signing" in the 1TS program: the former helps wallets confirm that the application front-end has not been tampered with, while the latter helps users understand the transaction content they are approving.

Telegram claims to have suffered from "de-listing extortion" attacks: the temporary removal of the app from the Apple App Store was caused by a user embedding prohibited content

Telegram founder and CEO Pavel Durov stated that Telegram was briefly removed from the App Store by Apple recently due to a user embedding illegal pornographic content in a public group. The app was restored within hours.Durov mentioned that the attackers exploited a technical vulnerability to insert AI-modified illegal content into old messages in active groups, hiding the content by editing historical messages, making it difficult for regular group members to discover and report it in a timely manner. Such attacks are classified as "takedown extortion," where attackers use automated accounts to embed violations in public groups and report them to platforms like Apple, attempting to force group administrators to pay a ransom, or else the community would be banned due to platform rules.Durov further explained that Telegram continuously combats illegal content through user reports, AI filtering, content hashing, and other mechanisms. This incident is not a systemic issue of the platform but rather a targeted attack exploiting rule loopholes by the attackers.He also warned that Apple's direct removal of the app without prior contact with Telegram could pose risks to all mobile applications that provide user-generated content (UGC), and platform developers need to enhance their defenses against malicious reporting and "takedown attacks."
app_icon
ChainCatcher Building the Web3 world with innovations.