BTC $78,058.14 -0.27%
ETH $2,438.59 -0.86%
BNB $686.85 -1.03%
XRP $1.37 -2.46%
SOL $102.68 -2.49%
TRX $0.3370 -1.04%
DOGE $0.0826 -2.76%
ADA $0.1954 -3.30%
BCH $246.33 +0.21%
LINK $11.27 -1.49%
HYPE $80.84 -2.92%
AAVE $123.18 -1.82%
SUI $0.7227 -3.07%
XLM $0.1763 -2.69%
ZEC $825.22 -1.45%
BTC $78,058.14 -0.27%
ETH $2,438.59 -0.86%
BNB $686.85 -1.03%
XRP $1.37 -2.46%
SOL $102.68 -2.49%
TRX $0.3370 -1.04%
DOGE $0.0826 -2.76%
ADA $0.1954 -3.30%
BCH $246.33 +0.21%
LINK $11.27 -1.49%
HYPE $80.84 -2.92%
AAVE $123.18 -1.82%
SUI $0.7227 -3.07%
XLM $0.1763 -2.69%
ZEC $825.22 -1.45%

rsi

All
Article
Flash

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

hot_img The Shanghai court in China analyzes the criminal responsibility determination in cases of "traffic diversion" fraud involving virtual currency, which may constitute complicity in fraud or illegal use of information networks

The Shanghai Intermediate People's Court has published typical cases, analyzing whether "traffic personnel" involved in telecommunications network fraud related to virtual currencies constitute accomplices in fraud. From February 2022 to April 2023, the defendants, for the purpose of profit, assisted upstream fraudulent activities by "draining traffic," using online virtual phone software to lure victims into related scam groups, ultimately causing 30 victims to be defrauded of more than 2.34 million yuan (the same currency hereafter) by an overseas fraudulent organization. The overseas fraudulent organization transferred funds into the suspects' trading accounts via virtual currency.The Shanghai First Intermediate People's Court pointed out that in telecommunications network fraud cases, "traffic personnel" may constitute accomplices in fraud or illegal use of information networks depending on specific circumstances. The key lies in determining whether they have formed a clear criminal intent connection with the upstream fraudulent organization and whether there is stable cooperation and division of labor. In judicial practice, when assessing the criminal responsibility of "traffic personnel," factors such as their role in the criminal chain, the degree of organizational management, connections with upstream criminals, methods of profit, and abnormal behavior should be comprehensively considered. Actions that only provide general online services and do not form a conspiracy to commit fraud should be distinguished from "draining" actions that knowingly participate in the implementation of fraud.

hot_img Centrifuge releases governance proposal: exploring the conversion of CFG tokens into equity

Centrifuge released governance proposal CP172 on August 18, exploring the feasibility of converting CFG tokens into company equity. The proposal states that Centrifuge's current business has shifted towards institutional infrastructure, and the original token structure restricts partner expansion and capital raising. It proposes to offer eligible CFG holders the option to convert their tokens into equity.The core details of the proposal include: 1 CFG can be exchanged for 1 share of Centrifuge Inc. equity, which will be recorded in a tokenized form; qualified holders with more than 100,000 CFG can directly enter the shareholder register, while holders below this threshold are proposed to participate through CoinList's trust structure, with no additional fees or minimum requirements; holders who do not participate in the conversion can continue to hold or sell their tokens, and the team, community, and partners will receive the same class of shares. The proposal is currently in the Request for Comments (RFC) stage for 14 days and will proceed only after board approval and governance voting.It is reported that Centrifuge is an open decentralized infrastructure for on-chain asset management and real-world asset (RWA) tokenization. The platform enables asset management companies to tokenize institutional-grade assets (such as credit, real estate, and government bonds) into freely transferable tokens for use in the DeFi ecosystem. Its core components include a compliant asset origination framework, Anemoy (a full-service fund architecture asset management division), and index proof (PoI) infrastructure for tokenizing structured financial products (such as S&P 500 index funds).
app_icon
ChainCatcher Building the Web3 world with innovations.