Skip to content

Blockchain News Feed

All the latest news on Blockchain & Cryptocurrencies

Menu
  • Home
  • News
  • Exchanges
  • Market Analysis
  • YouTube
  • Brave Browser
Menu

Hackers Steal Over $20 Million of Ethereum After Exploiting Port 8584

Posted on juni 13, 2018 by Blockchain News

Chinese cybersecurity Qihoo 360 Netlab confirmed a group of hackers were successful in stealing $20 million from exposed Ethereum-based mining rigs and dApp.

Ethereum dApps Exposed

As per a report on Bleeping Computer, the thefts occurred after a Remote Procedure Call (RPC) was exposed on port 8545 on Ethereum software applications. Qihoo 360 security researchers have been tracking the loophole since March 2018, and as on June 11, 2018, the heist far exceeded $20 million worth of ether (ETH)

In March 2018, Qihoo 360 alerted users of a “bad actor” scanning the exposed 8584 ports:

Someone tries to make quick money by scanning port 8545, looking for geth clients and stealing their cryptocurrency, good thing geth by default only listens on local 8545 port. So far it has only got 3.96234 Ether on its account, but hey it is free money! pic.twitter.com/YVSWlMtYGa

— 360 Netlab (@360Netlab) March 15, 2018

Despite their warning, users failed to implement relevant security measures. In due course, multiple fraudulent groups noticed the ease of exploiting Ethereum dApps and joined in the heist.

The most successful was a single group of attackers, presumably with advanced software skills and computing power, who stole $20 million alone.

Remember this old twitter we posted? Guess how much these guys have in their wallets? Check out this wallet address https://t.co/t4qB17r97J $20,526,348.76, yes, you read it right, more then 20 Million US dollars https://t.co/SXHrdTcb6e

— 360 Netlab (@360Netlab) June 11, 2018

As the report noted “multiple groups” infiltrating Ethereum systems, the overall amount of stolen ETH remains unknown. 

The 360 research team stated:

“If you have honeypot running on port 8545, you should be able to see the requests in the payload, which has the wallet addresses. Quite a few IPs scanning heavily on this port now.”

The culprit of this security error is the automated port 8584, which is installed by default on most Ethereum dApps and provides a “link” between the user system to the servers.

Unfortunately, as users do not conduct their due diligence before using software, Qihoo 360 expects the number of groups scanning for exposed ports to increase with time, subsequently leading to considerable financial losses for users.

As advice to its readership, BTCManager appeals you to carefully read the documentation of any installed Ethereum software, as well as using multiple security measures to ensure fund safety.

The RPC 101 – Understanding Port 8584

Ethereum applications are wholly decentralized in nature and make use of ports that relay data between servers of users. Only approved third-party applications or services are allowed to interact with the ports, mostly to retrieve data from the Ethereum application – such as a mining software, portfolio tracker, or wallet.

The RPC is the most crucial link in this system. It facilitates third-party application access to the user’s funds, private keys, and even personal information.

Due to its sensitive role, the RPC is disabled by default. Developers include warnings to not switch on the interface unless the user is fully secured by advanced firewalls, access control lists, or credible authentication systems. As an additional measure, developers configure RPCs to accepts requests only from local interfaces instead of the third party.

However, the report noted that experienced developers are increasingly tampering with Ethereum applications, augmenting function at the cost of user security. Additionally, users fail to carefully read the documentation and unknowingly install exposed applications – making them a prime target for attackers.

As reported by BTCManager in May 2018, the infamous Satori Botnet scanned the ecosystem for exposed Ethereum port 3333 from 17,000 independent I.P. addresses.  

The post Hackers Steal Over $20 Million of Ethereum After Exploiting Port 8584 appeared first on BTCMANAGER.


Source: BTCManager.com
Original Post: Hackers Steal Over Million of Ethereum After Exploiting Port 8584

Ledger Nano X - The secure hardware wallet

Recente berichten

  • Tornado Cash Placed On US Sanctions List
  • Crypto Reacts: Arrest Of The Alleged Tornado Cash Developer, A Watershed Moment
  • Tornado Cash Token Loses 24% Of Value After Developer Arrest
  • Crypto Adoption JUMPS + HOW Does This Work? & Binance DELISTING
  • Under-the-Radar Altcoin Soars After Surprise Coinbase Roadmap Listing

Categorieën

  • Altcoin Buzz
  • Altcoin Buzz News
  • AMBcrypto
  • Bitcoin.com
  • Bitcoinist
  • BTC Manager
  • CCN
  • Coin Mastery
  • Coindesk
  • Coinpower News
  • Cointelegraph
  • CryproSlate
  • Crypto Daily
  • Crypto News (.net)
  • Cryptocoin News
  • Cryptocurrency News
  • CryptoDaily.co.uk
  • CryptoPotato
  • CryptosRUs
  • Daily HODL
  • DataDash
  • Ethereum Worldnews
  • Exchanges
  • ICO's
  • Invest in Blockchain
  • Market Analysis
  • News
  • News BTC
  • Newsbit
  • Portfolio
  • Pricecheck
  • Ready Set Crypto
  • The Modern Investor
  • ToshiTimes
  • Use The Bitcoin

Archieven

  • augustus 2022
  • juli 2022
  • juni 2022
  • mei 2022
  • april 2022
  • maart 2022
  • februari 2022
  • januari 2022
  • december 2021
  • november 2021
  • oktober 2021
  • september 2021
  • augustus 2021
  • juli 2021
  • juni 2021
  • mei 2021
  • april 2021
  • maart 2021
  • februari 2021
  • januari 2021
  • december 2020
  • november 2020
  • oktober 2020
  • september 2020
  • augustus 2020
  • juli 2020
  • juni 2020
  • mei 2020
  • april 2020
  • maart 2020
  • februari 2020
  • januari 2020
  • december 2019
  • november 2019
  • oktober 2019
  • september 2019
  • augustus 2019
  • juli 2019
  • juni 2019
  • mei 2019
  • april 2019
  • maart 2019
  • februari 2019
  • januari 2019
  • december 2018
  • november 2018
  • oktober 2018
  • september 2018
  • augustus 2018
  • juli 2018
  • juni 2018
  • mei 2018
  • april 2018
  • maart 2018
  • februari 2018
  • januari 2018
  • december 2017
  • november 2017
  • oktober 2017
  • september 2017
  • maart 2017
  • juni 2016
  • juli 2014
  • september 2013
  • augustus 2013
©2022 Blockchain News Feed | Design: Newspaperly WordPress Theme