ETH Exchange ETH Exchange
Ctrl+D ETH Exchange
Home > Blockchain > Info

Analysis: Nomad attackers use the contract process function to extract



Time:8/2/2022 2:53:05 AM

[Analysis: Nomad attackers use contract process function to extract] Jinjin Finance News, at noon on August 2, Beijing time, public opinion monitoring of Chengdu Lianan Chain Bing-Blockchain Security Situational Awareness Platform showed that the cross-chain communication protocol Nomad was attacked , Chengdu Lianan security team will now share the analysis results as follows. Through the transfer transactions of the attacked contract (0x88a69b4e698a4b090df6cf5bd7b2d47325ad30a3), we can see that many addresses have been attacked. By finding a related transaction, we can see that the attacker used the process function in the contract (0xb36f6479b1aa5582ce862bfb6eb94591e1b0e0b977188c2e8ca85699efcd6183) to extract.

In the process function, you can see that the contract has judged _messageHash, and when the input messages[_messageHash] is 0x000000...., it is equivalent to any unused hash and can be judged to pass. Then follow up the acceptableRoot function, because _root is set to zero (x000000....), and confirmAt[_root] is equal to 1, resulting in a constant judgment and the attacker can withdraw funds. The Chengdu Lianan Lianbizhui platform will monitor the stolen funds in real time.

Other news:

Institutional analysis: WTI crude oil option long trading is active, indicating that it may continue to rise above $80: According to news on October 8, after the price of U.S. crude oil futures reached $80 a barrel, the oil options market showed that traders were hedging the risk of further price rises. On Friday, call premiums exceeded put premiums for the first time since October 2019. WTI oil prices hit a near seven-year high of $80 a barrel this week, but traders worry that higher natural gas prices will lead to a surge in demand for oil, while OPEC+ refrains from increasing output. ICAP energy expert Scott Shelton said severe winter weather "increases the potential for an upside burst in this market, and this skew (skew) will continue for several months." (Golden Ten) [2021/10/9 5:48:30]

Institutional analysis: Bitcoin's decline may signal a pause in bond selling: Bitcoin is about to suffer its largest two-day drop in a month, which may be a harbinger of a pause in bond selling that has panicked the market. Both cryptocurrencies and bond yields are surging for the same reason, expectations of massive stimulus. Based on market value, bitcoin yields are largely in sync with 10-year government bond yields in countries like the UK, Canada, Germany and the US. The bond sell-off in Asia is even showing signs of easing. It should be noted that this theory does not apply to oil prices. Bitcoin and oil prices also tend to move in tandem, but the cryptocurrency's ups and downs haven't had much of an impact on oil prices so far. (Golden Ten) [2021/2/23 17:43:36]

Analysis | coindesk analysis: Bitcoin has continued to fall for six months or will fall to $3,100: According to coindesk analysis, Bitcoin fell for the sixth consecutive month in January, enhancing the credibility of the bearish. Therefore, Bitcoin may retest the December low around $3,100. If strong support is found from the 200-week moving average at $3,298 and eventually pushes the price to $3,658, a sustained rally to $4,000 is possible. [2019/2/1]

Encrypted loan aggregation platform FujiDAO integrates Connext to expand cross-chain functions

According to news on August 2.

Block Chain:8/2/2022 2:52:53 AM
Twitter has issued dozens of subpoenas to investigate Musk's motives for breaking the contract.

According to news on August 3.

Block Chain:8/3/2022 2:55:17 AM
Gym Class, a sports metaverse start-up company, completed a $8 million seed round of financing, led by a16z

[Sports metaverse start-up company Gym Class completes $8 million in seed round financing.

Block Chain:8/3/2022 2:55:04 AM
OpenSea NFT gifting feature has "mismarked as a purchase transaction" issue.

Jinse Finance reported that according to d.

Block Chain:8/3/2022 2:55:03 AM
There are more than 400 Web3 Foundation Grant funding projects

Jinse Finance reported that according to Polkadot’s official news.

Block Chain:8/2/2022 2:52:57 AM
The cream finance flash loan attacker transferred 1473 ETH

On August 3, according to PeckShield monitoring.

Block Chain:8/3/2022 2:55:28 AM
Memorandum of Understanding between Dubai Blockchain Center and Chaintech Labs Ltd

Jinse Finance reported that Dubai Blockchain Center (DBCC) a.

Block Chain:8/1/2022 2:50:14 AM
British man James Howells plans to build a robot dog to find the hard drive of the lost BTC

Golden Finance reported that the British man James Ho.

Block Chain:7/31/2022 2:48:58 AM
Wom Music opens an appointment event and distributes 10,000 avatars

According to official news.

Block Chain:8/2/2022 2:52:40 AM