Oct 10, 2022 min read
Binance Bridge hack perspectives, a documentation hub for your DAO and much more!

Over the next 8-10 minutes, we will be talking about hacks that caught our eye, DApps that we found interesting and our picks from Twitter and Reddit that we enjoyed.

Security Digest

Binance Bridge Hack: The details you should care about


On Oct. 7, Binance Bridge was hacked and the attacker managed to spoof the bridge in to giving him 1,000,000 BNB twice, the net result of the dollar value being ~$570M. The hack was carried out when the attacker was able to forge a proof that would essentially allow the bridge to do whatever the attacker wanted it to do. To further understand what happened here, we must first understand the Binance architecture. Binance has two chains - the older blockchain now called the Beacon Chain and the newly implemented Binance Smart Chain (BSC) which is essentially like an Ethereum EVM. Both chains use BNB as the main token, and funds can be moved across blockchains using the Binance Bridge. On the BSC side, a proof is required that funds have been withdrawn from the old Beacon Chain to validate transactions. The attacker was able to take advantage of a bug that spoofed a proof on the BSC blockchain which led the bridge to mint BNB out of thin air after which the attackers started converting the newly minted BNB into various tokens to run away the money.

After the attack, Binance immediately took action to halt the BSC blockchain by working with the 26 validators of the Binance network, out of which 19 were able to come together and stop the attacker from getting away. The net result was that the attacker was only able to move $70-80M off of the halted BSC blockchain. But, the larger question remains the speed with which the Binance network was able to halt the entire blockchain. Harkening back to the DAO hack on the Ethereum network in 2016, the Ethereum community eventually settled on creating a hard fork of the network, which came after much debate, and consensus from the entire network of Ethereum participants. The point here being that the Ethereum network could not perform unilaterally - like in Binance’s case. The ability to quickly assimilate Binance validators puts in question the nature of decentralization of the network.

Finally, the message received from the Binance Bridge exploiters within their transaction. The attackers left a note stating the following,

“I don’t believe you because you are not sincere. I only exploited eth and bsc chains. If I attack other chains like FTM, TRON, POLYGON, I believe I can get $100 million. With reference to past Nomad and Wintermute events, I should get a higher bounty than what I get now. It’s hard not to suspect that this is your official backdoor, and you should be happy that the exploit was done by me and no one else.”

What would you classify this attack as, a criminal activity or simply an effective way to expose a vulnerability in an open system.

Dapp News

CharmVerse: Notion for web3


CharmVerse is a place for community contributors to coordinate day-to-day work, sign in with crypto wallets, and unlock workspaces with DAO tokens/NFTs. CharmVerse’s main proposition is to be able to create any task into a bounty. Workspace managers can pay out bounties in ETH, custom tokens or USDC. Additionally, CharmVerse can provide token gated access to individual wallets, NFTs, groups of token/NFT holders, DAO Members or POAP collectors. Workspace admins can create roles specific to the asset that an individual may hold in the wallet and provide access to specific segments within the workspace. DAOs and venture clubs could use CharmVerse to provide deal specific memos, or updates to those that have invested in the particular deal, the same goes for content creators wanting to engage their community.

Updates from Cypherock

NEAR is now supported on Cypherock X1. You will now be able to send and receive NEAR tokens with your Cypherock X1 wallet, additionally, you can create your custom .near account from within CySync. More details on updates and features to follow!

Is Your Crypto Safe? Take the Cypherock Quiz and find out!

Is your crypto safe

Will your crypto get hacked? Are you going to lose your crypto? Cypherock has come up with a detailed quiz that will help you understand the pros and cons of your security model. Upon completion, you will get a detailed analysis mailed to you. Take the quiz now!

