Crypto Prices

Security Flaw Leads to 36% Loss of Bitcoin Fund Backing; Incident Unnoticed for 74 Days

1 hour ago
1 min read
2 views

Security Vulnerabilities in Decentralized Finance

In a recent revelation of security vulnerabilities affecting decentralized finance, a significant flaw in a software system used by Nomic has led to the loss of a staggering one-third of a bitcoin fund’s financial support, an occurrence that astonishingly went undetected for almost two and a half months. The incident, which sheds light on the fragility of blockchain technologies, was specifically linked to a custom Inter-Blockchain Communication (IBC) path utilized by the decentralized exchange (DEX) platform, Osmosis.

The Incident

On June 25, an attacker exploited this flaw, allowing for the unauthorized minting of unsupported nBTC, which was subsequently deposited into the Alloyed BTC pool on Osmosis. This breach of security, initially obscured but eventually uncovered, resulted in a loss of approximately 39.84 nBTC, accounting for roughly 36% of the backing for Alloyed BTC.

Once the breach was detected, Osmosis took immediate action to halt all deposits and withdrawals concerning both Nomic and Alloyed BTC to prevent further unauthorized transfers. The platform collaborated with blockchain validators to execute an urgent update that secured 22.65 BTC from the attacker’s wallet.

Response and Recovery

In an official communication shared on X, Osmosis expressed their intention to propose the seizure of these assets to their governance framework, asking for the use of accumulated BTC from the community pool to compensate for the shortfall and restore the complete backing of Alloyed BTC.

Investigation Findings

An independent researcher, known as Rarma, investigated the underlying issue and identified that the flaw in Nomic’s code allowed for double-spending of nBTC. According to Rarma’s analysis, only one of the 18 processes governing coin creation in Nomic’s code malfunctioned, failing to verify the authenticity of the receiving account and permitting the duplicate minting of bitcoin.

This exploit required a minimal cost to execute, demonstrating that significant risks can exist in decentralized finance systems due to the reliance on custom code for minting tokens. Remarkably, Rarma noted that when he disclosed this vulnerability on September 8, the problematic code remained unaltered in Nomic’s development branch. The following day, an update addressing the security flaw was published by Osmosis.

Implications for Decentralized Finance

While the incident raises alarm regarding the stability of BTC tokens created on alternate chains, which are inherently reliant on the robustness of the underlying code, it serves as a crucial consideration for users engaging in decentralized financial systems. Meanwhile, the Liquid team has progressed to the next phase of their recovery following an earlier incident involving a white-hat hacker, indicating a continuing focus on security within cryptocurrency infrastructures.

As the world of decentralized finance evolves, this case highlights the ongoing need for vigilance and rigorous testing to safeguard against vulnerabilities that can lead to significant financial repercussions.

Popular