BadgerDAO disclosed details of how it was hacked for $120 million

[ad_1]

in a This week’s blog post, DeFi platform BadgerDAO provides detailed information $120 million was exploited earlier this month.

  • BadgerDAO stated that the phishing incident on December 2 was caused by “malicious injection fragments” of Cloudflare, an application platform running on the Badger cloud network.
  • Hackers use compromised API keys created without the knowledge or authorization of Badger engineers to regularly inject malicious code that affects some of their customers.
  • The hacker eventually stole $130 million in funds, but about $9 million of it was recoverable because these funds were transferred by the hacker but have not yet been withdrawn from the badger’s vault.
  • Badger has since patched the Cloudflare vulnerability, updated Cloudfare’s account password, and deleted or updated the API key when possible.
  • Badger has hired cybersecurity company Mandiant and blockchain analysis company Chainalysis to investigate the vulnerability, and is working with the two companies and the authorities in the United States and Canada to recover any possible funds.

[ad_2]

Source link