30/03/2022 A hacker stole $625 million from the blockchain behind NFT game Axie Infinity

Three non-NFT Sky Mavis “axie” charactersSky Mavisnone

Roughly $625 million worth of cryptocurrency has been stolen from Ronin, the blockchain underlying popular crypto gameAxie Infinity. Ronin andAxie Infinityoperator Sky Mavisrevealed the breachon Tuesday and froze transactions on the Ronin bridge, which allows depositing and withdrawing funds from the company’s blockchain.

Sky Mavis says it’s working with law enforcement to recover 173,600 Ethereum (currently worth around $600 million) and 25.5 million USDC (a cryptocurrency pegged to the US dollar) from the culprit, who withdrew it from the network on March 23rd. The attack focused on the bridge to Sky Mavis’ Ronin blockchain, an intermediary betweenAxie Infinityand other cryptocurrency blockchains like Ethereum. Users could deposit Ethereum or USDC to Ronin, then purchase non-fungible token items or in-game currency, or they could sell their in-game assets and withdraw the money.

According to Sky Mavis, an attacker used hacked private security keys to compromise the network nodes that validate transfers to and from the Ronin blockchain. That let the attacker quietly withdraw large quantities of Ethereum and USDC. The transfer was discovered today — nearly a week later — when another user attempted to withdraw 5,000 Ethereum through the bridge.

“As we’ve witnessed, Ronin is not immune to exploitation”

Sky Mavis says the “axie” NFT tokens players must buy to accessAxie Infinityhaven’t been compromised, nor have the SLP and AXS in-game cryptocurrencies used in battling and breeding the pokĂ©mon-like cartoon axolotls. (Disclosure: Adi purchased three axies for a total of $105 last month in order to report on the game; axies currently sell starting at around $25 apiece.) But the freezing of withdrawals and deposits effectively locks out many new players, and the hack leaves the fate of other user funds on the Ronin blockchain in question. Sky Mavis says it’s “working with law enforcement officials, forensic cryptographers, and our investors to make sure there is no loss of user funds,” calling that its “top priority.”

Validator nodes are a feature of proof-of-stake blockchains like Ronin, which are less energy intensive than proof-of-work systems like Bitcoin and Ethereum. The nodes review new transactions to confirm that their inputs and outputs match and that authorization signatures are valid, rejecting any transactions that don’t conform. Using a smaller number of nodes is faster and more efficient — but as the hack shows, it can create security risks if a majority of the nodes are compromised. It’s a potential vulnerability for blockchains that are touted as both cheaper and more environmentally friendly than Ethereum.

Validator nodes are a key feature of less energy-intensive blockchains

According to Sky Mavis, the Ronin attack was possible partly because of a shortcut the company had taken to relieve an “immense user load” on its network in November of last year — months after the gameexploded in popularity in the Philippinesand other countries where players relied on it as a full-time job. The system was discontinued in December, but the permissions that allowed it were never revoked. In addition to compromising four of Sky Mavis’ own nodes, the attacker exploited them to get access to one managed by the community-owned Axie DAO. After compromising five of the nine validator nodes, the attacker could effectively override any transaction security and withdraw whatever funds they liked.

Sky Mavis says it will increase the required number of nodes to eight for transactions, and it will reopen the Ronin bridge “at a later date” once it’s certain no more funds can be drained. For now, the Ronin breach appears to be the largest hack to date of “decentralized finance” networks, coming on the heels ofa $322 million theftfrom the bridge protocol Wormhole last month.

“As we’ve witnessed, Ronin is not immune to exploitation and this attack has reinforced the importance of prioritizing security, remaining vigilant, and mitigating all threats,” the company said in its announcement. “We know trust needs to be earned and are using every resource at our disposal to deploy the most sophisticated security measures and processes to prevent future attacks.”

Arts

https://www.theverge.com/2022/3/29/23001620/sky-mavis-axie-infinity-ronin-blockchain-validation-defi-hack-nft

Interesting NFTs
Michael Jordan - Crown Collection
“All you needed was one little match to start that whole fire.”- Michael Jordan. In regards to both the action on the court and everything that happened off of it, Jordan provided a spark that changed the future in so many different ways throughout his tenure in Chicago, and even decades after the fact. And, in the end, he got everything that he wanted when he began his NBA journey: he turned the team and organization as a whole into a respected program, like the dynasties he looked up to as a child. Having steered the Chicago Bulls to an incredible six championship rings in eight years from 1991-1998, scooping up five MVP awards in the process, Jordan is one of just a handful of superstars who have truly transcended their sports. Jordan and Scottie Pippen’s (right) relationship both on and off the pitch was arguably the foundation of the Bulls’ incredible success. Scottie Pippen was present with Jordan for all six championships in eight seasons. Dennis Rodman (left) His relentless and smart play perfectly suited what Jordan and Jackson wanted to do to take the Bulls to greater heights. Although his exploits off the court earned him special fame, Rodman was unquestionably one of the greatest basketball players of his generation and one of the finest defensive players in the history of the game.
Gunky's Uprising
Gunky's Uprising by SSX3LAU Slimesunday and 3LAU team up once again under their alias SSX3LAU for a collection featuring their first exploration into color. TBD is a full length music video featuring an unreleased song from 3LAU and Slimesunday\u2019s mesmerizing animation. In a first for the artists, TBD\u2019s collector will have the opportunity to name the song (some restrictions apply).
CryptoPunk #9373
The CryptoPunks are 10,000 uniquely generated characters. No two are exactly alike, and each one of them can be officially owned by a single person on the Ethereum blockchain. Originally, they could be claimed for free by anybody with an Ethereum wallet, but all 10,000 were quickly claimed. Now they must be purchased from someone via the marketplace that's also embedded in the blockchain.
#61028
By OthersideDeployer
static/bound
jean bordeaux, 2020. 1/1