Table of Contents:
· Galxe Incident and Possible Connection to Previous Front-End Attack on Balancer
· Both Back-End and Front-End Under Attack, Are Hackers Using More Diverse Methods?
On October 6th, several community users reported that their assets were stolen after authorizing the Web3 credential data network Galxe platform using their wallets. Galxe released a statement stating that the website has been shut down and they are working to fix the issue. Users are advised not to connect their wallets to Galxe during this time. Later, Galxe announced that they had discovered a security vulnerability affecting their official website's DNS records, which was attacked through their Dynadot account. Galxe is currently handling the situation and taking corrective measures. Please avoid visiting the official website domain for the time being.

Today, Galxe announced that it has regained control of its domain and ensured account security through Dynadot. Preliminary assessments indicate that the total amount of damaged funds is less than $200,000.
The on-chain detective ZachXBT posted on social media stating that the stolen funds from Galxe were transferred to the following address: 0x4103baBcFA68E97b4a29fa0b3C94D66afCF6163d, which appears to be the work of the same attacker who recently carried out the Balancer front-end attack.
Previously, on September 20th, DeFi liquidity protocol Balancer suffered from BGP or DNS hijacking attacks, resulting in a loss of $238,000. SlowMist Zone Intelligence Analysis believes that this was a BGPHijacking attack, and accessing the website link to the wallet would result in a phishing attack.
Related reading: "Balancer Attack: Security Team Layoffs and Hidden Dangers of Centralized Front-Ends"
The last time there was a large-scale discussion about decentralized front-ends was when Tornado Cash was sanctioned and its front-end was blocked. However, front-ends are still under security pressure today. Some people believe that ENS may be a solution to front-end attacks, but ENS domain name resolution is "centralized", so it is not very realistic to use it to resist "attacks on decentralization".
Although DeFi contracts are theoretically immutable and irreversible once deployed and cannot be tampered with, the vast majority of front-ends are still implemented through traditional architectures. Although web pages themselves are constantly evolving and developing, there are many potential threats in terms of domain names, network services, servers, storage services, etc., and attacks on front-ends are often overlooked by developers.
translates to
Earlier, the Curve pool vulnerability was different from most cryptocurrency hacking incidents we have seen in the past few years, as unlike many previous vulnerabilities, this one was not directly related to a smart contract vulnerability, but rather to the underlying compiler of the language it uses.
Related reading: "Deeply exploring how re-entry attacks stole $70 million from Curve pool"
Due to the problem in the way Vyper language handles re-entry locks, this issue occurred. Therefore, the contract creator may have deployed seemingly reasonable code, but due to the compiler not handling the lock correctly, attackers were able to exploit this flawed lock to achieve unexpected results in contract behavior.
BlockBeats reported on September 1st that since 2023, Web3 platforms have lost $1.25 billion in 211 hacking incidents, with losses exceeding $23 million in August alone due to hacking attacks. Since the launch of the Base mainnet to the public on August 9th, four projects have suffered significant losses due to hacking attacks, making it one of the most attacked chains alongside Ethereum and BNB Chain.

In addition, since September, multiple project parties have been targeted by hot wallet attacks.
On September 6th, Edward Craven, co-founder of Stake.com, addressed the recent hacking incident stating that the vulnerability was not due to the hacker controlling their private key, but rather that the attacker was able to make several unauthorized transactions from their hot wallet. Craven stated that the attack targeted the company's services for authorizing transactions on Ethereum, Polygon, and BNB Chain.
On September 14th, the cryptocurrency trading platform CoinEx released an update on a hacking incident, stating that the reason for the event was the leakage of the hot wallet's private key. The investigation and handling of the incident are being carried out in an orderly manner, and the assets in CoinEx's cold wallet have not been affected by this event.

On September 25th, Cyvers Alerts confirmed that a hot wallet for HTX was attacked, resulting in a loss of $7.9 million.

Compared with the past, the number of hacking incidents has been decreasing recently, which is closely related to the prosperity of the market. During the DeFi summer and NFT summer periods, new billion-dollar protocols were launched every week, but now the market has shrunk significantly. At the same time, the market opportunities for hackers to find vulnerabilities or create large-scale attack incidents are also gradually shrinking, which means that hackers need to explore new, undeveloped entry points.
Related reading: "Curve's vulnerability exploitation may have opened up new ideas for hackers".
In this Curve incident, Box believes that the lesson all developers should learn is: do not be greedy and choose immature solutions just to follow the trend; do not approve your own code without writing test cases (even the test cases for several versions of Vyper that went wrong were incorrect); never approve your own code; some wealth may take years to be discovered; being un-upgradable is arrogance towards oneself and contempt towards others.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia