Plan for $1M bug bounties and double the nodes in wake of $600M Ronin hack

Cointelegraph发布于2022-04-28更新于2022-04-28

文章摘要

The Ronin Network and Sky Mavis have vowed to upgrade their smart contracts, offer lucrative bug bounties and ramp up security following the $600 million hack late last month.

The Ronin Network and Sky Mavis have vowed to upgrade their smart contracts, offer lucrative bug bounties and ramp up security following the $600 million hack late last month.
As Cointelegraph previously reported, the Ethereum sidechain developed for the popular NFT game Axie Infinity was the victim of an exploit for 173,600 Ether (ETH) and 25.5 million USD Coin (USDC) worth more than $612 million at the time.
Earlier this month the Federal Bureau of Investigation (FBI) attributed the attack to North Korea-based and state-sponsored hacking group Lazurus, as it fired off a warning to other crypto and blockchain organizations.
Ronin announced its platform changes via a post-mortem report published yesterday, noting that all user funds are in the process of being restored as it vowed to make sure this “never happens again.”

The hack run down
The hack was the result of a spear phishing attack on a former Sky Mavis employee (developers of Axie Infinity). The bad actor was able to leverage the employee’s credentials to access Sky Mavis’s four validator nodes out of a total of nine in the Axie/Ronin ecosystem.
This by itself was not enough to do any damage, but “the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator.”
“This traces back to November 2021 when Sky Mavis requested help from the Axie DAO to distribute free transactions due to an immense user load. The Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allow list access was not revoked,” the report reads.
Following the hack, big changes are being implemented at both Sky Mavis and the Ronin Network.
Ronin
The Ronin Network hopes to have its bridge open again by mid to late May, with Binance providing support until then with withdrawal and deposit infrastructure for Axie users.
The team is about 80% through upgrading Ronin bridge smart contracts, they’ll be reworking the backend, migrating all pending withdrawals and launching a validator dashboard that “allows for approving large transactions and adding/removing new validators.”
“The Ronin Network bridge is currently being redesigned and will open once we are confident that it can stand the test of time. We initially expected to be able to deploy the upgrade by the end of April, but this is not a process that we can afford to rush.”
Sky Mavis
Sky Mavis will ramp up its security measures by seeking the help of “top tier security experts,” conducting contract audits and implementing stricter internal procedures such as training courses to “combat external threats.”
Notably, it will also be significantly upping its node count to help decentralize the project. Having already increased from nine to 11, Sky Mavis intends to get that number up to 21 within three months. Longer-term, the project is eyeing more than 100 nodes.
Sky Mavis will also be launching bug bounties of up to $1 million for any white hat hackers who are able to find further vulnerabilities.
“We recognize the importance and value of security researchers’ efforts in helping keep our community safe. Sky Mavis is offering bounties of up to $1 million to encourage responsible disclosure of security vulnerabilities.”

你可能也喜欢

日本加息,为什么全世界都在紧张?

日本央行在2026年6月将政策利率提升至1%,这是自1995年来的首次。尽管1%的利率在主要经济体中并不高,但由于日本长期充当全球最低成本融资中心的特殊角色,此次加息引发了全球市场的广泛关注。 过去二十余年,日本近乎零的利率环境催生了大规模的日元套利交易。国际资本以极低成本借入日元,转而投资于全球高收益资产,如美国科技股和新兴市场债券,这为全球资产价格上涨提供了重要的流动性基础。日本加息意味着这一廉价资金源头开始收紧,可能引发全球资本的去杠杆化调整。 日本长期维持超低利率,源于其人口老龄化、长期通缩和高额政府债务等结构性约束。然而,疫情后全球通胀传导、国内工资持续增长(近年春斗涨薪均超5%)以及日元贬值压力,共同推动其货币政策转向。 市场担忧的核心并非当前1%的利率水平,而是日本持续三十年的超宽松货币政策框架发生根本性转变的趋势。这种变化将重塑全球套利交易的逻辑和风险资产的定价基础。不过,决定全球资本最终流向的关键,仍在于美日之间的利差变化。如果未来美联储进入降息周期而日本继续加息,两者货币政策差异的收窄可能对国际资本市场产生更深远的影响。 简言之,日本加息标志着全球最重要的低成本融资来源进入正常化进程,这可能引发建立在廉价日元资金之上的全球资本配置体系进行深度重估。

marsbit1小时前

日本加息,为什么全世界都在紧张?

marsbit1小时前

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

摩根士丹利分析师Joseph Moore于5月28日更新了对迈威尔(MRVL)的研报。尽管公司季报创纪录并大幅上调全年展望,但Moore维持“等权重”(中性)评级,目标价从172美元上调至195美元,仍低于当时股价。 **核心观点**:分析师认可迈威尔的AI增长机会,但认为当前股价已充分反映预期。195美元目标价对应约40倍2027年预期市盈率。对比英伟达,两者股价接近,但英伟达的每股盈利预期是迈威尔的两倍多。Moore认为,迈威尔需同时兑现以下假设才能支撑当前估值:1)光互联业务持续放量;2)定制AI芯片顺利大规模出货;3)存储及企业业务复苏。 **业务分析**: - **光互联**(高速增长):受益于AI集群数据传输需求,预计未来几个季度光模块产品线年化营收将达10亿美元,是当前最确定的增长点。 - **定制AI芯片**(正在爬坡):为云厂商设计专用芯片,新大客户预计2028财年量产,但今年收入尚不明朗。 - **传统业务**:存储、企业数据中心等板块仍处于去库存阶段,短期缺乏复苏动力。 **关键监测信号**:光模块营收能否如期达到10亿美元年化水平;新客户定制芯片项目能否在2028财年量产;传统业务何时复苏。若任何一环不及预期,当前高估值可能面临压力。 (本文为对第三方研报的解读,不构成投资建议。)

marsbit2小时前

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

marsbit2小时前

交易

现货
合约
活动图片