
Sign up to save your podcasts
Or


In this episode we are joined by Mudit Gupta of SushiSwap to help break down the latest CREAM Finance hack. We explore how multiple Discord servers related to NFTs have been compromised recently. Police seized 48 BTC from a UK-based 16-year-old. We talk about how attackers are leveraging a custom administrative panel for phishing Coinbase credentials, including MFA. 3.1 million email addresses were leaked for users of CoinMarketCap. Facebook pushes for a metaverse and rebrands to "Meta".
Show Notes at: https://coinsecpodcast.com/Episode-46-562f5685ce6e490bafe66e8dbbbf1d4a
In this episode we talked about the largest crypto-related bug bounty payout ever. Compound accidentally sent millions in rewards due to a bug. StakeSteak left private keys on a Github repo resulting in compromise. A vulnerability was discovered in Rocketpool & Lido that would allow an ETH 2.0 node operator to perform front-running attacks against stakers. Indexed Finance, Pancake Hunny, and CreatureToadz all had security issues this week. We also discussed the potential for malicious NFTs and how they could be used to attack users on OpenSea.
Show Notes at: https://coinsecpodcast.com/Episode-45-6a8c7733f17b4cec8358ddeb92887a4f
00:00 - CoinSec Podcast Ep 45 – https://coinsecpodcast.com/Episode-45-6a8c7733f17b4cec8358ddeb92887a4f 01:23 - Story # 1: https://cointelegraph.com/news/crypto-market-cap-hits-new-all-time-high-as-btc-eth-soar 04:34 - Story # 2: https://decrypt.co/83997/polygon-dodges-850m-hack-pays-record-2m-bounty 11:38 - Story # 3: https://decrypt.co/82499/compound-exploit-drains-21m-from-lending-protocol 15:16 - Story # 4: https://stakesteak.medium.com/10-4-post-mortem-82edf38b0064 20:09 - Story # 5: https://medium.com/immunefi/rocketpool-lido-frontrunning-bug-fix-postmortem-e701f26d7971 24:30 - Story # 6: https://rekt.news/indexed-finance-rekt/ 41:57 - Story # 7: https://ownsnap.com/pancake-hunny-hunny-crashes-50-as-it-faces-token-leaks-in-pools/ 51:33 - Story # 8: https://thedrop.beehiiv.com/p/creature-toadz-hacked 55:58 - Story # 9: https://research.checkpoint.com/2021/check-point-research-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/
In episode 44 we talked about Bitcoin.org being compromised to redirect people to a scam. A Compound bug caused excess rewards to be sent out. pNetwork and VeeFinance were both hacked for millions of dollars. A malicious browser extension called Safepal was discussed. The largest bug bounty ever was paid equaling $1,050,000. We discussed an issue in SMS-based MFA resulting in theft from Coinbase users. Lastly, we talked about the many crypto-related puzzles currently available to participate in.
Show Notes at: https://coinsecpodcast.com/Episode-44-216ff3b62e21423c8be6e7134cca983b
00:00 - CoinSec Podcast 44 03:33 - Story # 1: https://decrypt.co/81612/bitcoin-org-compromised-fraudulent-crypto-giveaway-advertised 07:38 - Story # 2: https://twitter.com/dafthack/status/1439348515986104323?s=21 11:47 - Story # 3: https://www.rekt.news/overcompensated/ 19:22 - Story # 4: https://decrypt.co/81301/defi-bridging-protocol-pnetwork-suffers-12-million-hack 24:40 - Story # 5: https://rekt.news/veefinance-rekt/ 27:05 - Story # 6: https://www.bleepingcomputer.com/news/security/malicious-safepal-wallet-firefox-add-on-stole-cryptocurrency/ 32:15 - Story # 7: https://medium.com/immunefi/belt-finance-logic-error-bug-fix-postmortem-39308a158291 38:02 - Story # 8: https://twitter.com/electroneum/status/1440269750215479301?s=19 41:56 - Story # 9: https://www.bleepingcomputer.com/news/security/hackers-rob-thousands-of-coinbase-customers-using-mfa-flaw/ 49:09 - Crypto Puzzles!
In this episode we discuss one of the first major exploits on the Avalanche blockchain in Zabu Protocol. Some fake news surrounding Litecoin being accepted as payment at Wal-Mart was spread by major news outlets. An attack on Ethereum managed to trick some nodes into following a fake chain. Solana had a major denial-of-service issue. NowSwap was hacked resulting in the loss of over $1 million. Gelato had a front-running issue during its token sale. SushiSwap's token platform MISO was attacked via a supply chain attack.
Show Notes: https://coinsecpodcast.com/Episode-43-4bbec4a6843e4a279d3e42d9d45354e1
00:00 - CoinSec Podcast 43 03:41 - Story # 1: https://www.coindesk.com/tech/2021/09/13/avalanche-based-zabu-finance-exploited-in-32m-hack/ 08:03 - Story # 2: https://hypebeast.com/2021/9/litecoin-walmart-partnership-rumors-surge-and-crash 12:20 - Story # 3: https://www.theblockcrypto.com/linked/117637/unsuccessful-attack-on-ethereum-managed-to-trick-a-few-nodes 15:24 - Story # 4: https://finance.yahoo.com/news/solana-mainnet-finally-back-online-121733288.html 23:28 - Story # 5: https://coingape.com/defi-hack-alert-nowswap-losses-over-1-million-in-cyber-attack/ 25:46 - Story # 6: https://stockhead.com.au/cryptocurrency/gelato-network-customers-out-in-the-cold-as-front-runners-snatch-about-us8m-in-tokens-for-us1-5m/ 32:54 - Story # 7: https://decrypt.co/81120/sushiswaps-token-launchpad-hacked-over-3m-ethereum 38:49 - Story # 8: https://github.com/LavaMoat/LavaMoat 44:27 - Story # 9: https://start.blockchainhax.com/
In this episode of the CoinSec Podcast Steve Borosh (@424f424f) show how to track transactions using BitQuery. We talk about Miner Exctractable Value (MEV) and some potential protection mechanisms. DAOMaker was hacked for a 2nd time. Mastercard acquired CipherTrace. A contract analysis tool called TokenSniffer was discussed as well.
C.R.E.A.M. v1 market on Ethereum suffered an exploit draining $18.8 million. Bilaxy Exchange was hacked for $21 million. X-Token's xSNX smart contract was exploited with an estimate $4.5 million lost. Banksy was warned about a vulnerability in website prior to exploitation resulting in NFT scam. Steve shows off his PancakeSwap market prediction bot. Beau shows a new Blockchain Hacking QuickStart Guide he created at https://start.blockchainhax.com.
00:00 - CoinSec Podcast Ep 41 : https://coinsecpodcast.com/Episode-41-2f0413737fef4ba5833e9f246162bf70 04:07 - Story # 1: https://twitter.com/electroneum/status/1431620290967216131 09:53 - Story # 2: https://cointelegraph.com/news/cream-finance-defi-platform-loses-19m-in-a-flash-loan-hack 17:07 - Story # 3: https://cointelegraph.com/news/bilaxy-exchange-suspends-website-after-erc-20-hot-wallet-hack 19:44 - Story # 4: https://www.rekt.news/xtoken-rekt-x2/ 25:21 - Story # 5: https://www.bbc.com/news/technology-58437753 32:01 - LINK: Carnac https://github.com/rvrsh3ll/Carnac 41:32 - BlockchainHAX QuickStart Guide: https://start.blockchainhax.com/ 44:32 - Getting Started in Blockchain Security & Smart Contract Auditing: https://register.gotowebinar.com/register/3816384386435465995 Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/Geth version 1.10.7 and older has a vulnerability currently being exploited that split Ethereum's chain. Poly Network has announced that they have regained control of all stolen funds. Potential rug pull in Luna Yield protocol. Maze Protocol hack investigation update. Antinalysis Bitcoin tracing tool. Big tech companies to spend billions on cybersecurity. A vulnerability was patched in an OpenZeppelin library.
Show Notes: https://coinsecpodcast.com/Episode-40-214c586a59434780bbc2d325649bf86f
00:00 - CoinSec Podcast Episode 40 01:05 - LINK: https://coinsecpodcast.com/Episode-40-214c586a59434780bbc2d325649bf86f 01:26 - Story # 1: https://www.bleepingcomputer.com/news/security/ethereum-urges-go-devs-to-fix-severe-chain-split-vulnerability/ 09:54 - Story # 2: https://medium.com/poly-network/poly-network-asset-recovery-complete-a7ba33c2f2e4 12:31 - Story # 3: https://www.coindesk.com/markets/2021/08/20/solanas-luna-yield-goes-dark-with-some-fearing-a-rug-pull-involving-67m/ 17:56 - Story # 4: https://blog.mazeprotocol.com/an-aftermath-update-a1ee7b24468c 20:49 - Story # 5: https://decrypt.co/79331/dark-web-tool-dirty-bitcoin-returns-after-shutdown?utm_source=twitter&utm_medium=social&utm_campaign=auto 25:28 - Story # 6: https://www.cnbc.com/2021/08/25/google-microsoft-plan-to-spend-billions-on-cybersecurity-after-meeting-with-biden.html 35:47 - Story # 7: https://twitter.com/OpenZeppelin/status/1430999829748932614 42:58 - Story # 8: https://decrypt.co/79459/brazilian-police-carry-out-record-cryptocurrency-seizure?utm_source=twitter&utm_medium=social&utm_campaign=auto 47:24 - Story # 9: https://twitter.com/kelvinfichter/status/1430951568505978888Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/
CoinSec is back after a lengthy hiatus. Much has happened in the crypto space since the last episode. In this episode we discuss the largest DeFi hack ever along with two other hacks that resulted in large financial loss. Also, we discuss the looming infrastructure bill and potential concerns around crypto.
00:00 - CoinSec Episode 38 02:49 - Story # 1: https://decrypt.co/78163/polynetwork-suffers-record-breaking-600-3m-hack 03:13 - LINK: coinsecpodcast.com 25:36 - Story # 2: https://decrypt.co/77620/defi-protocol-popsicle-finance-hacked-25-million 28:02 - Story # 3: https://cointelegraph.com/news/dao-maker-crowdfunding-platform-loses-7m-in-latest-defi-exploit?utm_content=buffer1b294&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer 34:08 - Story # 4: https://www.cnbc.com/2021/08/09/senate-rejects-compromise-crypto-tax-amendment-to-infrastructure-bill.html 39:17 - Bug Bounty Programs: https://docs.pancakeswap.finance/code/bug-bounty
Show Notes: https://coinsecpodcast.com/Episode-38
Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/
On this episode Mike Felch (@ustayready) details some of the critical vulnerabilities that can be introduced into Ethereum smart contracts. The largest cryptocurrency hack ever happened to Coincheck. Coinhive made it's way into Google ads, and a new malware called WannaMine is using the NSA Eternal Blue exploit to compromise more hosts to mine on. Also, NIST put out guidance on Blockchain & cryptocurrency.
From the publisher's feed