The CoinSec Podcast

The CoinSec Podcast

By The CoinSec PodcastTechnology
Download on the App Store

The CoinSec Podcast episodes

  • Episode 46: Mudit Gupta Interview, Cream Finance Hacked Again, NFT Discord Hacks, 45 BTC Seized

    In this episode we are joined by Mudit Gupta of SushiSwap to help break down the latest CREAM Finance hack. We explore how multiple Discord servers related to NFTs have been compromised recently. Police seized 48 BTC from a UK-based 16-year-old. We talk about how attackers are leveraging a custom administrative panel for phishing Coinbase credentials, including MFA. 3.1 million email addresses were leaked for users of CoinMarketCap. Facebook pushes for a metaverse and rebrands to "Meta".

    Show Notes at: https://coinsecpodcast.com/Episode-46-562f5685ce6e490bafe66e8dbbbf1d4a

    59 min
  • Episode 45: OpenSea Malicious NFTs, ETH 2.0 Front-Running attacks, Indexed Finance hacked & more

    In this episode we talked about the largest crypto-related bug bounty payout ever. Compound accidentally sent millions in rewards due to a bug. StakeSteak left private keys on a Github repo resulting in compromise. A vulnerability was discovered in Rocketpool & Lido that would allow an ETH 2.0 node operator to perform front-running attacks against stakers. Indexed Finance, Pancake Hunny, and CreatureToadz all had security issues this week. We also discussed the potential for malicious NFTs and how they could be used to attack users on OpenSea.

    Show Notes at: https://coinsecpodcast.com/Episode-45-6a8c7733f17b4cec8358ddeb92887a4f

    00:00 - CoinSec Podcast Ep 45 – https://coinsecpodcast.com/Episode-45-6a8c7733f17b4cec8358ddeb92887a4f 01:23 - Story # 1: https://cointelegraph.com/news/crypto-market-cap-hits-new-all-time-high-as-btc-eth-soar 04:34 - Story # 2: https://decrypt.co/83997/polygon-dodges-850m-hack-pays-record-2m-bounty 11:38 - Story # 3: https://decrypt.co/82499/compound-exploit-drains-21m-from-lending-protocol 15:16 - Story # 4: https://stakesteak.medium.com/10-4-post-mortem-82edf38b0064 20:09 - Story # 5: https://medium.com/immunefi/rocketpool-lido-frontrunning-bug-fix-postmortem-e701f26d7971 24:30 - Story # 6: https://rekt.news/indexed-finance-rekt/ 41:57 - Story # 7: https://ownsnap.com/pancake-hunny-hunny-crashes-50-as-it-faces-token-leaks-in-pools/ 51:33 - Story # 8: https://thedrop.beehiiv.com/p/creature-toadz-hacked 55:58 - Story # 9: https://research.checkpoint.com/2021/check-point-research-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/

    1 hr 4 min
  • Episode 44: Bitcoin.org, pNetwork, and VeeFinance Hacks, Malicious Wallet, Compound Bug, & Puzzles

    In episode 44 we talked about Bitcoin.org being compromised to redirect people to a scam. A Compound bug caused excess rewards to be sent out. pNetwork and VeeFinance were both hacked for millions of dollars. A malicious browser extension called Safepal was discussed. The largest bug bounty ever was paid equaling $1,050,000. We discussed an issue in SMS-based MFA resulting in theft from Coinbase users. Lastly, we talked about the many crypto-related puzzles currently available to participate in.

    Show Notes at: https://coinsecpodcast.com/Episode-44-216ff3b62e21423c8be6e7134cca983b

     

    00:00 - CoinSec Podcast 44 03:33 - Story # 1: https://decrypt.co/81612/bitcoin-org-compromised-fraudulent-crypto-giveaway-advertised 07:38 - Story # 2: https://twitter.com/dafthack/status/1439348515986104323?s=21 11:47 - Story # 3: https://www.rekt.news/overcompensated/ 19:22 - Story # 4: https://decrypt.co/81301/defi-bridging-protocol-pnetwork-suffers-12-million-hack 24:40 - Story # 5: https://rekt.news/veefinance-rekt/ 27:05 - Story # 6: https://www.bleepingcomputer.com/news/security/malicious-safepal-wallet-firefox-add-on-stole-cryptocurrency/ 32:15 - Story # 7: https://medium.com/immunefi/belt-finance-logic-error-bug-fix-postmortem-39308a158291 38:02 - Story # 8: https://twitter.com/electroneum/status/1440269750215479301?s=19 41:56 - Story # 9: https://www.bleepingcomputer.com/news/security/hackers-rob-thousands-of-coinbase-customers-using-mfa-flaw/ 49:09 - Crypto Puzzles!

    1 hr 1 min
  • Episode 43: MISO Supply Chain Hack, Gelato Front-Run, NowSwap & Zabu Hacks, Solana DoS & ETH Attack

    In this episode we discuss one of the first major exploits on the Avalanche blockchain in Zabu Protocol. Some fake news surrounding Litecoin being accepted as payment at Wal-Mart was spread by major news outlets. An attack on Ethereum managed to trick some nodes into following a fake chain. Solana had a major denial-of-service issue. NowSwap was hacked resulting in the loss of over $1 million. Gelato had a front-running issue during its token sale. SushiSwap's token platform MISO was attacked via a supply chain attack.

    Show Notes: https://coinsecpodcast.com/Episode-43-4bbec4a6843e4a279d3e42d9d45354e1

    00:00 - CoinSec Podcast 43 03:41 - Story # 1: https://www.coindesk.com/tech/2021/09/13/avalanche-based-zabu-finance-exploited-in-32m-hack/ 08:03 - Story # 2: https://hypebeast.com/2021/9/litecoin-walmart-partnership-rumors-surge-and-crash 12:20 - Story # 3: https://www.theblockcrypto.com/linked/117637/unsuccessful-attack-on-ethereum-managed-to-trick-a-few-nodes 15:24 - Story # 4: https://finance.yahoo.com/news/solana-mainnet-finally-back-online-121733288.html 23:28 - Story # 5: https://coingape.com/defi-hack-alert-nowswap-losses-over-1-million-in-cyber-attack/ 25:46 - Story # 6: https://stockhead.com.au/cryptocurrency/gelato-network-customers-out-in-the-cold-as-front-runners-snatch-about-us8m-in-tokens-for-us1-5m/ 32:54 - Story # 7: https://decrypt.co/81120/sushiswaps-token-launchpad-hacked-over-3m-ethereum 38:49 - Story # 8: https://github.com/LavaMoat/LavaMoat 44:27 - Story # 9: https://start.blockchainhax.com/

    57 min
  • Episode 41: CREAM, Bilaxy, & X-Token Hacks, PancakeSwap Prediction Bot, & A Blockchain Hacking Guide

    C.R.E.A.M. v1 market on Ethereum suffered an exploit draining $18.8 million. Bilaxy Exchange was hacked for $21 million. X-Token's xSNX smart contract was exploited with an estimate $4.5 million lost. Banksy was warned about a vulnerability in website prior to exploitation resulting in NFT scam. Steve shows off his PancakeSwap market prediction bot. Beau shows a new Blockchain Hacking QuickStart Guide he created at https://start.blockchainhax.com. 

    00:00 - CoinSec Podcast Ep 41 : https://coinsecpodcast.com/Episode-41-2f0413737fef4ba5833e9f246162bf70 04:07 - Story # 1: https://twitter.com/electroneum/status/1431620290967216131 09:53 - Story # 2: https://cointelegraph.com/news/cream-finance-defi-platform-loses-19m-in-a-flash-loan-hack 17:07 - Story # 3: https://cointelegraph.com/news/bilaxy-exchange-suspends-website-after-erc-20-hot-wallet-hack 19:44 - Story # 4: https://www.rekt.news/xtoken-rekt-x2/ 25:21 - Story # 5: https://www.bbc.com/news/technology-58437753 32:01 - LINK: Carnac https://github.com/rvrsh3ll/Carnac 41:32 - BlockchainHAX QuickStart Guide: https://start.blockchainhax.com/ 44:32 - Getting Started in Blockchain Security & Smart Contract Auditing: https://register.gotowebinar.com/register/3816384386435465995   Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/
    47 min
  • Episode 40: Geth Vuln Causes Eth Fork, Poly Hack Update, Antinalysis, OpenZeppelin Vuln & Rug Pulls

    Geth version 1.10.7 and older has a vulnerability currently being exploited that split Ethereum's chain. Poly Network has announced that they have regained control of all stolen funds. Potential rug pull in Luna Yield protocol. Maze Protocol hack investigation update. Antinalysis Bitcoin tracing tool. Big tech companies to spend billions on cybersecurity. A vulnerability was patched in an OpenZeppelin library.

    Show Notes: https://coinsecpodcast.com/Episode-40-214c586a59434780bbc2d325649bf86f

    00:00 - CoinSec Podcast Episode 40 01:05 - LINK: https://coinsecpodcast.com/Episode-40-214c586a59434780bbc2d325649bf86f 01:26 - Story # 1: https://www.bleepingcomputer.com/news/security/ethereum-urges-go-devs-to-fix-severe-chain-split-vulnerability/ 09:54 - Story # 2: https://medium.com/poly-network/poly-network-asset-recovery-complete-a7ba33c2f2e4 12:31 - Story # 3: https://www.coindesk.com/markets/2021/08/20/solanas-luna-yield-goes-dark-with-some-fearing-a-rug-pull-involving-67m/ 17:56 - Story # 4: https://blog.mazeprotocol.com/an-aftermath-update-a1ee7b24468c 20:49 - Story # 5: https://decrypt.co/79331/dark-web-tool-dirty-bitcoin-returns-after-shutdown?utm_source=twitter&utm_medium=social&utm_campaign=auto 25:28 - Story # 6: https://www.cnbc.com/2021/08/25/google-microsoft-plan-to-spend-billions-on-cybersecurity-after-meeting-with-biden.html 35:47 - Story # 7: https://twitter.com/OpenZeppelin/status/1430999829748932614 42:58 - Story # 8: https://decrypt.co/79459/brazilian-police-carry-out-record-cryptocurrency-seizure?utm_source=twitter&utm_medium=social&utm_campaign=auto 47:24 - Story # 9: https://twitter.com/kelvinfichter/status/1430951568505978888

    Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/

    52 min
  • Episode 39: SushiSwap Fix Vuln, Liquid Global Hack, Ransomware Bribes & a Flash Loan Exploit Demo
    In episode 39 we discuss how SushiSwap was able to fix an issue in their MISO auction potentially saving $350 million in funds. Japanese exchange Liquid Global was hacked for close to $90 million. Some cybercrime groups are offering $1 million in Bitcoin to target employees to deploy ransomware on their networks. Finally, we demonstrate an example smart contract exploit against a flash loan lending pool. Show Notes:  https://coinsecpodcast.com/Episode-39-1fcad93d5e60429b9f6a2cd68ea78327   00:00 - CoinSec Podcast Ep 39 01:51 - LINK CoinSecPodcast.com 02:13 - Story # 1: https://decrypt.co/78802/ethereum-dex-avoids-350m-defi-hack-thanks-white-hat-heroics 08:01 - Story # 2: https://cointelegraph.com/news/breaking-liquid-exchange-hacked-to-the-tune-of-80-million 15:16 - Story # 3: https://thehackernews.com/2021/08/cybercrime-group-asking-insiders-for.html 20:46 - Story # 4: https://docs.google.com/document/d/1-WoQwT1QrPEX-r4N-fDamRQ50LM8DsdsOyq1iTabS3Q/edit 28:51 - Story # 5: https://decrypt.co/78715/crypto-exchanges-see-10x-increase-phishing-attacks-says-new-report?utm_source=twitter&utm_medium=social&utm_campaign=auto 33:34 - Story # 6: https://blog.mazeprotocol.com/neko-hacking-incident-report-e46cdf179fd9 36:41 - Mobile Apps coming to Windows 11 : https://www.cnet.com/tech/computing/android-apps-on-windows-11-yup-how-it-works-which-apps-you-get-when-to-download/ 41:09 - https://cryptozombies.io/ 43:26 - Exploit Demo   Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/
    58 min
  • Episode 38: Poly Network Hack, Popsicle Finance Hack, DAO Maker Hack, and the Infrastructure Bill

    CoinSec is back after a lengthy hiatus. Much has happened in the crypto space since the last episode. In this episode we discuss the largest DeFi hack ever along with two other hacks that resulted in large financial loss. Also, we discuss the looming infrastructure bill and potential concerns around crypto.

    00:00 - CoinSec Episode 38 02:49 - Story # 1: https://decrypt.co/78163/polynetwork-suffers-record-breaking-600-3m-hack 03:13 - LINK: coinsecpodcast.com 25:36 - Story # 2: https://decrypt.co/77620/defi-protocol-popsicle-finance-hacked-25-million 28:02 - Story # 3: https://cointelegraph.com/news/dao-maker-crowdfunding-platform-loses-7m-in-latest-defi-exploit?utm_content=buffer1b294&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer 34:08 - Story # 4: https://www.cnbc.com/2021/08/09/senate-rejects-compromise-crypto-tax-amendment-to-infrastructure-bill.html 39:17 - Bug Bounty Programs: https://docs.pancakeswap.finance/code/bug-bounty

    Show Notes: https://coinsecpodcast.com/Episode-38 

    Honk Kong by Taseh is licensed under a Attribution-NonCommercial-ShareAlike License. Based on a work at https://taseh.bandcamp.com/

    42 min
  • Episode 4: Smart Contract Security Issues, Coincheck Hack, NIST Guidance on Blockchain, Coinhive in Google Ads, and WannaMine

    On this episode Mike Felch (@ustayready) details some of the critical vulnerabilities that can be introduced into Ethereum smart contracts. The largest cryptocurrency hack ever happened to Coincheck. Coinhive made it's way into Google ads, and a new malware called WannaMine is using the NSA Eternal Blue exploit to compromise more hosts to mine on. Also, NIST put out guidance on Blockchain & cryptocurrency.

    1 hr 4 min

About The CoinSec Podcast

From the publisher's feed

The CoinSec Podcast is a show about cryptocurrency and blockchain technologies with a focus on securing them. Each of the hosts are hackers that perform a broad spectrum of offensive security…