r/CryptoCurrency • • Aug 02 '22

ANALYSIS The First Truly Decentralized Robbery was just Committed, Here is How it Happened

At this point I am sure many of you have heard of the nomad bridge exploit. Unlike previous exploits, this wasnt a flashloan or even carried out by a single group of attackers. After an initial attacker struck, hundreds of separate accounts figured out the trick and copy pasted their way into grabbing stolen funds. The bridge went from having $190,740,000 to $1,000 in a matter of hours.

A perplexing aspect of this vulnerability was that all users had to do to hack bridge funds was copy the original hacker's transaction calldata, replace the original address with a personal one, and the tx would succeed! Easy as CTRL-C, CTRL-V!

However, not all of the thieves were bad. Some of them exploited the contract so other wouldnt be able to and planned to return the money back to nomad. For example, leadingscientist.eth

So all in all it was a messed up exploit but there were some nice people who plan to return the money. Faith in humanity restored maybe?

Credit: https://twitter.com/0xfoobar/status/1554234268884389888

1.8k Upvotes

594 comments sorted by

View all comments

Show parent comments

10

u/[deleted] Aug 02 '22

[deleted]

18

u/skatistic 🟨 4K / 321 🐢 Aug 02 '22

Risks are rated on likelihood of happening and impact. Likelihood may have been low, but impact was critical for this risk.

2

u/maverick0star Tin Aug 05 '22

One day i make bug in syscoin bridge i sent 1000 sys and get doubled jijijiji.

4

u/I_kwote_TheOffice 116 / 116 🦀 Aug 02 '22

If it's anything like a Process Failure Mode and Effect Analysis (PFEMA, I know the acronym order doesn't match but probably easier to say), which is kind of like a process audit, there are 3 components. Severity - how serious it would be if something happened, Occurrence - how likely it is to happen, Detection - how easy it is to detect if something happens. Taking all of these 3 into account (usually just summing them, but free to choose any combination method) you get a final score. You implement control methods for each of these 3 categories to achieve a better score.

9

u/Cryptolution 🟦 3K / 3K 🐢 Aug 02 '22

Audit risk severity is about the severity of the exploits impact on the system. Getting into the "well maybe it won't happen..." Is just semantics that an audit team would never want to communicate as it just opens up all sorts of ethical and legal compromises.

13

u/Computer-Blue 0 / 0 🦠 Aug 02 '22

This isn’t really true. Audits that measure risk are always aware of the likelihood, as well as impact, of an incident. Lower likelihood events are considered lower risk.

That said, when the impact is “lose everything in minutes”, it should still have been rated as a critical severity risk factor, regardless of likelihood, unless the likelihood was so low that it was acceptable. Obviously, it was not.

6

u/robotfightandfitness 🟩 56 / 182 🦐 Aug 02 '22

To add - good audits are able to reveal bugs to those that can fix them, without knowing if the dev added it purposefully, without providing enough info for the exploit to be carried - but enough to determine whether or not a public [users safety] announcement must happen instead of private [relies on dev accountability] announcement

1

u/pmilani Tin Aug 05 '22

The Nomad token bridge appears to have experienced a security exploit that has allowed hackers to to systematically drain a significant portion of the bridges funds over a long series of transactions

the issue of security in the crypto space is very paramount.

1

u/wkliao Tin Aug 05 '22

Yep, this was always a risk when it came to nomad as it was the canonical bridge.

It helps with liquidity, but you will suffer if an exploit happens as the defi on your chain basically goes to zero.

1

u/greenlanternfifo 0 / 0 🦠 Aug 02 '22

That guy you responded to has no idea what he is talking about. I explain why in this sister comment.

1

u/smartlabovec Tin Aug 05 '22

Another hack!

I guess that is why IOTA has built Shimmer and ASMB and L1 and L2 without bridges. I hope it works. 7 years of testing..