• Home
  • News
  • Bitcoin
  • Blockchain
  • Altcoins
  • Ethereum
  • Regulations
  • Technology
What's Hot

BlackRock announces the launch of a new Bitcoin trust private spot

August 11, 2022

Coordination between utilities and crypto miners – when does it make sense?

August 11, 2022

Inside Out: Is a Recent Crypto Asset Insider Trading Case a Prelude to More SEC Enforcement Actions? | McDermott Will & Emery

August 11, 2022
Facebook Twitter Instagram
Facebook Twitter Instagram
The Crypto News
  • Home
  • News

    BlackRock announces the launch of a new Bitcoin trust private spot

    August 11, 2022

    Polygon maintains strong footing as 300% MATIC balloons since June

    August 11, 2022

    How to Earn Interest on Crypto Savings Accounts?

    August 11, 2022

    AVAX holds firm and aims for a breach of the $50 barrier

    August 11, 2022

    Ethereum whale transactions peak at 2-month high amid Goerli testnet meltdown

    August 11, 2022
  • Bitcoin

    Bitcoin Miner Genesis Digital Acquires Additional 708MW Capacity CryptoGlobe

    August 11, 2022

    Bitpay Reveals Prepaid Cardholders Can Get Up To 15% Cash Back Through Select Retailers – Bitcoin News

    August 11, 2022

    Is the Bitcoin surge due to an external reason? What the data suggests

    August 11, 2022

    US inflation slowed to 8.5% in July. Bitcoin Jumps – Bitcoin Magazine

    August 11, 2022

    Belarus Issues International Arrest Warrant For Owner Of Country’s ‘Largest Crypto Exchange’

    August 11, 2022
  • Blockchain

    Green Shiba Inu had a major fall – Is it a scam?

    August 11, 2022

    Celsius Price Prediction CEL Price Pumps 100% in 7 Days

    August 11, 2022

    ADA resumes consolidation above the $0.54 level

    August 11, 2022

    Triple bottom chart pattern at $2.84 triggers uptrend

    August 11, 2022

    BTC attempts a positive break above $24,500

    August 11, 2022
  • Altcoins

    Altcoins can take a 30% drop if they don’t meet these requirements: Rekt Capital

    August 11, 2022

    Bitcoin Braces for Parabolic Crossing to $100,000 as Altcoin Season Peaks, Says Crypto Analyst

    August 11, 2022

    What Are the Implications of Bitcoin’s Battle Against Two-Month Resistance

    August 11, 2022

    Meme Coins vs. Prime Tokens in Crypto Bear Markets

    August 11, 2022

    Bitcoin and Altcoins Rise as US Inflation Falls

    August 11, 2022
  • Ethereum

    Ethereum merger scheduled for September 15/16, ETH price soars

    August 11, 2022

    Merger Causes Divergence Between Ethereum and Bitcoin SOPR

    August 11, 2022

    ETH Gas Fees Drop as Merge Test Ends

    August 11, 2022

    Ethereum climbs 12% after Goerli testnet merger completes

    August 11, 2022

    Goerli is successful. Does the Vitalik against Saylor "Battle" Continue?

    August 11, 2022
  • Regulations

    Inside Out: Is a Recent Crypto Asset Insider Trading Case a Prelude to More SEC Enforcement Actions? | McDermott Will & Emery

    August 11, 2022

    Australia’s top regulator says crypto became ‘increasingly mainstream’ thus requiring stricter regulation

    August 11, 2022

    Over 7% of Indians owned cryptocurrencies in 2021, UN report reveals

    August 11, 2022

    Why hackers are able to steal billions of dollars worth of cryptocurrency

    August 11, 2022

    South Korea double downs on crypto regulation, arrests 3 people over illegal trading biz

    August 11, 2022
  • Technology

    Coordination between utilities and crypto miners – when does it make sense?

    August 11, 2022

    Former 2020 US Presidential Candidate Unveils Super PAC to Popularize Web3

    August 11, 2022

    Belfrics Technologies Limited launches operations in Dubai International Financial Center

    August 11, 2022

    Venture Capitalists Get The Crypto Option

    August 11, 2022

    New financial technology: a millionaire’s flight

    August 11, 2022
The Crypto News
Home»Technology»Crypto Firms Make an Offer to Thieving Hackers: Keep Some, Return the Rest
Technology

Crypto Firms Make an Offer to Thieving Hackers: Keep Some, Return the Rest

July 25, 2022No Comments6 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Some cryptocurrency platforms that have seen millions of dollars disappear in digital heists have made an unusual pitch to their attackers: keep some, but give the rest back.

Pleas amount to ultimate pleas to convince the hackers to return most of the stolen funds. Victims have offered up to $10 million in these efforts and compared it to bug bounties paid to security researchers for discovering software flaws.

Similar to ransom payments, the deals can make business sense, allowing a business to return to normal after a cyberattack, security experts say. But calling them “bounties” has infuriated vulnerability specialists. For them, this practice legitimizes thieves by confusing them with hackers, who report software flaws for a fee. Ethical hackers deal directly with companies, including multinational corporations, such as

Microsoft Corp.

or go through third-party platforms.

“It dilutes all the work that people have put in to do the right thing,” said Casey Ellis, founder and CTO of bug-bounty platform Bugcrowd Inc. “I have to get away from the keyboard of once in a while when it comes upstairs.”

Casey Ellis, Founder and CTO of Bugcrowd.


Photo:

Sean Proctor/Bloomberg News

Hackers have plundered digital currency projects over the past year, with North Korea-linked groups stealing over $1 billionlargely from decentralized financial platforms, according to crypto research firm Chainalysis Inc. The multi-million dollar heists have continued even as cryptocurrencies have entered a vortex.

This month, DeFi trading platform Crema Finance exposed the theft of around $8.8 million worth of crypto, and its developers quickly teamed up with third-party sleuths to trace the stolen funds through blockchains or cryptocurrencies. digital public registers.

A few days later, Crema tweeted that she had made contact with her attacker.

After “a long negotiation,” Crema said, the hacker agreed to keep the equivalent of nearly $1.7 million as “the white hat bounty.”


Newsletter Sign-Up

WSJ Pro

cyber security

Cybersecurity news, analysis and insights from the WSJ’s global team of reporters and editors.


Social media followers applauded Crema for making the best of a bad situation. Crema’s own reaction was muted. “From our perspective, we don’t believe the end result is perfect,” the company said in a statement.

The company didn’t respond to a request for comment on how it vetted the forward before closing the deal, and it declined to make the developers available for an interview.

“We are concerned that discussing the trading process in too much detail will actually provide more help to hackers than to the DeFi community,” Crema said.

Other such offers by other DeFi platforms seem to have failed. In January, lending platform Qubit Finance published a

Twitter

message offering $2 million as a “well-deserved bounty” in exchange for hackers returning the balance of an $80 million theft.

People with access to an Ethereum address associated with the Qubit exploit have moved millions of stolen funds into blockchain-based mixing software known as Tornado Cash, which is often used for money laundering. Stolen Ether valued at nearly $35 million stay at this address.

The Tornado Cash website on a laptop and smartphone.


Photo:

News by Luke MacGregor/Bloomberg

The hackers behind an April theft of around $80 million from Rari Capital, a DeFi lending platform, temporarily stopped sending stolen funds into Tornado Cash after the platform’s developers -form tweeted that they would lose $10 million, “no questions asked,” in exchange for the rest of the money.

“I was hopeful that he was considering whether or not to send the money back and get the bounty,” Rari co-founder Jack Lipstone said. But the striker eventually started funneling the money back to Tornado Cash in an apparent attempt to obscure its source.

“It’s like the worst feeling ever,” Mr Lipstone added.

Last month, as the DeFi Harmony crypto project responded to $100 million heisthe tweeted that he would offer a $1 million “bounty” to the hackers in exchange for the rest of the funds.

“Harmony will plead for no criminal charges when the funds are returned,” he said. The company then increased its offer to $10 million.

Blockchain analysis experts suspect Hackers linked to North Korea stole the funds, and also funneled crypto into Tornado Cash. Harmony declined to comment.

“The criminal is capable of stealing money and is happy to accept a much smaller amount of clean money so he can get away with it unscathed.”


—Alex Rice, HackerOne

Alex Rice, co-founder and chief technology officer of bug bounty platform HackerOne, said cyber incidents on these largely unregulated new systems can range from accidental exploits to criminal heists. If in the latter category, post-mining payments are like “a form of money laundering, almost,” he said.

“The criminal is capable of stealing money and is happy to accept a much smaller amount of clean money so he can get away with it,” Rice said.

US officials, who have stepped up efforts to track down stolen crypto and sanction hacking groups, are discouraging companies from paying hackers after ransomware attacks. The Treasury Department did not respond to requests for comment, and the Justice Department declined to comment on the most nascent form of post-exploit payments.

Amid the wave of high profile hacks, some crypto platforms have started offering traditional bug bounties as a preemptive way. In June, an infrastructure platform known as

Dawn

paid $6 million to a white hat hacker for spotting a vulnerability.

Rice said HackerOne has crypto-based businesses as customers, but it wouldn’t work with DeFi platforms with non-traditional operating structures. Many are not registered as real businesses and are governed by people who hold tokens and can vote on how the projects are run.

“It’s unclear who you’re actually contracting with, who’s legally responsible if some type of crime is committed or if a bill has to be paid,” said Rice, whose firm’s clients include

Starbucks Corp.

and

General Motors Co.

But most DeFi crypto platforms haven’t attempted to launch bug bounty programs, he said.

“It’s not widespread,” Mr. Rice added. “We operate in the modern business world, which means we need appropriate business entities to engage in business relationships with.”

Write to David Uberti at david.uberti@wsj.com

Copyright ©2022 Dow Jones & Company, Inc. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Coordination between utilities and crypto miners – when does it make sense?

August 11, 2022

Former 2020 US Presidential Candidate Unveils Super PAC to Popularize Web3

August 11, 2022

Belfrics Technologies Limited launches operations in Dubai International Financial Center

August 11, 2022

Venture Capitalists Get The Crypto Option

August 11, 2022
Add A Comment

Leave A Reply Cancel Reply

Latest

BlackRock announces the launch of a new Bitcoin trust private spot

August 11, 2022

Polygon maintains strong footing as 300% MATIC balloons since June

August 11, 2022

How to Earn Interest on Crypto Savings Accounts?

August 11, 2022
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

News
  • Altcoins (334)
  • Bitcoin (475)
  • Blockchain (543)
  • Ethereum (141)
  • News (526)
  • Regulations (569)
  • Technology (536)
News
  • Altcoins (334)
  • Bitcoin (475)
  • Blockchain (543)
  • Ethereum (141)
  • News (526)
  • Regulations (569)
  • Technology (536)
Get Informed

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Top Insights

Bitcoin Miner Genesis Digital Acquires Additional 708MW Capacity CryptoGlobe

August 11, 2022

Bitpay Reveals Prepaid Cardholders Can Get Up To 15% Cash Back Through Select Retailers – Bitcoin News

August 11, 2022

Is the Bitcoin surge due to an external reason? What the data suggests

August 11, 2022
Facebook Twitter Instagram Pinterest
  • About us
  • Privacy policy
  • Terms and services
  • Contact us
© 2022 Designed by thecryptonews.co.uk.

Type above and press Enter to search. Press Esc to cancel.