• AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    Aurora Mainnet experienced an attack yesterday. It was timely stopped. Vulnerability fixed for all virtual chains. The attacker stole $240. If you think $240 isn't much, just imagine 40 delicious Big Macs. 🧵

    AlexAuroraDev tweet picture

    26 11 126 12K 5
    Download Image
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At 20:05 UTC August 7, fewnode2790.near starts experimenting with calling different system methods in Aurora contract. nearblocks.io/txns/BKJF8e6gw…

    3 0 12 814 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    It looks like he roughly understands what he wants to achieve, but he struggles to line up required execution order and find correct payloads.

    1 0 8 784 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At 20:59 he still didn’t achieve anything, but now his intention is clear: he wants to set his prepared address (0x9b1218a9Aab6555E3F5A491d587bBc6CCA855026) as ERC-20 fallback address via calling `set_erc20_fallback_address` method. nearblocks.io/ru/txns/7NzNp1…

    1 0 9 786 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At 21:12 he finally succeeds. Even though there’s no harm done yet at this point, this already goes beyond what users should be allowed to do. nearblocks.io/ru/txns/CWZNyr…

    1 0 8 725 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At 21:18 attacker successfully executed `set_whitelist_status` to basically disallow all actions for non-whitelisted addresses. Because of this change, ERC-20 token transfers are not able to be processed; instead, funds are redirected to ERC-20 fallback address.

    1 0 9 704 1
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At this point attacker starts stealing user money during bridging actions.

    1 0 10 675 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    The whitelist functionality is a feature of Aurora engine that allows to launch virtual chains with permissioned access. You can learn more about this and other features of Aurora Cloud at auroracloud.dev

    1 0 11 681 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    Over the course of the next ~2 hours attacker gets his loot 12 times, resulting in ~$240. explorer.aurora.dev/address/0xFa84…

    1 0 9 640 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At the same time, Aurora Mainnet becomes nearly non-operational. Because of whitelist being enabled, most of the user transactions are failing with ERR_NOT_ALLOWED error.

    1 0 8 644 0
  • AlexAuroraDev Profile Picture

    Alex Shevchenko 🇺🇦 @AlexAuroraDev

    2 months ago

    At 21:32 - Infra SRE Team gets an alert from automatic end-to-end test suite, that effectively complains about Aurora Mainnet being non-operational.

    1 0 11 626 0
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 www.instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer