EtherDelta’s DNS Hacked, Website Replaced With Hacker’s Duplicate to Steal Funds

On Wednesday, December 20, the decentralized exchange EtherDelta fell victim to a malicious phishing attack on its DNS server. The hacker compromised EtherDelta’s website, rerouting transacted funds to a replica site that replaced the legitimate one for a number of hours.

Decentralized but Still Compromised

At 1:34 p.m. EST, EtherDelta tweeted a message suggesting that its DNS server had been hacked, followed up by a series of tweets suggesting that the original website had been replaced by a doppelganger created by the hacker.

The culprit created a near-replica of the exchange’s website, barring a few technical functions and cosmetic features. According to the tweets, the spoof site included a fake order book but neglected to include a chat box or Twitter feed.  

During the crafty phishing attack, users who interacted with the fraudulent site may have had their funds stolen. Users who deposited or withdrew funds using the imposter site at the time of the attack more than likely sent their funds directly to the hacker’s wallet address.   

The attack ran from approximately 1:30 p.m. to 8:00 p.m. EST, and EtherDelta suspended its service during the raid. After bagging a hefty 308 ETH (approximately US$244,000) and a considerable amount of ERC20 tokens, the hacker split the funds between various wallet addresses around 1:30 a.m. the following day.

It’s important to note that while EtherDelta’s website was breached, the smart contracts it utilizes were not. This means that if you didn’t upload or enter a private key on the fake site at the time of the attack, your funds could not be touched. EtherDelta users have the option of managing their funds with a Ledger Nano S, with the MEW browser wallet, or by manually inputting an account’s private keys.

The EtherDelta team made it clear in Thursday morning’s tweet that if you were using a Ledger Nano S or MEW wallet at the time of the phishing attack, your funds are safe. They also clarified that deposits on the exchange can only be accessed using an individual’s private key. So long as you never uploaded your key to the fake site, your funds were safe in the exchange’s smart contracts.

Could’ve Been Worse

2017 has been hard on exchanges. It seems like every time we turn around, a new exchange has been hit, more funds have been stolen, and the collateral damage leaves individual coffers bleeding.

The phishing attack on EtherDelta is unfortunate, but thanks to the exchange’s internal security features, it isn’t devastating. The site definitely bit the bullet, but unlike Youbit in the fallout of its own hacking, it didn’t bite the dust. EtherDelta’s decentralized nature and the smart contracts it employs are largely to thank for minimizing the damage.

With a trusted, centralized exchange like Youbit, a hacker need only compromise the exchange’s server to access its hot wallet. This hot wallet holds reserves of the funds the exchange manages for its users. Like a bank with fiat, you trust the exchange to hold your keys for you as credit, and when you wish to withdraw your assets, it debits your funds by relinquishing the keys. The danger of this system is that if a hacker compromises the exchange, he or she has access to any and all funds.

With EtherDelta, however, the exchange doesn’t hold any keys; the users do, managing them using Ethereum-powered smart contracts. This is why the hacker had to make a fake website. There’s no reserve to tap into, so unless an individual revealed his or her private keys on the hacker’s copycat site, their funds could not be stolen. Also, it was helpful that the exchange runs on a series of nodes and that there is no central access point. Essentially, this insulated the exchange and its smart contracts from being compromised, and it’s the reason the hacker could only execute a phishing attack from the website’s DNS server.

As of yesterday morning, EtherDelta’s site is back up and running.

 

73 Comments

  1. JamesCef January 13, 2021
  2. JamesFieds January 14, 2021
  3. JamesFieds January 16, 2021
  4. JamesEmack January 16, 2021
  5. Lesternep January 19, 2021
  6. DavidSek January 22, 2021
  7. Geraldgof January 26, 2021
  8. zortilo nrel January 28, 2021
  9. thednscheck January 29, 2021
  10. Louisnax February 4, 2021
  11. Louisnax February 5, 2021
  12. Louisnax February 5, 2021
  13. RolandJache February 7, 2021
  14. Europa-Road February 9, 2021
  15. roth ira dividends February 9, 2021
  16. ponto do rateio February 10, 2021
  17. rateiosdcursos February 10, 2021
  18. Slot February 10, 2021
  19. GlennTaupe February 11, 2021
  20. joker123 casino February 11, 2021
  21. elementor website February 12, 2021
  22. scrapbook album February 13, 2021
  23. wedding venues February 13, 2021
  24. produtor grama February 13, 2021
  25. revelar fotos February 13, 2021
  26. weight loss February 13, 2021
  27. Magic mushrooms February 14, 2021
  28. Auto detailing bangor maine February 14, 2021
  29. almofadas decorativas February 15, 2021
  30. fitness shop February 15, 2021
  31. look at this now February 16, 2021
  32. TS911 February 16, 2021
  33. Hot Tub Cover February 17, 2021
  34. malaysia solar February 17, 2021
  35. RichardRex February 17, 2021
  36. kedai jual tangki air February 17, 2021
  37. computer screen repair near me February 17, 2021
  38. RichardRex February 17, 2021
  39. RichardRex February 17, 2021
  40. series flix February 18, 2021
  41. Names for Free Fire February 18, 2021
  42. internet hız testi February 19, 2021
  43. How to make money from amazon February 19, 2021
  44. RichardRex February 19, 2021
  45. amazon fba February 19, 2021
  46. RichardRex February 20, 2021
  47. RichardRex February 20, 2021
  48. RichardRex February 20, 2021
  49. RichardRex February 20, 2021
  50. network installation February 21, 2021
  51. Frankie Lundell February 21, 2021
  52. kreuzfahrten February 21, 2021
  53. jovens de sucesso February 21, 2021
  54. Seguro de Carro SP February 21, 2021
  55. famosas tv February 21, 2021
  56. qqslot February 21, 2021
  57. kreuzfahrten February 22, 2021
  58. stock market crash prediction February 23, 2021
  59. lupus weight gain plaquenil February 23, 2021
  60. air cushion vehilce February 23, 2021
  61. ESL teacher February 23, 2021
  62. Ghana Music February 23, 2021
  63. Moon Arab chat February 24, 2021
  64. video bumper examples February 24, 2021
  65. Accessibility Testing February 24, 2021
  66. solar malaysia February 25, 2021
  67. 3m water filter malaysia February 25, 2021
  68. bairros de sao jose dos campos February 26, 2021
  69. banda de formatura February 26, 2021
  70. skylux centro February 26, 2021

Leave a Reply