Tornado Cash suffers governance hijack

TL;DR Breakdown

  • Tornado Cash encountered a slight setback after its governance was hijacked by an attack.
  • The platform is seeking measures to salvage the situation.

In a concerning development, Tornado Cash, a decentralized crypto mixer, has encountered a significant setback as an attacker managed to seize full control of the platform’s governance through a malicious proposal. The incident unfolded on May 20 at 3:25 ET when the attacker granted themselves 1.2 million votes, effectively taking over Tornado Cash’s governance system. This exploit occurred despite the proposal receiving over 700,000 legitimate votes, allowing the attacker to manipulate the platform at will.

The attacker designed a malicious program to attack Tornado Cash

The details of the attack were shared by @samczsun, a member of Paradigm, a research-driven technology investment firm. According to @samczsun, the attacker cunningly designed the malicious proposal to resemble a previously successful one, exploiting the trust and familiarity of the community. However, this time, the proposal included an additional function.

Once the proposal gained sufficient votes, the attacker swiftly executed the emergency stop function, modifying the proposal logic to grant themselves the fraudulent votes. With complete control over Tornado Cash’s governance, the attacker proceeded to withdraw 10,000 votes as TORN and subsequently sold them for personal gain.

This incident serves as a stark reminder to crypto investors about the importance of scrutinizing proposal descriptions and logic before casting their votes. In response to the attack, Tornado Cash’s active community member known as Tornadosaurus-Hex or Mr. Tornadosaurus Hex confirmed that all funds within the Governance system are potentially compromised. They urged all members to withdraw their locked funds from governance to safeguard their assets.

In an effort to address the situation, the community attempted to deploy a contract to revert the changes and advised members to withdraw their funds. Meanwhile, a distressed call for help was issued by a community developer, confirming the attack and stating that the situation currently remains dire, with the attacker controlling the Governance system.

The platform is looking for ways to salvage the situation

The Tornado Cash team is actively seeking Solidity developers who can assist in salvaging the protocol from this critical situation. Additionally, they are seeking to establish contact with Binance, as the exchange holds more tokens than the attacker, potentially providing a path for mitigating the damage.

Meanwhile, a former Tornado Cash developer is reportedly working on creating a new crypto mixing service from scratch. This new solution aims to address the “critical flaw” present in Tornado Cash while empowering the community to protect against hackers without resorting to excessive regulation or compromising the core principles of cryptocurrencies.

As Tornado Cash faces the aftermath of this attack, the crypto community is reminded of the ongoing challenges and vulnerabilities present in the decentralized ecosystem. Efforts to enhance security measures and community involvement are essential to safeguarding the integrity and trustworthiness of these platforms in the future.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Tornado Cash suffers governance hijack

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月22日 20:06
Next 2023年5月22日 21:38

Related articles

  • Celsius network files petition for relief in GK8 proceeds distribution amidst legal turmoil

    TL;DR Breakdown Celsius Network files a petition seeking relief in distributing proceeds from the GK8 sale. A settlement agreement was reached among Series B investors, allocating $25 million, with $24 million for legal fees and $1 million for stockholders. Acquisition of GK8 and subsequent bankruptcy present challenges for Celsius Network. Description Celsius Network, a bankrupt cryptocurrency lending company, has approached the court for relief concerning the distribution of proceeds from the sale of the self-custody platform GK8. Significantly, on July 17th, the company’s unsecured creditors filed a document. It announced that the Series B investors of the company had agreed to a settlement. This agreement would … Read more Celsius Network, a bankrupt cryptocurrency lending company, has approached the court for relief concerning the distribution of proceeds from the sale of the self-custody platform GK8. Significantly, on July 17th, the company’s unsecured creditors filed a document. It announced that the Series B investors of the company had agreed to a settlement. This agreement would divide $25 million from the GK8 sale. The creditors’ committee, the debtors, and the original consenting…

    Article 2023年7月18日
  • France invites crypto companies that are tired of the U.S.

    TL;DR Breakdown France is extending an invitation to cryptocurrency companies seeking a predictable regulatory environment amid increasing uncertainty in the United States. Already hosting 74 registered crypto firms, France is expecting a surge in anticipation of the EU’s Markets in Crypto Assets rules. Despite the complexity and rigor of France’s regulatory framework, French officials maintain that the requirements are practical and achievable, offering a more predictable path compared to the U.S. In the face of escalating regulatory uncertainty in the United States, France extends an invitation to beleaguered cryptocurrency companies looking for a more predictable environment. French officials are confidently promoting their nation’s regulatory framework, which already hosts approximately 74 registered cryptocurrency firms, a figure poised to rise with the upcoming implementation of the European Union’s Markets in Crypto Assets rules. A pioneer in crypto regulation France has taken significant strides in legitimizing the digital asset market. The Secretary General of the Autorité des marchés financiers (AMF), Benoît de Juvigny, asserted France’s leading role in crafting the crypto service asset provider (PSAN) regime in 2019. He stated, “In France, we…

    Article 2023年5月18日
  • National Australia Bank reveals drastic measures to protect customers from crypto scams

    TL;DR Breakdown One of the key steps outlined by NAB is the blocking of certain cryptocurrency platforms, citing high levels of scam risk within the industry. Although the bank did not disclose the names of the specific cryptocurrency exchanges that will be affected, Chris Sheehan, NAB’s executive for group investigations and fraud, mentioned that the blocks would target “high-risk” platforms known for prevalent scam activities. The bank highlighted the rapid growth of cryptocurrency-related scams, with Australians losing over $221 million to such schemes in the previous year. Description On July 17, National Australia Bank (NAB) made an announcement regarding its new measures to protect customers from fraud as part of its “bank-wide scam strategy.” One of the key steps outlined by NAB is the blocking of certain cryptocurrency platforms, citing high levels of scam risk within the industry. The bank revealed that it … Read more On July 17, National Australia Bank (NAB) made an announcement regarding its new measures to protect customers from fraud as part of its “bank-wide scam strategy.” One of the key steps outlined by NAB…

    Article 2023年7月17日
  • IOSCO releases recommendations to strengthen crypto regulation

    TL;DR Breakdown IOSCO has released a recommended guide to help regulators strengthen the regulatory framework of the crypto industry. The body wants regulatory clarity and criticism of the regulatory framework. The International Organization of Securities Commissions (IOSCO), a prominent global securities watchdog, has taken steps to assist policymakers in effectively regulating cryptocurrency. On May 23, the IOSCO Board’s Fintech Task Force released a consultation report containing a set of regulatory recommendations concerning cryptocurrencies. IOSCO releases its recommendations The report consists of 18 policy recommendations aimed at helping securities regulators worldwide address concerns related to market integrity and investor protection in the crypto space. Following a consultation period until the end of July, the recommendations are expected to be finalized by late 2023. In its first chapter, IOSCO presents an overarching recommendation advising regulators not to create disparities between the regulation of cryptocurrency and traditional finance. The organization suggests that crypto regulators should strive to achieve regulatory outcomes that are consistent with those required in traditional financial markets. This approach aims to establish a level-playing field between crypto-assets and traditional financial…

    Article 2023年5月25日
  • Binance faces leadership exodus amid regulatory crackdown

    TL;DR Breakdown Binance, the world’s largest cryptocurrency exchange, has experienced the departure of two senior executives, Gleb Kostarev and Vladimir Smerkis, who were overseeing operations in Eastern Europe and Russia. They join a list of other high-profile exits, adding to the challenges facing the company. The departures come amid increasing regulatory scrutiny from U.S. and other global authorities, including lawsuits from the U.S. Securities and Exchange Commission and the Commodity Futures Trading Commission. CEO Changpeng Zhao acknowledged the departures but did not elaborate on the reasons. Description Binance, the world’s largest cryptocurrency exchange, has seen the departure of two key executives overseeing its operations in Eastern Europe and Russia. This comes as the exchange faces increasing scrutiny from regulators in the United States and other countries. A spate of high-profile departures Gleb Kostarev, who was the regional head for Eastern Europe, the … Read more Binance, the world’s largest cryptocurrency exchange, has seen the departure of two key executives overseeing its operations in Eastern Europe and Russia. This comes as the exchange faces increasing scrutiny from regulators in the United…

    Article 2023年9月7日
TOP