By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
GPTTradeAssist.comGPTTradeAssist.com
  • Home
  • AI Advisor
  • Strategy Builder
  • RSI Strategy
  • Pinescript
  • Spreadsheet
  • Bot Builders
    • Binance Bot
    • TradeStation Bot
    • MultiCharts Bot
  • Blog
Reading: Friend.tech Front-End Breach Could Be More “Devastating” Than Balancer’s
Sign In
Aa
Aa
GPTTradeAssist.comGPTTradeAssist.com
  • Home
  • AI Advisor
  • Strategy Builder
  • RSI Strategy
  • Pinescript
  • Spreadsheet
  • Bot Builders
  • Blog
Search
  • Home
  • AI Advisor
  • Strategy Builder
  • RSI Strategy
  • Pinescript
  • Spreadsheet
  • Bot Builders
    • Binance Bot
    • TradeStation Bot
    • MultiCharts Bot
  • Blog
Have an existing account? Sign In
Follow US
© 2023 Chaplin.app. All Rights Reserved.
GPTTradeAssist.com > Blog > Friend.tech Front-End Breach Could Be More “Devastating” Than Balancer’s
Blog

Friend.tech Front-End Breach Could Be More “Devastating” Than Balancer’s

Team GTA
Team GTA
Last updated: 2023/09/22 at 12:00 AM
Crypto news Template49, GPTTradeAssist.com

GTP Trade Assist Banner Horizontal, GPTTradeAssist.com

One of the core developers behind DeFiLlama, a portal that analyzes decentralized finance (DeFi) protocols, believes that a hack on Friend.tech, a decentralized social media network on Base, a layer-2 platform backed by Coinbase, will be more “devastating” than the recent breach on Balancer whose front-end was exploited and over $238,000 worth of assets reportedly stolen. 

Contents
3 Ways Friend.tech Users Can Lose Funds If HackedThe Balancer Hack

In the analyst’s assessment, the social media network can be compromised in three ways, stating that any exploit initiated from the front end could see Friend.tech users lose funds simply by “opening the app,” adding that they won’t have “to do anything.”

3 Ways Friend.tech Users Can Lose Funds If Hacked

Upon analyzing Friend.tech’s security model, the analyst explained that if their direct iframe was compromised, a hacker could gain unauthorized access to the user’s funds.

In web development, the direct iframe allows users to embed links, which can be from social media or even Google. All the developer needs is to enable HTML addition before formatting using CSS.

While the direct iframe is easy to use and flexible, it also introduces security risks. This is because by allowing anyone to insert HTML code, malicious agents can choose to embed corrupted code.

Besides direct iframe, the analyst also pointed out a hack on Friend.tech’s privy iframe can lead to loss of funds. He notes that the platform’s privy iframe holds the private keys, allowing users to easily connect the dapp with their non-custodial wallets such as MetaMask.

Privy iframe is critical in DeFi, forming the critical infrastructure for decentralized exchanges (DEXs) and non-fungible token (NFT) marketplaces operating on public networks like Ethereum or the BNB Chain. 

BNB price on September 21| Source: BNBUSDT on Binance, TradingView

A privy iframe allows developers to embed a Privy wallet. A Privy wallet is non-custodial, meaning the end-user has control of the necessary private keys. At the same time, they are isolated to ensure that user private keys cannot be accessed by third parties or even other code.

Moreover, the analyst notes that if Friend.tech’s privy iframe loses data, funds wouldn’t be accessible since they hold 2/3 shards, essentially equating to losing private keys.

The Balancer Hack

On September 19, the front-end of Balancer, a DeFi protocol that allows users to create and manage custom liquidity pools, was hacked. Peckshield, a blockchain security platform, estimated that at least $238,000 of assets had been stolen before Balancer asked users not to interact with the portal. When interacting with the protocol, some users noted that they were requested change chains and approve malicious contracts.

Statistics from DeFiLlama states that at least $7 billion of assets have been stolen through hacks. According to the DeFi analytics platform, besides the Balancer hack, other notable exploits resulting in significant loss include the Remitano breach where hackers stole $2.7 million, and Curve’s where over $61 million was lost.

Total amount of assets stolen via hacks| Source: DeFiLlama
The total amount of assets stolen via hacks| Source: DeFiLlama

Feature image from Canva, chart from TradingView



GTP Trade Assist Banner Horizontal, GPTTradeAssist.com

Source link

You Might Also Like

MACD, RSI, ADX, Bollinger Bands, and More

EMA Crossover Signal and Higher Timeframe Trend Forex Trading Strategy

NZD/USD gathers strength above 0.5800 as New Zealand exits recession

Strong Selling The Day Before A Fed Day

Bakkt stock tumbles nearly 30% after losing Bank of America and Webull

Team GTA September 22, 2023
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

dollar printing gm502820559 44181970 Large, GPTTradeAssist.com
Dollar tumbles on Fed’s pivot despite US economy still outperforming
Blog
gold on weight scale gm165418687 21879510 Large, GPTTradeAssist.com
XAU/USD to extend its race higher once hurdle at $2,135/$2,140 is overcome – SocGen
Blog
microstrategy world thumbnail day 2, GPTTradeAssist.com
LIVE – MicroStrategy World: Bitcoin for Corporations Day 2
Blog
Fed Bowman id 668943c6 0464 41a7 8ab8 817bf9eda962 size975, GPTTradeAssist.com
Feds Bowman: Further interest rate increases likely appropriate with inflation still high
Blog
1500x500 e1713876788472, GPTTradeAssist.com
Why TREAT Carries A Critical Role
Blog
US dollar volatility id 48401308 28dd 4e62 ac87 d054e26f5024 size975, GPTTradeAssist.com
April seasonality USD tends to fall in April and bounce back in May — SocGen
Blog

GPTTradeAssist.comGPTTradeAssist.com
Follow US

© 2023 GPTTradeAssist.com | All rights reserved

  • Home
  • Privacy
  • Terms

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Continue with Google
Lost your password?