{"id":12693,"date":"2022-04-03T20:50:55","date_gmt":"2022-04-03T20:50:55","guid":{"rendered":"http:\/\/egrowonline.com\/?p=12693"},"modified":"2022-04-03T20:50:55","modified_gmt":"2022-04-03T20:50:55","slug":"625m-hack-highlights-crypto-security-problems","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=12693","title":{"rendered":"$625M Hack Highlights Crypto Security Problems"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"pymnts-content1274085\">\n<p>How do you steal $625 million? In the case of the Ronin Network, a cross-chain bridge that lets people make payments on one blockchain using cryptocurrency from another, you hack five passwords.<\/p>\n<p>If that seems a bit light on the security front, welcome to crypto, where $14 billion was stolen, hacked and scammed last year.<\/p>\n<p><strong>See also:<\/strong> <a target=\"_blank\" href=\"https:\/\/www.pymnts.com\/news\/security-and-risk\/2022\/pymnts-crypto-crime-series-latest-defi-hack-drains-record-625m\/\" rel=\"noopener noreferrer\">PYMNTS Crypto Crime Series: Latest DeFi Hack Drains Record $625M<\/a><\/p>\n<p>But the Ronin Network hack showed a far bigger problem that crypto may have to confront as more and more money gets poured into decentralized finance (DeFi) projects: If your morals are elastic enough, sometimes crime pays very, very well \u2014 and $625 million will rubberize a lot of people\u2019s morals.<\/p>\n<p>This problem is one that the payments industry will have to pay attention to, as it goes to the heart of the technology permitting blockchain transactions to scale to the point where they can compete with credit card networks and other payments rails.<\/p>\n<p>\u201cThis hack reflects the continuing challenges that blockchains and operators face in balancing user experience and security,\u201d <a target=\"_blank\" href=\"https:\/\/www.yahoo.com\/now\/commentary-huobi-analyst-speaks-625-024500388.html\" rel=\"noopener noreferrer\">said<\/a> Flora Li, head of the Huobi cryptocurrency exchange\u2019s Research Institute.<\/p>\n<p>Ronin Network is the blockchain underlying Axie Infinity, far and away the top blockchain-based massively multiplayer online (MMO) game, for the convenience of its eight million-plus players.<\/p>\n<p>The problem, Li explained, is that as the game \u201cexploded in popularity and saw a rapid influx in users on the Ronin blockchain,\u201d and the developers \u201ctook shortcuts to relieve network bottlenecks, cutting down the number of nodes that needed to be validated for transactions [to be added to the blockchain] to just five of nine nodes, making it easier for hackers to exploit.\u201d<\/p>\n<p><strong>Read more:<\/strong> <a target=\"_blank\" href=\"https:\/\/www.pymnts.com\/cryptocurrency\/2022\/51-percent-attack-crypto-double-spending-achilles-heel\/\" rel=\"noopener noreferrer\">The 51% Attack: Crypto\u2019s Double-Spending Achilles Heel<\/a><\/p>\n<p>That\u2019s the dirty little secret of crypto, which likes to tout the immutability of the permanent and unchangeable blockchain. While that\u2019s not wrong, what it doesn\u2019t say is that current and recent transactions aren\u2019t nearly as secure.<\/p>\n<p>And even worse, taking control of a blockchain project allows you to rewrite its rules \u2014 which is apparently what happened to the Ronin Network.<\/p>\n<p><strong>Big Stakes<\/strong><\/p>\n<p>The blockchain technology in question is called proof-of-stake, or PoS, and it\u2019s the consensus mechanism used to secure virtually all DeFi projects \u2014 and really all crypto projects \u2014 in the past couple of years.<\/p>\n<p><strong>Related:<\/strong> <a target=\"_blank\" href=\"https:\/\/www.pymnts.com\/cryptocurrency\/2022\/pymnts-crypto-basics-series-whats-a-consensus-mechanism-and-why-is-it-destroying-the-planet\/\" rel=\"noopener noreferrer\">PYMNTS Crypto Basics Series: What\u2019s a Consensus Mechanism and Why Is It Destroying the Planet?<\/a><\/p>\n<p>You can get into the details using the link above, but the core point is that PoS is what lets new blockchains avoid the energy-intensive, pollution-belching mining that powers Bitcoin.<\/p>\n<p>PoS replaces Bitcoin\u2019s miners, who compete to validate transactions, add them to the blockchain and collect a reward in newly-minted tokens. In blockchain, randomness is key to security \u2014 no one knows who\u2019s going to be approving any specific transaction.<\/p>\n<p>Instead of racing to solve a puzzle, like miners, PoS blockchains use randomly selected validators who put up a \u201cstake\u201d that is similar to the bonds criminal defendants put up to be allowed out on bail \u2014 a surety that they will show up for trial.<\/p>\n<p>Like bail-jumpers, validators can be penalized by having their stake \u201cslashed\u201d for bad behavior, ranging from letting the network go down to approving bad transactions.<\/p>\n<p>However, the problem isn\u2019t that it\u2019s sometimes worth jumping \u2014 it\u2019s that if there are too few validators, it\u2019s too easy to jump.<\/p>\n<p>Which is where we get back to that fact that the Ronin thief only had to hack five passwords. With only nine validators maintaining the project, and well over a half billion dollars on the line, controlling more than half took a comparatively small amount of phishing to accomplish.<\/p>\n<p><strong>Bad Actors<\/strong><\/p>\n<p>There\u2019s another potential flaw with too small a PoS blockchain that doesn\u2019t rely on hacking, however. Bad actors don\u2019t have to be outsiders.<\/p>\n<p>Let\u2019s pause to be very clear: No one has even suggested the Ronin Blockchain validators were anything other than victims, but the thought exercise is pretty easy to follow.<\/p>\n<p>To become a validator on many decentralized blockchains, all you have to do is set up a node \u2014 a computer running a copy of the blockchain \u2014 and put up a stake.<\/p>\n<p>Generally, it\u2019s not really that much money \u2014 in the five figures range \u2014 worth of the blockchain\u2019s native token. If you set up enough nodes, you can overwhelm the \u201cgood\u201d nodes.<\/p>\n<p>It\u2019s not quite that simple, of course. For one thing, staking generally involves getting lots of token holders to \u201cdelegate\u201d their tokens to the staker in exchange for a cut of the rewards. While randomly chosen to validate any one block, validators are selected in proportion to the size of their stake \u2014 someone with 5% of the total amount staked will be chosen to validate 5% of the new blocks.<\/p>\n<p><strong>Other Options, Other Problems<\/strong><\/p>\n<p>An alternative is delegated proof of stake (DPoS), in which token-holders vote on a set number of delegates, with the top vote-holders becoming the validators. If that sounds better, it isn\u2019t.<\/p>\n<p><strong>See also:<\/strong> <a target=\"_blank\" href=\"https:\/\/www.pymnts.com\/blockchain\/2022\/voting-power-struggles-plague-defis-efforts-to-gain-broader-acceptance\/\" rel=\"noopener noreferrer\">Voting Power Struggles Plague DeFi\u2019s Efforts to Gain Broader Acceptance<\/a><\/p>\n<p>One example is Steem, a DPoS blockchain running a social media project. It was run by governance tokens, whose owners voted for \u201cwitnesses\u201d with the 20 largest acting as validators.<\/p>\n<p>When a wealthy investor bought a large majority, the witnesses froze his tokens\u2019 votes. He then gathered enough votes to replace the witnesses and reverse the action and wrest back control of Steem. While no user funds were lost, a very large number decamped to a new version created by forking the blockchain.<\/p>\n<p>Nor is mining-style proof-of-work, or PoW, a panacea. An offshoot of Ethereum, Ethereum Classic, suffered 51% attacks several times when bad actors were able to rent enough mining power to gain control.<\/p>\n<p><strong>A Balancing Act<\/strong><\/p>\n<p>The problem in Ronin\u2019s case came down to centralization \u2014 or rather, lack of decentralization. It comes down to a tradeoff common to blockchain technology that Ethereum creator Vitalik Buterin called the \u201cBlockchain Trilemma.\u201d<\/p>\n<p>At its core, it says that the three aspects of blockchain \u2014 decentralization, security and speed \u2014 require a tradeoff that means any two can only be improved at the expense of a third. As such, blockchain design is a balancing act.<\/p>\n<p>Improving decentralization means more nodes, which slows the speed of the consensus in consensus mechanism \u2014 all nodes must agree to the validator\u2019s proposed block.<\/p>\n<p>Scalability means the number of transactions per second that the blockchain can handle. Making it more decentralized and secure cuts into its scalability. Security, of course, requires more decentralization, but cuts into speed and scalability.<\/p>\n<p>That said, it\u2019s also easy to read too much into the security problems Ronin Network\u2019s hack displayed. Most of the top PoS blockchains have far more validators, and when Ethereum switches from mining to staking in the Ethereum 2.0 project, its number will be vast. It also claims it will be able to handle 100,000 transactions per second.<\/p>\n<p>However, if you\u2019re looking at putting payments on a blockchain, know what you\u2019re getting into, and don\u2019t buy into the immutable hype.<\/p>\n<div class=\"pymnt-bottom-of-article\" id=\"pymnt-1758404603\"><a target=\"_blank\" data-bid=\"1\" href=\"https:\/\/www.pymnts.com\/linkout\/558671\" rel=\"noopener\"><!--noptimize--><\/p>\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n<p><strong>NEW PYMNTS DATA: <span style=\"color: #525252\">WHY PATIENT PORTALS ARE BECOMING TABLE STAKES TO CONSUMERS<\/span><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1273778\" src=\"https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022.jpg\" alt=\"\" width=\"1200\" height=\"452\" srcset=\"https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022.jpg 1200w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-258x97.jpg 258w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-457x172.jpg 457w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-768x289.jpg 768w\" \/><img loading=\"lazy\" decoding=\"async\" class=\"lazyload alignnone size-full wp-image-1273778\" src=\"https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022.jpg\" alt=\"\" width=\"1200\" height=\"452\" srcset=\"https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022.jpg 1200w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-258x97.jpg 258w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-457x172.jpg 457w, https:\/\/securecdn.pymnts.com\/wp-content\/uploads\/2018\/11\/PYMNTS-Study-April-2022-768x289.jpg 768w\" data-sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p><strong>About: <\/strong>Patient portals are now a must-have for providers \u2014 so much so that 61% of patients interested in using the tools say they would switch to a healthcare provider that offers one. For Accessing Healthcare: Easing Digital Frictions In The Patient Journey, a PYMNTS and Experian Health collaboration, PYMNTS surveyed 2,333 consumers to learn how healthcare providers can relieve digital pain points to offer improved patient care and satisfaction.<\/p>\n<p><!--\/noptimize--><\/a><\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.pymnts.com\/cryptocurrency\/2022\/in-625m-hack-a-bigger-crypto-security-problem-is-on-display\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How do you steal $625 million? In the case of the Ronin Network, a cross-chain bridge that lets people make payments on one blockchain using cryptocurrency from another, you hack five passwords. If that seems a bit light on the security front, welcome to crypto, where $14 billion was stolen, hacked and scammed last year. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12694,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[6912,62,517,6745,2754,1349],"class_list":["post-12693","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-625m","tag-crypto","tag-hack","tag-highlights","tag-problems","tag-security"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/04\/ronin-network-blockchain-hack-1000x600.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/12693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12693"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/12693\/revisions"}],"predecessor-version":[{"id":12695,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/12693\/revisions\/12695"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/12694"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12693"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}