Categories: News

Found serious bug in the portfolios of Dapp DeFi

A team of product designers for ZenGo, a non-portfolio company, has discovered a flaw that can drain user funds from almost all dapp wallets. This security bug has been known for two years. Ouriel Ohayon, CEO of ZenGo, is now sounding the alarm claiming that it poses a risk to users who do not face it directly.

How the bug works

The security problem, called BaDApprove, is not a code bug but a problem in the way users select transaction permissions in the default settings. Ohayon found that when users approve a specific transaction, they are also approving all future transactions by default.

This opens the door to decentralized malware applications that interact with users' funds without their knowledge.

Because it hasn't been resolved before

What Ohayon and ZenGo have highlighted has been a known problem in the DeFi community for years. The question is, then, why it hasn't been resolved before. For some in the industry, the answer is that it's not so much a flaw or bug as bad functionality.

In September 2018, Jordan Randolph, a representative of Ethex, a decentralized exchange, categorized the problem as being of medium severity. One-off authorizations to move "an almost infinite amount of tokens … can be convenient," he wrote.

“However, having an almost infinite number of approved tokens means that all [tuoi] tokens could be transferred with a smart contract. " The portfolio preset then boils down to a choice between convenience and security, he said.

Ben He, CEO of imToken, said: "It's not a security bug, it's a bad convention for the entire Ethereum ecosystem that most Dapps / DeFi apps require unlimited user approvals."

Metamask presented a similar response regarding unlimited authorizations. “This is actually a secure feature that users regularly use responsibly. It's not a kind of bug or problem. "

Both ImToken and MetaMask have been proactive in adding guarantees, such as pop-up messages that ask for confirmation for sending funds and allow users to change the approved amount in advanced settings. Ohayon also cited Brave and Coinbase for their warnings complementary to those of the Dapps.

Dapps need to be adapted to a mainstream DeFi

"Certain security compromises that may have been acceptable in an era when users were few and highly technically trained are no longer acceptable as DeFi goes mainstream, acquiring many technically poorly trained users and managing billions of dollars in crypto tokens ( USD) ”, Alex Manuskin, ZenGo researcher, wrote in a post.

He believes that if ever the cryptocurrency that is already possible to trade on platforms like Bitcoin Pro will become mainstream, adequate guarantees must be put in place so that new users are not exploited. A similar problem was raised two weeks ago after the crypto flash, when the issue of circuit breaker trading emerged.

For many, these precautions run counter to the crypto ethos of decentralization and personal autonomy.

Miners Hashrate

Recent Posts

Mining RTX 3070 at NiceHash: Overclocking, tuning, profitability, consumption

Mining on RTX 3070. Overclocking, tuning, profitability, consumption: If you are interested in finding more…

6 months ago

Mining GTX 1660, 1660 Ti, 1660 Super: Overclocking, settings, consumption

Mining with GTX 1660, 1660 Ti, 1660 Super. Overclocking, settings, consumption, profitability, comparisons - If…

6 months ago

Mining RTX 2070 and 2070 Super: Overclocking, profitability, consumption

Mining with RTX 2070 and 2070 Super. Overclocking, profitability, consumption, comparison What the RTX 2070…

6 months ago

Mining with RTX 3060, 3060 Ti. Limitations, overclocking, settings, consumption

Mining with RTX 3060, 3060 Ti. Limitations, overclocking, settings, consumption, profitability, comparison Let's look at…

6 months ago

Alphacool Eisblock Aurora Acryl GPX-A Sapphire – test: 2.8 GHz++ are not an issue

Alphacool Eisblock Aurora Acryl GPX-A (2022) with Sapphire Radeon RX 6950 XT Nitro+ Pure in…

6 months ago

Corporate Crypto Strategies 4.0: Leading with Bitcoin Expertise

In the ever-evolving landscape of business strategy, Bitcoin has emerged as a pivotal asset. With…

6 months ago

This website uses cookies.


Notice: ob_end_flush(): failed to send buffer of zlib output compression (1) in /home/gamefeve/bitcoinminershashrate.com/wp-includes/functions.php on line 5420

Notice: ob_end_flush(): failed to send buffer of zlib output compression (1) in /home/gamefeve/bitcoinminershashrate.com/wp-includes/functions.php on line 5420