Un contratista vinculado a Corea del Norte accedió al código de MetaMask durante un mes

Un contratista vinculado a Corea del Norte contribuyó al código de MetaMask desde el 9 de marzo hasta que Consensys canceló su acceso en abril. La compañía no halló pruebas de robo de activos, compromiso de datos o código malicioso.

Consensys señaló que una alerta interna en abril suspendió todos los lanzamientos de productos mientras se investigaba el asunto. Se instruyó al personal para que no interactuara con el consultor durante ese periodo. El asesor jurídico general, Matt Corva, declaró que la firma identificó la amenaza rápidamente, cortó el acceso y notificó a las fuerzas del orden. Señaló que la relación con el proveedor de servicios se consideraba reputada. Según la compañía, no se vieron comprometidas cuentas de usuario ni activos de billeteras. Consensys ha revisado desde entonces sus prácticas con proveedores externos para aplicar controles más estrictos. El incidente involucró únicamente contribuciones de código y no afectó al software desplegado ni a los fondos de los usuarios.

Artículos relacionados

Illustration of a hacked Polymarket wallet showing $520,000 being drained on the Polygon blockchain.
Imagen generada por IA

Polymarket internal wallet drained of over $500,000

Reportado por IA Imagen generada por IA

A private key compromise led to a drain of more than $520,000 from a Polymarket-linked wallet on the Polygon blockchain on May 22. The prediction market platform confirmed that user funds and core contracts remained unaffected.

Hackers stole roughly $3.1 million in PUSD tokens from 11 user wallets on the prediction platform. The theft followed a phishing attack that exploited a compromised third-party vendor.

Reportado por IA

MetaMask has introduced a new wallet designed for AI agents to conduct decentralized finance trades while maintaining user oversight. The launch was announced Monday by the Consensys-owned provider. It includes built-in security measures such as transaction simulations and spending controls.

Jaredfromsubway.eth, a prominent Ethereum MEV bot, lost more than $7.5 million after approving attacker-controlled contracts that enabled an allowance drain. The incident occurred through a series of fake trading routes set up over several weeks. Security firm Blockaid identified the exploit as targeting the bot's automated approval logic rather than private keys or protocol flaws.

Reportado por IA

South Korean prosecutors have arrested the creators of the Solana-based meme coin CatFi over allegations of a rug pull that caused around $599,000 in investor losses. The arrests mark the first application of the country's new Virtual Asset User Protection Act. The coin surged 6,000 percent following the detentions.

MetaMask has introduced a new Money Account that combines stablecoin yield, spending and trading in one self-custodial product. The feature is built on the Monad blockchain and centers on the company's mUSD stablecoin.

Reportado por IA

Allbridge Core has paused its cross-chain stablecoin protocol after losing roughly 1.65 million dollars in a flash loan attack on its Solana liquidity pools. The attacker used a 1.12 million dollar flash loan from Kamino to manipulate pool ratios before withdrawing assets and bridging them to Ethereum.

 

 

 

Este sitio web utiliza cookies

Utilizamos cookies para análisis con el fin de mejorar nuestro sitio. Lee nuestra política de privacidad para más información.
Rechazar