{"id":12964,"date":"2022-06-26T18:38:40","date_gmt":"2022-06-26T18:38:40","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst-bitcoin-news\/"},"modified":"2022-06-26T18:38:40","modified_gmt":"2022-06-26T18:38:40","slug":"harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst-bitcoin-news\/","title":{"rendered":"Harmony&#8217;s $100M Hack Was Due to a Compromised Multi-Sig Scheme, Says Analyst \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n<\/div>\n<p><strong>On June 23, 2022, the Harmony development team announced that $100 million was siphoned from the Horizon bridge, and the organization explained it was working with national authorities and forensic specialists. According to an account published Polygon\u2019s chief information security officer, Mudit Gupta, the Horizon bridge attacker allegedly took control of the multi-signature wallet leveraged in Harmony\u2019s bridge.<\/strong><\/p>\n<h2>Harmony\u2019s Multi-Sig Exploited Polygon\u2019s CSO Says, Harmony Protocol\u2019s Founder Found Evidence That \u2018Private Keys Were Compromised\u2019<\/h2>\n<p>Three days ago, Harmony explained that it was attacked and the team witnessed $100 million siphoned from the Horizon bridge. \u201cThe Harmony team has identified a theft occurring this morning on the Horizon bridge amounting to approx. $100 [million],\u201d Harmony <a href=\"https:\/\/twitter.com\/harmonyprotocol\/status\/1540110924400324608?s=20&amp;t=OUkGVDqN-C8OLhiwumm9Cg\">tweeted<\/a> on Thursday. \u201cWe have begun working with national authorities and forensic specialists to identify the culprit and retrieve the stolen funds,\u201d the Harmony team added.<\/p>\n<p>Following the exploit, the very next day, Polygon\u2019s chief information security officer, Mudit Gupta, <a href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1540225234153996288?s=20&amp;t=gWW5geLAcUP5iK9wV7jrgw\">said<\/a> that the bridge was a 2 of 5 multi-signature scheme, and anyone with two of the addresses can take control of it. \u201cThe hacker compromised 2 addresses and made them drain the money,\u201d Gupta added. Gupta said while the details aren\u2019t public yet he summarized what he believes took place during the hack. \u201cThe two addresses were likely hot wallets used to listen for and process legit bridging transactions,\u201d Gupta <a href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1540225237912010753?s=20&amp;t=gWW5geLAcUP5iK9wV7jrgw\">explained<\/a>.<\/p>\n<p>\u201cThe attacker compromised the server(s) that these hot wallets were running on,\u201d the Polygon CSO wrote on Friday. \u201cOnce inside the server, they could access the keys that were kept in plaintext for signing legit transactions. The server exploit was likely either SSH key compromise or social engineering. This is eerily similar to how Ronin was hacked.\u201d The analyst further added:<\/p>\n<blockquote>\n<p>This was not a \u2018Blockchain Hack.\u2019 It was a \u2018Traditional Hack.\u2019 I\u2019ve been begging protocols to focus on traditional security too alongside blockchain security for months now\u2026<\/p>\n<\/blockquote>\n<p>Furthermore, an <a href=\"https:\/\/twitter.com\/stse\/status\/1540896631339438080?s=20&amp;t=OUkGVDqN-C8OLhiwumm9Cg\">incident report<\/a> written by the <a href=\"https:\/\/twitter.com\/stse\">Harmony Protocol\u2019s founder<\/a> says \u201cthe team has found evidence that private keys were compromised, leading to the breach of our Horizon bridge \u2014 Funds were stolen from the Ethereum side of the bridge.\u201d The Harmony founder also noted that \u201cconfidentiality is key to maintain integrity as part of this ongoing investigation \u2014 The omission of specific details is to protect sensitive data in the interest of our community.\u201d<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/100-million\/\">100 million<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/2-of-5-multi-signature-scheme\/\">2 of 5 multi-signature scheme<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/confidentiality\/\">Confidentiality<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/decentralized-finance\/\">decentralized finance<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi\/\">DeFi<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi-hacks\/\">defi hacks<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/harmony-hack\/\">Harmony Hack<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/harmony-protocol\/\">Harmony Protocol<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/harmony-protocols-founder\/\">Harmony Protocol\u2019s founder<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/horizon-bridge\/\">Horizon Bridge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/horizon-bridge-exploit\/\">Horizon bridge Exploit<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/incident-report\/\">incident report<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/mudit-gupta\/\">Mudit Gupta<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/multi-signature\/\">Multi-signature<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/polygon-cso\/\">Polygon CSO<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ronin-exploit\/\">Ronin Exploit<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/sensitive-data\/\">sensitive data<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/stolen-funds\/\">Stolen funds<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think about the Harmony exploit for $100 million? Let us know what you think about this subject in the comments section below.<\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-300x300.jpg 2x\" class=\"avatar avatar-150 photo\"\/><\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nJamie Redman <\/h6>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today.<br \/><span class=\"td-social-icon-wrap\"><br \/>\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/jamieCrypto\" title=\"Twitter\" rel=\"noopener\"><br \/>\n<i class=\"td-icon-font td-icon-twitter\"\/><br \/>\n<\/a><br \/>\n<\/span>\n<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons<\/em><\/p>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/harmonys-100m-hack-was-due-to-a-compromised-multi-sig-scheme-says-analyst\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) On June 23, 2022, the Harmony development team announced that $100 million was siphoned from the Horizon bridge, and the organization explained it was working with national authorities and forensic specialists. According to an account published Polygon\u2019s chief information security officer, Mudit Gupta, the Horizon bridge attacker allegedly [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":12965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/12964"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=12964"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/12964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/12965"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=12964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=12964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=12964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}