💎 Fed’s first rate cut since 2020 set to trigger market. Find undervalued gems with Fair ValueSee Undervalued Stocks

More on MyEtherWallet Saga: Attackers Have 25K Ether Stockpile

Published 04/25/2018, 07:04 AM
Updated 04/25/2018, 07:31 AM
 More on MyEtherWallet Saga: Attackers Have 25K Ether Stockpile
AMZN
-

After careful investigation of the recent MyEtherWallet hack, reports show that the attackers had a stash of Ether worth over $17 million. In addition to this, Cryptovest.com found more details related to the incident, including the attack vector used for poisoning the myetherwallet.com DNS.

On Tuesday, between 11am and 1pm UTC, the way the internet routed people to IP addresses was partially compromised after what is presumed to be a group of hackers took advantage of the Border Gateway Protocol—a crucial backbone used to route traffic in the internet—to insert malicious routes on Amazon’s Route 53 service.

Because the system is responsible for so much traffic on the internet, it relies on several “trusted” DNS providers to give users the information they need to resolve the domain names of the servers they need to connect to. Amazon (NASDAQ:AMZN) Route 53 is by far one of the most crucial, directing traffic for websites like Twitter. The attack was initiated when hackers used a man-in-the-middle technique to hook onto one of Equinix’s servers in Chicago.

“So far the only known website to have traffic redirected was to MyEtherWallet.com, a cryptocurrency website. This traffic was redirected to a server hosted in Russia, which served the website using a fake certificate—they also stole the cryptocoins of customers,” wrote Kevin Beaumont, an independent cybersecurity researcher.

We have no evidence at this moment that any other websites were affected. However, as Beaumont explains in his blog, it is suspicious for hackers that possess a total of over $17 million in Ether to go through this much effort just to steal $150,000.

This is by far the most sophisticated crypto-related hacking incident yet; taking control of one of the major backbones of the internet to siphon cryptocurrency from people’s wallets.

For all we know, this could have been a test run. The likelihood of another attack is high enough that it might have the cybersecurity community following them for the foreseeable future.


This article appeared first on Cryptovest

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.