« 2022 »

296 reports

2022-08-06 • Nomad

Nomad traced the bridge compromise to an implementation bug in the Replica contract that let forged messages pass authentication. Unproven messages could resolve to bytes32(0), and the initializer had set confirmAt[bytes32(0)] to 1, so acceptableRoot(byte…

#Cryptocurrency #Nomad
2022-08-05 • Nomad

Nomad Bridge published post-incident bounty guidance for hackers after the bridge exploit, offering white-hat treatment to parties returning most stolen funds. The report is operationally relevant CTI for cryptocurrency incident response because it docume…

#Cryptocurrency #Nomad
2022-08-05 • Somansa

The report describes H0lyGh0st ransomware as activity linked to a newly observed North Korean attack group with suspected ties to Andariel. The extracted PDF notes sandbox-evasion capability, use of public open-source components, public-key encryption for…

#Andariel #Ransomware #H0lyGh0st