Hiding in Plain (Text) Sight

3
0.50
Bifrost releases the technical investigation of the abnormal movement of BNC on July 6th. They have determined that while their on-chain code has been rigorously audited and battle-tested, the security of their off-chain script code was overlooked. The multi-signature script private key was stored in plain text on a configuration file of the hacked script server. The automated fee replenishment script had a 100 BNC limit but no limit on call frequency, so it was easily circumvented by utilizing batch calls. The 3/5 multi-signature for the script is useless because it is not verified during an automated multi-signature. Bifrost is taking various steps to prevent future incidents from occurring, including comprehensively reviewing its off-chain code and moving its scripts on-chain where possible

Tags

Reactions

More from this author

Healing From Beyond
yay.oi
yay.oi
April 3, 2026

Healing From Beyond

The Mossdragon pet on Outmine now has a new ability. On death, Miss You heals all remaining allies by 50% of its max HP.

logo
yay.oi
yay.oi
April 3, 2026

Brewing a Migration

MachineX is halting the PEAQ/BREW pool on April 6th to prepare for the HomebrewRobotics token migration from Raydium to PumpSwap. Holders will need to bridge to Solana and use the official migration platform to ensure compatibility with the new pool once it launches.

Nova鈥檚 Yielding to the Change
yay.oi
yay.oi
April 3, 2026

Nova鈥檚 Yielding to the Change

Nova Wallet v10.8.2, now live, has updated DOT issuance parameters in line with the March 14th halving. This update ensures that in-app staking APYs accurately reflect the resulting reduction in yields.