• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Io.net Responds Swiftly to Cybersecurity Breach

user avatar

by Giorgi Kostiuk

a year ago


Io.net, a decentralized physical infrastructure network known as DePIN, recently experienced a cybersecurity breach. Malicious attackers took advantage of exposed user identity disclosures to carry out a Structured Query Language (SQL) injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

Insights from a Prominent Figure

Husky, the security chief of Io.net, promptly responded to the incident with remedial actions and security upgrades to protect the network. Fortunately, the attack did not harm the actual hardware of GPUs that remained secure due to robust permission layers. The attack was detected during an increase in write operations to the GPU metadata API, triggering alerts on the morning of April 25.

In response, security measures were enhanced by implementing SQL checks in application programming interfaces (APIs) and improving the logging of unauthorized attempts. Additionally, a user-specific authentication solution utilizing OKTA and Auth0 to address security vulnerabilities in universal authorization processes was quickly deployed.

This security update coincided with a snapshot of the reward program, exacerbating the expected decrease among participants on the supply side. As a result, legitimate GPUs that were not restarted and updated could not access the runtime API, leading to a significant drop from 600,000 to 10,000 active GPU connections.

Details of the Attack

The breach stemmed from security vulnerabilities that emerged while applying a proof of work (PoW) mechanism to identify fake GPUs. Aggressive security patches applied before the incident resulted in an increase in attack methods, necessitating ongoing security reviews and improvements.

Attackers exploited a security flaw in the API to view content in the input and output explorer, inadvertently exposing user identities while searching by device identifiers. Malicious actors compiled this leaked information in a database weeks before the breach.

Husky emphasized ongoing comprehensive reviews and penetration tests at public endpoints to detect and neutralize threats early. Efforts to encourage participation on the supply side, rebuild network connections, ensure platform integrity, and serve tens of thousands of computing hours per month continue despite challenges.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Binance Alpha Initiates Contract Swap for Griffin AI GAIN Token

chest

On October 13, Binance Alpha announced a contract swap for the Griffin AI GAIN token following a hacking incident.

user avatarKenji Takahashi

Binance Wallet Users Face Delays Amid Heavy Network Traffic

chest

On October 13, Binance Wallet users faced delays in accessing event participation details due to heavy network traffic.

user avatarDiego Alvarez

BitMine's October Chairman's Message Highlights Ethereum Supercycle

chest

In the October Chairman's Message, Thomas Tom Lee discusses the potential of Ethereum in a Supercycle driven by AI and blockchain integration.

user avatarMaria Fernandez

Mythical Games Expands Marketplace with Worldchain Integration

chest

Mythical Games plans to integrate its marketplace with Worldchain to enhance secure gaming infrastructure and digital ownership.

user avatarGustavo Mendoza

Eightco Holdings Inc Makes Strategic Investment in Mythical Games

chest

Eightco Holdings Inc announces a strategic investment in Mythical Games as part of their Series D financing, led by ARK Invest.

user avatarLuis Flores

JPMorgan Chase Unveils $18 Billion Tech Investment Plan for 2025

chest

JPMorgan Chase has announced an ambitious $18 billion technology investment plan for 2025, focusing on advancements in artificial intelligence, automation, and infrastructure.

user avatarMiguel Rodriguez

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.