• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Io.net Responds Swiftly to Cybersecurity Breach

user avatar

by Giorgi Kostiuk

2 years ago


Io.net, a decentralized physical infrastructure network known as DePIN, recently experienced a cybersecurity breach. Malicious attackers took advantage of exposed user identity disclosures to carry out a Structured Query Language (SQL) injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

Insights from a Prominent Figure

Husky, the security chief of Io.net, promptly responded to the incident with remedial actions and security upgrades to protect the network. Fortunately, the attack did not harm the actual hardware of GPUs that remained secure due to robust permission layers. The attack was detected during an increase in write operations to the GPU metadata API, triggering alerts on the morning of April 25.

In response, security measures were enhanced by implementing SQL checks in application programming interfaces (APIs) and improving the logging of unauthorized attempts. Additionally, a user-specific authentication solution utilizing OKTA and Auth0 to address security vulnerabilities in universal authorization processes was quickly deployed.

This security update coincided with a snapshot of the reward program, exacerbating the expected decrease among participants on the supply side. As a result, legitimate GPUs that were not restarted and updated could not access the runtime API, leading to a significant drop from 600,000 to 10,000 active GPU connections.

Details of the Attack

The breach stemmed from security vulnerabilities that emerged while applying a proof of work (PoW) mechanism to identify fake GPUs. Aggressive security patches applied before the incident resulted in an increase in attack methods, necessitating ongoing security reviews and improvements.

Attackers exploited a security flaw in the API to view content in the input and output explorer, inadvertently exposing user identities while searching by device identifiers. Malicious actors compiled this leaked information in a database weeks before the breach.

Husky emphasized ongoing comprehensive reviews and penetration tests at public endpoints to detect and neutralize threats early. Efforts to encourage participation on the supply side, rebuild network connections, ensure platform integrity, and serve tens of thousands of computing hours per month continue despite challenges.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Twenty One Capital Executes $39B Bitcoin Transfer, Signaling Institutional Confidence

chest

Twenty One Capital has executed a massive Bitcoin transfer of 43,122 BTC, valued at approximately $3.94 billion, signaling deep institutional confidence in Bitcoin's long-term value.

user avatarLuis Flores

Yearn Finance yETH Vault Exploit Results in 9 Million Loss

chest

Yearn Finance's yETH vault was exploited, leading to a loss of 9 million.

user avatarZainab Kamara

Chainlink's Open Interest Surges Amid Bearish Market Conditions

chest

Chainlink's open interest has surged past 127 million USDT, indicating increased leverage in a bearish market as the token retests a critical breakdown support level.

user avatarArif Mukhtar

Trump Administration Advances Crypto Policies Amid National Security Strategy Release

chest

The Trump administration has been actively promoting crypto policies this year, supporting the GENIUS Act and establishing a Bitcoin reserve, despite the omission of cryptocurrency in the national security strategy.

user avatarMaria Gutierrez

Bitcoin Encounters Significant Resistance Levels Ahead.

chest

Bitcoin is approaching significant resistance levels, with immediate resistance at 91,650 and key levels at 92,000 and 93,000. A close above 93,000 could lead to further increases, potentially testing the 95,000 resistance. However, if Bitcoin fails to rise above the 91,650 resistance zone, it may start another decline, with immediate support near 90,000 and major support at 89,500.

user avatarDavid Robinson

Uniswap Achieves Milestone of 4 Trillion in Trading Volume

chest

Uniswap Labs announced this week that the protocol has surpassed 4 trillion in cumulative trading volume across 2,586 days.

user avatarSon Min-ho

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.