• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Io.net Responds Swiftly to Cybersecurity Breach

user avatar

by Giorgi Kostiuk

a year ago


Io.net, a decentralized physical infrastructure network known as DePIN, recently experienced a cybersecurity breach. Malicious attackers took advantage of exposed user identity disclosures to carry out a Structured Query Language (SQL) injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

Insights from a Prominent Figure

Husky, the security chief of Io.net, promptly responded to the incident with remedial actions and security upgrades to protect the network. Fortunately, the attack did not harm the actual hardware of GPUs that remained secure due to robust permission layers. The attack was detected during an increase in write operations to the GPU metadata API, triggering alerts on the morning of April 25.

In response, security measures were enhanced by implementing SQL checks in application programming interfaces (APIs) and improving the logging of unauthorized attempts. Additionally, a user-specific authentication solution utilizing OKTA and Auth0 to address security vulnerabilities in universal authorization processes was quickly deployed.

This security update coincided with a snapshot of the reward program, exacerbating the expected decrease among participants on the supply side. As a result, legitimate GPUs that were not restarted and updated could not access the runtime API, leading to a significant drop from 600,000 to 10,000 active GPU connections.

Details of the Attack

The breach stemmed from security vulnerabilities that emerged while applying a proof of work (PoW) mechanism to identify fake GPUs. Aggressive security patches applied before the incident resulted in an increase in attack methods, necessitating ongoing security reviews and improvements.

Attackers exploited a security flaw in the API to view content in the input and output explorer, inadvertently exposing user identities while searching by device identifiers. Malicious actors compiled this leaked information in a database weeks before the breach.

Husky emphasized ongoing comprehensive reviews and penetration tests at public endpoints to detect and neutralize threats early. Efforts to encourage participation on the supply side, rebuild network connections, ensure platform integrity, and serve tens of thousands of computing hours per month continue despite challenges.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Understanding the Bitcoin Price Drop: What It Means for Investors

chest

Bitcoin has dipped below $110,000, raising concerns among investors. This article examines the causes and market reactions.

user avatarGiorgi Kostiuk

PYTH Surges Over 100% After Being Chosen as U.S. Government Oracle Partner

chest

The price of PYTH token rose over 100% after the announcement of its partnership with the U.S. government. What are the implications of this increase?

user avatarGiorgi Kostiuk

Ethereum Profits Could Rotate into Cardano and Layer Brett: An Analysis of Current Market Trends

chest

This article explores why investors are shifting focus from Ethereum to Cardano and Layer Brett, and how it impacts the market.

user avatarGiorgi Kostiuk

Bitcoin Attempts to Recover After Distribution Phase

chest

Analysis of current Bitcoin market trends indicates an accumulation stage and potential formation of a new base.

user avatarGiorgi Kostiuk

Caliber: Market Reacts to Chainlink's Adoption in Digital Asset Strategy

chest

Caliber has announced a digital treasury strategy using Chainlink, resulting in a 77% surge in its stock.

user avatarGiorgi Kostiuk

OSL Group Results: 58% Revenue Increase in H1 2025

chest

OSL Group reports a 58% increase in revenue in the first half of 2025 amid growing interest in digital assets.

user avatarGiorgi Kostiuk

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.