SlideShare a Scribd company logo
How Blockchain Applications Can Be
Hacked, And What You Can Do To
Prevent It
Despite much of the early hype, blockchain applications are not
“unhackable.” In the last year, a handful of highly visible attacks against
blockchain-based tools served as a reminder that there’s no such thing as
flawless security. Luckily, none of the recent blockchain compromises have
done lasting damage to its overall public image. In fact, cryptocurrency is
more popular than ever before. With this in mind, spreading awareness of
blockchain security issues has become a key task for the crypto community.
Following these highly public incidents, developers and end users alike are
discussing ways in which cryptocurrency security can be compromised, and
the various countermeasures most effective against it.
The most notable cases of blockchain hacking have shown that it suffers from
the same security issues of older technologies. These attacks did not result
from the vulnerabilities in the blockchain itself, but the ways it was
implemented by a particular company or initiative. In other words, the issue
was not related to the technical protocol, but weaknesses introduced by
external developers.
This was certainly true in the case of Bitfinex, whose August 2016 hack
resulted in the total theft of $60 million worth of BTC. The issue here was not
the blockchain on which it was based, but the exchange’s specific encryption
strategy. Bitfinex used multi-signature wallets for its user accounts. This
works by distributing private keys between a numbers of different parties in
order to minimize the risk associated with centralizing key storage. One of the
keys that were distributed was obtained by a bad actor that proceeded to drain
Bitfinex accounts. This not only hurt individual investors, but sent the price of
Bitfinex stock tumbling by almost twenty percent.
Bitfinex made early promises to repay all of its investors in full, a goal it was
able to meet by April 2017. This helped to quell speculation that the exchange
was compromised from within and helped rebuild its overall reputation. The
repayment and overall recovery of Bitfinex marks it a success story, and today
the Hong Kong-based exchange has reasserted itself as a leading
cryptocurrency trading platform.
The takeaway from the attack on Bitfinex is that well-known hacking methods
are very much present in the cryptocurrency realm, no matter how strong the
blockchain might be. The attack did not reveal any weaknesses in blockchain
protocol itself, but a layer of encryption that was added to it. This additional
protection was the site of exploitation — i.e., the place where the private key
was taken.
Stealing private keys has been a hacking strategy since the rise of key-based
encryption, and often happens through social engineering. If social engineering
was indeed the culprit in this case, the attack may have simply been prevented
by sharper awareness and defensiveness. Even in the “unhackable” territory of
blockchain, there’s no shortcut for individual vigilance.
Another recent attack likewise stemmed not from protocol weakness, but
missteps taken by an external party. TheDAO hack was a very regrettable
affair: it not only resulted in net financial loss, but reflected poorly on the idea
of DAOs and undermined confidence in the Ethereum blockchain. The strong
controversy over the hard fork that resulted from theDAO hack stands as a
significant chapter in the Ethereum saga.
This incident resulted from a weakness in the smart contract written for it — not
the blockchain itself. Since its inception, Ethereum has been committed to
open source. Accordingly, it supports the type of third-party development that
was necessary to create theDAO. But there is risk associated with the creation
of third-party applications, even if the platform on which it is built has proven
strong. Developers make mistakes, especially when they’re not backed up by a
large and well-established team. Unfortunately, theDAO was an attractive
target for those who keen to exploit this type of oversight.
There’s no way to completely bypass the risk of placing assets in a network like
theDAO. However, there are certain measures that investors and end users
can take to protect themselves. First and foremost, it’s good to remember that
holding or investing your assets in a new technology does not necessarily
mean enhanced security. Instead, it may be more useful to think in terms of
different security. Traditional banks, exchanges and other forms of asset
growth and protection are liable to theft. So are those based on newer
methods? Just as you would do homework about a bank or potential stock
investment, it helps to become very savvy about the blockchain network you’re
interested in. Even if it runs on a robust platform like Ethereum, external
development projects can render it vulnerable. Learning about how it works,
and who is making it work, is important to making smart decisions about your
assets.
The aforementioned incidents demonstrate how external development can
compromise a secure blockchain. As noted, this does not have to do with the
design of the blockchain, but rather the way in which other software projects
interact with it. However, the security of the blockchain protocol itself is not
fail-proof. One potentially destructive feature of blockchain is that it’s possible
for bad actors to control a network by sheer virtue of computing power, since
all that’s required to validate a transaction is majority consensus. If more than
half of the processing power on a blockchain fell into the hands of a single
malicious entity — which could be one person controlling a number of nodes,
or a group of hackers working together — it could prove very destructive for
the other, well-intentioned members of the network.
This type of hack, known as a “51% Attack,” has not yet happened (as far as we
know). In reality, the computing power available to most people right now, it
would be extremely difficult to facilitate. And even if it did happen, it may not
be disastrous. Blockchain’s auditability means that it’s possible to quicly
detect double-spending fraud on the network. A temporarily successful 51%
attack may lead to those involved simply being kicked off the blockchain.
However, the advances in processing power provided by quantum computing
could make 51% attacks a very real threat. This has been hypothesized and
written on by many figures into the crypto community. As the widespread
adoption of quantum computing becomes more imminent, this is certainly an
issue to watch.
In short, well-known security practices are as essential to blockchain
applications as they are older technologies. It is important to remember that
all digital networks are rife with bad actors and vulnerabilities. A defensive
mindset is key to making sure your assets remain safe. If you are interested in
the long-term health of blockchain and cryptocurrency, the most important
step you can take is self-education. Being on the frontline of innovation means
keeping pace with emerging insights so you can confidently decide what
choices are best for you.

More Related Content

Recently uploaded

Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
my Pandit
 
AI Transformation Playbook: Thinking AI-First for Your Business
AI Transformation Playbook: Thinking AI-First for Your BusinessAI Transformation Playbook: Thinking AI-First for Your Business
AI Transformation Playbook: Thinking AI-First for Your Business
Arijit Dutta
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
taqyea
 
Profiles of Iconic Fashion Personalities.pdf
Profiles of Iconic Fashion Personalities.pdfProfiles of Iconic Fashion Personalities.pdf
Profiles of Iconic Fashion Personalities.pdf
TTop Threads
 
The Steadfast and Reliable Bull: Taurus Zodiac Sign
The Steadfast and Reliable Bull: Taurus Zodiac SignThe Steadfast and Reliable Bull: Taurus Zodiac Sign
The Steadfast and Reliable Bull: Taurus Zodiac Sign
my Pandit
 
CULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for dukeCULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for duke
ZevinAttisha
 
Call8328958814 satta matka Kalyan result satta guessing
Call8328958814 satta matka Kalyan result satta guessingCall8328958814 satta matka Kalyan result satta guessing
Call8328958814 satta matka Kalyan result satta guessing
➑➌➋➑➒➎➑➑➊➍
 
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
BBPMedia1
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
DearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUniDearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUni
katiejasper96
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Discover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling ServiceDiscover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling Service
obriengroupinc04
 
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Kalyan Satta Matka Guessing Matka Result Main Bazar chart
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results
 
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
taqyea
 
IMG_20240615_091110.pdf dpboss guessing
IMG_20240615_091110.pdf dpboss  guessingIMG_20240615_091110.pdf dpboss  guessing
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
jeffkluth1
 
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
valvereliz227
 
Science Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around UsScience Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around Us
PennapaKeavsiri
 

Recently uploaded (20)

Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
Unveiling the Dynamic Personalities, Key Dates, and Horoscope Insights: Gemin...
 
AI Transformation Playbook: Thinking AI-First for Your Business
AI Transformation Playbook: Thinking AI-First for Your BusinessAI Transformation Playbook: Thinking AI-First for Your Business
AI Transformation Playbook: Thinking AI-First for Your Business
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
 
Profiles of Iconic Fashion Personalities.pdf
Profiles of Iconic Fashion Personalities.pdfProfiles of Iconic Fashion Personalities.pdf
Profiles of Iconic Fashion Personalities.pdf
 
The Steadfast and Reliable Bull: Taurus Zodiac Sign
The Steadfast and Reliable Bull: Taurus Zodiac SignThe Steadfast and Reliable Bull: Taurus Zodiac Sign
The Steadfast and Reliable Bull: Taurus Zodiac Sign
 
CULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for dukeCULR Spring 2024 Journal.pdf testing for duke
CULR Spring 2024 Journal.pdf testing for duke
 
Call8328958814 satta matka Kalyan result satta guessing
Call8328958814 satta matka Kalyan result satta guessingCall8328958814 satta matka Kalyan result satta guessing
Call8328958814 satta matka Kalyan result satta guessing
 
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
NIMA2024 | De toegevoegde waarde van DEI en ESG in campagnes | Nathalie Lam |...
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
DearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUniDearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUni
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
 
Discover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling ServiceDiscover the Beauty and Functionality of The Expert Remodeling Service
Discover the Beauty and Functionality of The Expert Remodeling Service
 
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
❼❷⓿❺❻❷❽❷❼❽ Dpboss Matka Result Satta Matka Guessing Satta Fix jodi Kalyan Fin...
 
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan ChartSatta Matka Dpboss Kalyan Matka Results Kalyan Chart
Satta Matka Dpboss Kalyan Matka Results Kalyan Chart
 
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
一比一原版(QMUE毕业证书)英国爱丁堡玛格丽特女王大学毕业证文凭如何办理
 
IMG_20240615_091110.pdf dpboss guessing
IMG_20240615_091110.pdf dpboss  guessingIMG_20240615_091110.pdf dpboss  guessing
IMG_20240615_091110.pdf dpboss guessing
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
 
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
欧洲杯赌球-欧洲杯赌球买球官方官网-欧洲杯赌球比赛投注官网|【​网址​🎉ac55.net🎉​】
 
Science Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around UsScience Around Us Module 2 Matter Around Us
Science Around Us Module 2 Matter Around Us
 

Featured

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
SpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
Rajiv Jayarajah, MAppComm, ACC
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
Christy Abraham Joy
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
Vit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
MindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
GetSmarter
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
Alireza Esmikhani
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
Project for Public Spaces & National Center for Biking and Walking
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
DevGAMM Conference
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
Erica Santiago
 

Featured (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

How blockchain applications can be hacked, and what you can do to prevent it

  • 1. How Blockchain Applications Can Be Hacked, And What You Can Do To Prevent It Despite much of the early hype, blockchain applications are not “unhackable.” In the last year, a handful of highly visible attacks against blockchain-based tools served as a reminder that there’s no such thing as flawless security. Luckily, none of the recent blockchain compromises have done lasting damage to its overall public image. In fact, cryptocurrency is more popular than ever before. With this in mind, spreading awareness of blockchain security issues has become a key task for the crypto community. Following these highly public incidents, developers and end users alike are discussing ways in which cryptocurrency security can be compromised, and the various countermeasures most effective against it. The most notable cases of blockchain hacking have shown that it suffers from the same security issues of older technologies. These attacks did not result from the vulnerabilities in the blockchain itself, but the ways it was implemented by a particular company or initiative. In other words, the issue was not related to the technical protocol, but weaknesses introduced by external developers. This was certainly true in the case of Bitfinex, whose August 2016 hack resulted in the total theft of $60 million worth of BTC. The issue here was not the blockchain on which it was based, but the exchange’s specific encryption strategy. Bitfinex used multi-signature wallets for its user accounts. This works by distributing private keys between a numbers of different parties in order to minimize the risk associated with centralizing key storage. One of the keys that were distributed was obtained by a bad actor that proceeded to drain Bitfinex accounts. This not only hurt individual investors, but sent the price of Bitfinex stock tumbling by almost twenty percent. Bitfinex made early promises to repay all of its investors in full, a goal it was able to meet by April 2017. This helped to quell speculation that the exchange was compromised from within and helped rebuild its overall reputation. The repayment and overall recovery of Bitfinex marks it a success story, and today the Hong Kong-based exchange has reasserted itself as a leading cryptocurrency trading platform. The takeaway from the attack on Bitfinex is that well-known hacking methods are very much present in the cryptocurrency realm, no matter how strong the
  • 2. blockchain might be. The attack did not reveal any weaknesses in blockchain protocol itself, but a layer of encryption that was added to it. This additional protection was the site of exploitation — i.e., the place where the private key was taken. Stealing private keys has been a hacking strategy since the rise of key-based encryption, and often happens through social engineering. If social engineering was indeed the culprit in this case, the attack may have simply been prevented by sharper awareness and defensiveness. Even in the “unhackable” territory of blockchain, there’s no shortcut for individual vigilance. Another recent attack likewise stemmed not from protocol weakness, but missteps taken by an external party. TheDAO hack was a very regrettable affair: it not only resulted in net financial loss, but reflected poorly on the idea of DAOs and undermined confidence in the Ethereum blockchain. The strong controversy over the hard fork that resulted from theDAO hack stands as a significant chapter in the Ethereum saga. This incident resulted from a weakness in the smart contract written for it — not the blockchain itself. Since its inception, Ethereum has been committed to open source. Accordingly, it supports the type of third-party development that was necessary to create theDAO. But there is risk associated with the creation of third-party applications, even if the platform on which it is built has proven strong. Developers make mistakes, especially when they’re not backed up by a large and well-established team. Unfortunately, theDAO was an attractive target for those who keen to exploit this type of oversight. There’s no way to completely bypass the risk of placing assets in a network like theDAO. However, there are certain measures that investors and end users can take to protect themselves. First and foremost, it’s good to remember that holding or investing your assets in a new technology does not necessarily mean enhanced security. Instead, it may be more useful to think in terms of different security. Traditional banks, exchanges and other forms of asset growth and protection are liable to theft. So are those based on newer
  • 3. methods? Just as you would do homework about a bank or potential stock investment, it helps to become very savvy about the blockchain network you’re interested in. Even if it runs on a robust platform like Ethereum, external development projects can render it vulnerable. Learning about how it works, and who is making it work, is important to making smart decisions about your assets. The aforementioned incidents demonstrate how external development can compromise a secure blockchain. As noted, this does not have to do with the design of the blockchain, but rather the way in which other software projects interact with it. However, the security of the blockchain protocol itself is not fail-proof. One potentially destructive feature of blockchain is that it’s possible for bad actors to control a network by sheer virtue of computing power, since all that’s required to validate a transaction is majority consensus. If more than half of the processing power on a blockchain fell into the hands of a single malicious entity — which could be one person controlling a number of nodes, or a group of hackers working together — it could prove very destructive for the other, well-intentioned members of the network. This type of hack, known as a “51% Attack,” has not yet happened (as far as we know). In reality, the computing power available to most people right now, it would be extremely difficult to facilitate. And even if it did happen, it may not be disastrous. Blockchain’s auditability means that it’s possible to quicly detect double-spending fraud on the network. A temporarily successful 51% attack may lead to those involved simply being kicked off the blockchain. However, the advances in processing power provided by quantum computing could make 51% attacks a very real threat. This has been hypothesized and written on by many figures into the crypto community. As the widespread adoption of quantum computing becomes more imminent, this is certainly an issue to watch. In short, well-known security practices are as essential to blockchain applications as they are older technologies. It is important to remember that all digital networks are rife with bad actors and vulnerabilities. A defensive mindset is key to making sure your assets remain safe. If you are interested in the long-term health of blockchain and cryptocurrency, the most important step you can take is self-education. Being on the frontline of innovation means keeping pace with emerging insights so you can confidently decide what choices are best for you.