HomeSecurityApps like Coinbase Wallet are vulnerable to “Red Pill” attacks

Apps like Coinbase Wallet are vulnerable to 'Red Pill' attacks

The Coinbase wallet and other decentralized crypto apps (dapps) were found vulnerable to “red pill attacks”, a method that can be used to hide malicious behavior of smart contracts from security features.

Red Pill coinbase
Apps like Coinbase Wallet are vulnerable to 'Red Pill' attacks

Coinbase is a leading cryptocurrency exchange that offers a cryptocurrency wallet app for storing, managing, and interacting with a wide range of digital assets that can be purchased from the platform, including Bitcoin, Ethereum , and ERC-20 tokens.

In a shocking discovery, security researchers at ZenGo Wallet have revealed that apps like Coinbase Wallet were vulnerable to an attack that allowed malicious behavior in smart contracts during simulated transactions. This tricked users into believing their transactions were safe and allowed them to continue, only to realize too late that their funds had been taken by the rogue smart contract.

After reporting the vulnerability to Coinbase, the company immediately addressed all security concerns and awarded ZenGo Wallet many bug bounties for its responsible disclosure.

Simulation Attack

Web3 smart contracts are revolutionary programs that can be executed automatically when cryptocurrency transactions occur, providing developers with a wealth of capabilities for websites and digital assets .

Smart contracts can be used for a variety of tasks, such as automatically sending an NFT to someone after payment is successfully received, imposing “taxes” on users who hold their asset after acquiring it, and even authoring content on websites depending on the transaction.

Unfortunately, however, hackers exploit smart contracts for malicious purposes, such as stealing digital currency or draining a wallet of its assets.

It can be difficult to distinguish malicious contract signing requests from genuine ones, making it challenging for cryptocurrency holders to stay safe.

To protect against these malicious attacks, application developers have developed transaction simulation solutions. This simulates what will happen when a user signs a transaction and predicts the outcome before consent is given. The result of this simulation is then presented to the user so that they can see what will happen if they choose to approve it, allowing them to make an informed decision about whether or not they want the transaction to go through.

Red Pill coinbase

However, as the ZenGo Wallet report emphasizes, some malicious smart contracts can detect when they are being simulated and exhibit non-authentic behavior so as to appear benign or profitable for the target, thus deceiving the web3 simulation security system.

Experts have warned that cybercriminals can develop strategically designed “red pills” within malicious contracts to change their behavior when they simulate and to take money from potential victims, if approved in the real world.

This destructive form of attack occurs when an attacker substitutes “malicious” data in place of the original, “safe” variables during a live transaction. It intentionally creates false security by making the smart contract appear safe and reliable in simulations, but allows crypto to be stolen by unsuspecting users during real transactions.

Apps like Coinbase Wallet are vulnerable to 'Red Pill' attacks
Apps like Coinbase Wallet are vulnerable to 'Red Pill' attacks

Through the thorough investigation of these “red pill” attack cases, ZenGo Wallet discovered that six cryptocurrency wallet dapps are vulnerable to exploitation.

These are Coinbase Wallet, Rabby Wallet, Blowfish, PocketUniverse, Fire Extension, and an anonymous extension that has not yet resolved the issue.

Red Pill coinbase

All the other providers mentioned above have applied fixes to their transaction simulation shortly after the update from ZenGo Wallet.

The solution to this attack is to stop using arbitrary values for vulnerable variables, preventing their use as “red pills” in malicious contracts.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS