Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Crypto Platform Mistakenly Gives $90M To Users, Asks For Refund

Crypto Platform Mistakenly Gives $90M To Users, Asks For Refund

In a major blunder, cryptocurrency platform Compound accidentally paid out $90 million among its users.

Shortly after the mistake, the platform’s founder began asking users to return the money—or else they would be reported to IRS, and possibly doxxed, threatened the founder.

Platform upgrade error spills out $90 million

Compound is an Ethereum-based money market protocol that enables users to earn interest or borrow assets against collateral. Lenders can provide assets to Compound’s liquidity pool and start earning compounding interest, with interest rates dictated automatically by supply and demand.

Yesterday, due to an erroneous upgrade process, the decentralized finance (DeFi) platform ended up spilling out Ethereum assets worth $90 million to its users.

Compound’s “Comptroller” contract’s transaction history shows where all the Ethereum tokens went. 

Compound’s founder Robert Leshner urged users who received these Compound tokens in error to return the assets to the platform’s Timelock contract.

Also Read: How PII Data Works In Businesses And Its Advantages

To incentivize users, Leshner stated that for their “white-hat” behaviour they may keep 10% as a reward. 

“Otherwise, it’s being reported as income to the IRS, and most of you are doxxed,” threatened the founder in the same tweet.

And it was this last bit that may have rubbed some users the wrong way.

“Wow… this is just embarrassing – a plea wrapped in a threat, fueled by the lack of privacy,” reacted blockchain engineer Assaf Morami to Leshner’s tweet.

Also Read: How To Check Data Breach And How Can We Prevent It

“This is how to make people who would marginally be willing to help you out for your mistake keep it out of spite,” said tech entrepreneur Ryan Lackey.

I want my money back!

Following the $90-million-blunder, the value of Compound’s native token, COMP dropped by around 13% within 24 hours of Leshner’s tweet. Although, at the time of writing, the value is steadily climbing back up:

COMP token value
COMP token value dropped by around 13% following Leshner’s tweet (Coinranking)

Realizing that the original wording of his tweet may not have sat well with many, Leshner revised his tone:

“I’m trying to do anything I can to help the community get some of its COMP back, and this was a bone-headed tweet / approach. That’s on me,” said Leshner.

“Luckily, the community is much bigger, and smarter, than just me. I appreciate your ridicule and support.”

Although, you may be relieved to learn that user funds, supplied assets, borrowed assets, and positions are not impacted by this incident.

“Users don’t have to worry about their funds; the only risk is that you (or another user) receives an unfairly large quantity of COMP,” explains Leshner.

Because the Compound protocol requires a seven-day governance process before any production changes can be made, Compound’s only option at this time is to wait on users, hoping they will return the assets.

It remains yet to be seen how many users who erroneously received the crypto assets would be returning them to Compound. But, the odds look optimistic for the platform.

In two recent cryptocurrency heists, Poly Network’s attackers had returned the $611 million stolen from the DeFi platform. SushiSwap’s MISO platform was also able to recover $3 million worth of coins stolen during an insider attack.

The stark difference being, both of these incidents concerned criminal activity, followed by a successful recovery outcome. Whereas, in Compound’s case, the technical error has left the funds in the hands of honest users who, we hope, will remain honest.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us