Industry News: Cyber

Know Your Breach: MM.Finance

Written by Cybersecurity | May 13, 2022 1:36:41 PM

The Target: MM.Finance, the largest decentralized finance platform on the Cronos blockchain.

The Take: $2 Million

The Vector: A DNS (domain name service, a server that directs users to the appropriate website upon entering the name of a site) vulnerability allowed attackers to inject a malicious website address into the code on the front-facing website as a redirected destination. When users visited the site to make transactions, they were instead sent to a bad website address where the threat actor was able to steal the funds being transacted.

This breach is an important reminder of the critical nature of user-facing website security. Any method which allows public access must be secured to the highest standard and regularly audited for potential breaches. Furthermore, monitoring and updating, if necessary, configurations of key infrastructure like DNS servers is part of maintaining a robust cybersecurity posture.

Read more...