# m4rio.eth - When Web2 Ghosts Haunt Web3

- Channel: [ETHCluj Meetup](https://streameth.org/ethcluj-meetup)
- Date: 2025-11-09
- Duration: 24:31
- Watch: https://streameth.org/watch/yt-0_JLawCfwsE
- YouTube: https://www.youtube.com/watch?v=0_JLawCfwsE

## Description

In this talk, m4rio.eth shares a perspective on the latest Web2 attack in the Web3 world and discuss the still-growing Web2 attacks in Web3

## Transcript

I'm Mario. I'm a security researcher at Canina and I've been in security for a long time. I've been uh doing a lot of web to security stuff beforehand and I've been in crypto for like I don't know five six seven whatever years and um one thing uh it's keep like repeating over the years and the fact that um uh in in this world web three world is the fact that we are still not ready yet to tackle the web two components of our web three uh world. Perfect. uh I want to say a bit about uh what's what does like web two web three means people are have like various terms uh what I consider web three is basically uh smart contracts blockchain infrastructure everything that uh let's say has a trait of decentralization right you have a nodes run like by many uh parties and that's kind of like for kind of like of a decentralization right smart context which means basically code run on chain which been basically something that you cannot alter uh easily. Uh what do we consider web two? Well uh the cloud basically every other component of a product right the cloud front end back end wallet even wallets uh if they are not like something self-hosted or whatever uh and even humans right humans are some sort of like web two component uh and the key trait of uh of this is basically centralization like there is a a way you can control like a net that can control all of this and uh basically you rely on that uh entity Uh, cool. Wait, did not work. Come on. Ah, okay. Cool. Worked. Uh, I want to uh talk a bit about the web three improvements over the years. So, I've been in this field for a long time. I know exactly what what was to actually, you know, build or like do security. Back in the days in this web3 world, I had no tools. I just had know solidity in solidity remix for for those who remember solidity IDE we were in browser you were writing some sort of like weird JavaScript at the beginning because that was like solidity uh and um nowadays we got like way better like the field it's so uh uh like it grew a lot and it's understandable right uh so we have like more robust frameworks like foundry soldier hardart VM wagmi and all all of the like testing environment ments like tenderly and so on we can actually use nowadays we have actually a very strong uh security community like we have like a lot of elite auditors security reviewers uh white hat nowadays uh we have a lot of like security platforms from cantina sherlock code hog c4 unifi and you name it like many many more uh we actually have now mature infrastructure platforms right uh like from RPCs like alchemy furat roll up as a services indexes APIs we don't have only one and so on and so forth uh we have basically safer smart contracts why because we have all of this tooling that enables us new uh techniques of testing and actually uh uh let's say guarding our smart contact as to recode them uh don't forget that coding a smart contact is the first step but what you do after that testing, verifying, formal verifying, fuzzing and so on and so forth is like as important as writing the code itself. Uh we have the mature API uh EIP tooling and so on like uh we have now safer multisig we have safer like 4626 uh which basically uh lets you build on top uh and maybe expand just a bit but you can use them like out of the gate. And of course tools like you know Dune Nansen which can like bring a lot of analytics to your uh to your stack. We have also a lot of web two improvements because this is what we want to talk about. I mean over the years of course we have um a lot of like you know confidential computing uh like enclaves and so on and so forth better access control over like this cloud. You don't have just this weird console where you open a VPS. you can have like now a lot of like you know um ACL over the cloud uh you can do a lot of stuff uh authentication identity it's widespread now like back in the days we kind of like everyone build their own authentication now we kind of use these protocols which um are like well known and they're well tested uh we have also AI power thread detection nowadays uh like uh it's getting more more popular with scans a lot for for threats and so on we have a a mature DevOps pipeline right now like we have a lot of tools that are like already established and people are using so they are less prone to to to let's say uh doing like uh bugs that building and creating bug that shouldn't uh happen but uh unfortunately it's not enough. Uh why is not enough? Because if we look here at a report in 2023, uh we can see that uh is this pointer working? I'm not sure if it's working. Anyhow, you can see here that private key compromise was actually around 900 million worth of assets stolen in 2023. Fishing, it's a small 200 there. Uh code vulnerability, it's kind of there. So people focus a lot on the code vulnerability, but we have a lot of these that are actually non-code vulnerability that uh creates a lot of issues. 2024 looks even scarier if you if you if you ask me. Uh I mean if you look at the fishing I'm not sure if you can see it. H you can see it. Okay. Uh the fishing uh chart I mean it's of the charts. uh it was the main basically attack vector that uh was running in web in the web three world like fishing a lot of fishing a lot of funds lost to fishing and a lot of idea trend uh attack vectors related to fishing happened uh uh in 2024 and I want now to go through some of them so I can highlight some of these uh problems and how uh they may seem harmless uh at first but uh we can I want to showcase that web 3 is not yet know fully ready to uh to battle the web to attack vectors that happen in our world. So for example in uh 2023 mixing uh with this was a simple you know uh web to attack uh where basically they hackers breach a database of uh the cloud service provider which therefore managed to get uh access to mixins uh cloud services and there probably they had the the you know the the hot wallet key saved somewhere in where database or whatever and uh basically the hackers stole around 200 million. Uh we have multi-chain which uh again uh it's a centralized admin keys uh attack vector. This one is a weird one because um even though it had 130 mi 130 millions in losses, I think I think it's actually more because multi-chain was kind of like the bridge for every token like every token that uh wanted to bridge used multi-chain and they had a lot of high TVL tokens across many many um many many uh chains. I remember that that time a lot of like chains also suffered a lot because they multi-chain there was the only uh bridge that basically could bridge in and out of of their uh of their chain and it was also weird then because um the team wrote I think on X or something like yeah we cannot get a hold of our founder and he has all the keys and we are like okay what and I think for for like a week no one knew what happened. if I recall correctly but uh feel free to fast check everything of course and I think after a week or something uh founder sister wrote on X saying that uh yeah uh it seems that Chinese government took uh my brother and that's it and after some time fund started to you know to move and no one knew what happened at that point but basically that also meant the end of multi- chain but again centralization right um come on uh this is another one it's atomic wallet uh which uh apparently it was a malware or infrastructure some some sort bridge which managed to inject some sort of like uh um I think JavaScript and they managed to basically get the private keys of a lot of like people wallets and from there Of course they they they got a lot of funds out. Um you're going to see the Lazarus for those probably you already know that Lazarus groups is one of our main threats in web three and this was claimed by Lazarus. Let's go to 2024 uh Bitcoin DM Bitcoin um 300 millions again. Nor Lazarus group seems to be uh uh the uh the the exploiter uh they managed to again fishing malware probably because they didn't some of these especially Asian ones don't disclose exactly what happened and we are we are just guessing at this moment uh and because Lazarus is kind of known for fishing and malware operations probably that's how they manage also to get into DNM bitcoin and still around how 300 millions worth of bitcoin. Uh uh was was your ex from India? Again, this was um it's kind of like still some sort of like uh uh fishing malware infection, but they this one wasn't like just a crypto uh you know like a they store some keys and that was it. This was a bit more uh planned because what they did they basically spoofed the UI of the multisig that the founders were signing and the founders were thinking like yeah we are signing this correct multisig. Apparently they did not sign the correct transaction and uh yeah they trick the multi wallet to basically give give the hackers the controls and from there everything goes uh as uh planned for the hackers of course extracting all the the money. uh all of the previous uh attacks were let's say uh on uh centralized entities right I mean all of those like you you you've seen wallets you've seen exchanges and you can say yeah well it's c centralized of course you have a lot of uh problems because being centralized we we live in a decentralized world right but I want to say to talk a bit about the radian capital which basically it's a defy so it's a decentralized basically lives on on on blockchain uh it has smart contracts. So, it's a decentralized protocol, right? But this attack was also very uh uh interesting because uh it basically the attackers managed to trick three out of 11 multi uh signers to sign a malicious transaction and they actually used a very uh advanced technique if I may say because they managed to kind of like spoof the transaction. So for those who do not know when you sign a transaction in safe multisig sometimes it fails by these reasons nons I don't know not enough gas whatever and they manage to uh actually uh trick the signers because the signers were were kind of I mean they know what they're doing they they simulated the transaction everything look good but they simulated just the first transaction the attackers made made it fail and then they had to reschedule trans the same transaction they did not check again because right of course I already checked it. And second time they actually uh the uh devices that send the request to the hardware wallet sent a different uh basically thing to sign than what they saw previously and that basically managed to of course the goal was to transfer all machines for the multisig and from that everything got um bananas of course. So yeah uh very advanced technique. So you can see out to what lengths they go just for uh you know to steal the funds. It's not just simple uh admin key league or whatever. They actually go beyond just a simple attacks. And that's where we get to 2025 and probably everyone in this uh uh in this room knows about the bioate hack which is one of the uh most um I mean is the highest one uh in TVL and but also like very sophisticated because um let's go through I I took a bit of uh time to explain this one because it's uh uh good to understand like even at like big big uh companies that do a lot of uh uh let's say security audits and whatever it's still it's still a problem. Why? Because well uh the attackers go be beyond just a simple uh you know uh fishing attack. So uh everything happened like uh on February 21st. I remember this message from Zach saying like okay it seems that we have you know an outflow of funds from buy bit. At first I was like, "Okay, maybe just a false alarm, you know, false positive." Even though Zach kind of like never misses. Uh he did not miss this one as well. So after this, basically everything went bananas. And uh for some days, no one knew exactly how the hackers managed to get the funds out of like so so some so some so some so some so some so some so some so some so some so some so so many funds. It's not like 100 millions or whatever. It's 1.4 billions. It's crazy amount. So let's go through the you know through the phases. Well, it all started with of course Lazarus which uh they first uh compromised uh they run a social engineering attack on a on a safe multisc developer. Uh by bit was using safe multisync to to for their multisync uh solutions and they they targeted a safe multisync developer. They used a a docker project name whatever to compromise the developer Mac OS workstation. You can search more exactly how they did it. They purchased a domain previously and they spoof that domain. It's a bit more complicated but just uh wrote here a bit you know the highlight after that safe was I mean safe was not easy to break because I mean again it's not a small company they had a lot of security and stuff. the attacker tried to, you know, go straight to the AWS. They he couldn't actually because they had to FAS, but he found a way by using like temporary session tokens to uh bypass the securities uh of the of the MFA and so on. He basically for 12 days he kept you know monitoring and tried to find a way into the AWS because it wasn't that easy. Again, a safe is not a a company that doesn't know how to do security, but they didn't know how to do one thing, but I'm going to talk about that a bit later. After that, they managed to get into the using the tokens to get into the AWS S3 and inject a JavaScript code uh into the safe multisig. I mean if you think about like macro this this could have been like devast like this could basically mean end of web web three if you can say like having access to multisig uh and uh to safe multisig fronted and doing something malicious think about like all the projects I think almost all the projects in this space uh that are on the EVM are using a safe some of them are hosting their own multisig front ends but most don't So it I mean they managed to do that but they're also clever because they knew that they couldn't try it on a small project. They had to go big or go home because they knew that they will get uh uh coke if after the first you know uh attempt. So they designated a special transaction that targeted by bit probably they looked at the most you know at the most used whatever protocol that that they could drain out of and apparently by bit was their target. So they created a special the special JavaScript that targeted just bar by uh transactions. uh the other safe wallets weren't affected because they they they didn't want to to try multiple times. Uh now of course February 21st by bit was like okay everything is good uh nothing and I we just do a an a cold wallet rot rotation and that's of course when everything happened the attack enter into the uh into the play and they basically introduced some methods that basically swept everything from the multisig and uh from now from there everything went of course monitoring and so on and so forth. So yeah, uh by bit had no idea like that that could happen because their probably internal policies were like super strict about this, but they missed one thing which was did not expect that safe would actually get hacked and that they would get targeted. Come on. Uh now how I mean uh what what can we do? Well, it's kind of like there is no easy way for uh you know uh to strengthen the web two part of the web three than just work towards uh better uh policies uh better security policies on your product. uh people focused a lot on web three policies and how they you have audits you have bug bounties and so on but web two is still you know um work in progress and I've seen the request of many um after bipit of course many of our clients started to look into how can we protect also the web to part and there are like some points here use uh of course harder wallets uh never expose private keys uh do a lot of uh fishing campaigns where you train your employees uh uh on like fishing, how to respond to fishing, how to to see if it's a fishing or not. Um you need to secure of course your web infrastructure like locking the DNS, cloud configs, 2FAS everywhere. uh most important is actually adopt a zero trust principle like question everything never think that something is safe and neither dependencies browser extension everything can be compromised and the last point of course it's uh hire professionals it's very important to hire someone who can think as a a bad guy and I think that's it and my time is over &gt;&gt; perfect timing Mario thank you so much and thank you for reminding us that legacy bugs are in the system still. I noticed facing once I have so many people coming into Telegram like my wallet got drained. So, how do you respond when somebody comes in and says like my wallet just been drained because they clicked the link, they exchanged the wrong token, all these things. &gt;&gt; Well, there is not an easy response here. Well, at first I try to calm that uh I mean one thing that you have to deal with when you deal with such situation is to emotions like there are a lot of emotions and it's first important to contain the attack. Maybe he has multiple wallets. Maybe on his machine he's using multiple things. And first is to try to find the calm the victim and try to find the the root cause and contain uh further losses. And then fortunately we have to go to you know to law enforcement and work from there up. But unfortunately being blockchain is very hard nowadays. There are there were some successful campaigns and some of these uh hackers, exploiters, fishers uh have been cocked but it's very very hard. But yeah, the first thing is just to calm the victim and try to find the root cause. Nothing uh you can do at that point and maybe recover if possible, but 90% of the cases it's impossible. &gt;&gt; That's like the least I ever hear somebody getting funds back after getting a wallet drain especially. And the buy bit one I remember that one because I was sitting online and I just saw the charts start hitting the floor. It's like this is going to hurt. &gt;&gt; Yeah, exactly. So I want to ask do we have any questions from the audience sitting here today? Now is your time to actually ask about security and everything and pick his brain. There we go. &gt;&gt; Thank you. I meant to ask uh why do you think this kind of uh devastating attacks just happened in web 3 especially the buy bit one as you described it was basically they managed to infect this dependency that the by bit in this case was using. So I can uh imagine the same scenario for a bank. A bank is certainly built on some dependency be operating system or just npm packages or why is it not present there? Well, there is one one thing I can tell you is that web three evolved a lot through the years and it grew so fast that we don't have a lot of uh you know policies if I may say like in place and a lot of a lot of the founders and product people in our space adopt the fact that they want to be a corporation they don't want to they want they don't own processes they want to build as a startup and so on and so forth unfortunately you cannot build a bank as a startup uh first you have you have to go through a lot of regulations, a lot of you know things in our world unfortunately no and uh we are linked directly to the money. So it's easier for the for the attackers to attack us than a bank because bank has 10,000 I mean I've seen banks with with shitty security but uh some most of them are like enclosed and you can actually access their system and way more complicated to get into a bank system than uh plus they they I mean they have a lot of regulations that have to pass and those are means a lot of like uh testing and security reviews and so on and so forth. short while on our unfortunately uh world is still we are still not there and so that's why we are targeted because we are easy targets unfortunately. &gt;&gt; So it's because like you're saying lack of resources and preparation and uh proper processes. Yeah, exactly. All of these are I mean because that's how this world was built at first, you know, being scrappy and trying to do stuff and uh unfortunately uh we did not have time to also be mature on the tooling and processes part. We are getting better but we are still at early stages. That's why and if you look back uh back in the you know uh when the banks if I may say were like early stages you'll see a lot of problems there as well but banks are how many 40 years whatever so they had time to prepare &gt;&gt; but they could roll back and that's another thing they could roll back a bank can always scrap from a database here we can't &gt;&gt; thank you so touch.
