212 похожих чатов

We'Ve detected an attack coming from Indonesia against SOLAR dVPN

infrastructure which is responsible for fiat-to-DVPN convertion.

What happened?

Today, at 17:04 Tallinn Time, our internal monitoring systems reported an unusual spike — number of the new in-app subscriptions with trial period were doubling each 5 minutes. Our team decided to investigate what is happening and what is the reason for that spike.

What we found out?

As we found out that 100% of new subscriptions with active trial period are being created from Indonesia, we've ran a search on social media and news, trying to find whether this spike is justified by some certain line of events or some online-article. According to our data, nothing like that happened.

Using benefits of blockchain transparency, we took a step further to investigate what is the pattern of the actions for newly created wallets.

We found that unknown malicious actor have created an undefined number of Google accounts and subscribed to a 7-day trial period using Google Play In-App purchases mechanism.

As our app is built in such a way that we are paying for nodes on behalf of the users while they only pay for subscription, malicious actor took advantage of it. He rolled out his own low quality nodes with a insanely high pricing per GB and started to subscribe to such nodes from newly created wallets, forcing us to deposit DVPN tokens to his nodes.

It is clear that malicious actor intention was to force us to transfer as much DVPN tokens as possible to his nodes during the trial period and cancel subscription before the first payment.

What measures we've taken?

We've temporary disabled free trial period for Android, replacing it with discount instead. During next couple days our anti-fraud mechanism will be deployed on the servers of the fiat-crypto ramp to prevent this from happening in the future. We've also taken down from the app listing malicious servers (they weren't providing VPN service itself, only gathering tokens). Normal users are not affected, app continues to operate normally.

5 ответов

32 просмотра

Why nothing in your wallet suggest that this story is true? sent1jqapaq49p4d2fel4maa9u7g6walr8pys9tkrhf Or was the attack 1k dvpn in total since 5pm? Also there are no new nodes with unusual high price

blueeyeswhitebaddragon
Why nothing in your wallet suggest that this story...

We can always look at MathNodes metabase. We archive every subscription on the Sentinel network. We'll have to see how many subscriptions were recently made, to what nodes, and what price, and how much data was consumed, and from what wallets the subscriptions took place. Feel free to investigate. Sign-up @ https://meile.app - Its free

freQniK | MathNodes
We can always look at MathNodes metabase. We archi...

Yea most expensive ones are 6k but have been used only a few times over a week ago. Next expensive are 300 which is nothing. I will look again when it updates the data for today but I doubt there will be anything that suggests that there was an attack

I think its better to banned those account, as Indonesian i pretty often found people cheating like that

Похожие вопросы

Обсуждают сегодня

@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Hello, Is iExec also part of the "inception program" or another one ? Would it be a name to qualified the nature of the relationship between iExec and Nvidia? And does Secret ...
Ñïķøłäś
8
Ready for some fun AND a chance to win TKO Tokens? Join us for exciting minigames in our Telegram group! 🕒 Don’t miss out—games start on today 25 October 2024, at 8 PM! Ge...
Milkyway | Tokocrypto
255
any reference of this implementation?
BitBuddha
29
Also, why can’t the community have a vote/ say when it comes to initiatives like buybacks. Isn’t the point of crypto decentralisation? Don’t we deserve input as long term supp...
👨🏽‍🦰
13
Hi guys, any problem with Pulsebrige? Trying to transfer from wETH to ETH. First it tells me to connect my metamask "through mobile app" not desktop. Then I did and confirmed ...
Snowflakecrypto
13
Карта сайта