212 похожих чатов

We'Ve detected an attack coming from Indonesia against SOLAR dVPN

infrastructure which is responsible for fiat-to-DVPN convertion.

What happened?

Today, at 17:04 Tallinn Time, our internal monitoring systems reported an unusual spike — number of the new in-app subscriptions with trial period were doubling each 5 minutes. Our team decided to investigate what is happening and what is the reason for that spike.

What we found out?

As we found out that 100% of new subscriptions with active trial period are being created from Indonesia, we've ran a search on social media and news, trying to find whether this spike is justified by some certain line of events or some online-article. According to our data, nothing like that happened.

Using benefits of blockchain transparency, we took a step further to investigate what is the pattern of the actions for newly created wallets.

We found that unknown malicious actor have created an undefined number of Google accounts and subscribed to a 7-day trial period using Google Play In-App purchases mechanism.

As our app is built in such a way that we are paying for nodes on behalf of the users while they only pay for subscription, malicious actor took advantage of it. He rolled out his own low quality nodes with a insanely high pricing per GB and started to subscribe to such nodes from newly created wallets, forcing us to deposit DVPN tokens to his nodes.

It is clear that malicious actor intention was to force us to transfer as much DVPN tokens as possible to his nodes during the trial period and cancel subscription before the first payment.

What measures we've taken?

We've temporary disabled free trial period for Android, replacing it with discount instead. During next couple days our anti-fraud mechanism will be deployed on the servers of the fiat-crypto ramp to prevent this from happening in the future. We've also taken down from the app listing malicious servers (they weren't providing VPN service itself, only gathering tokens). Normal users are not affected, app continues to operate normally.

5 ответов

12 просмотров

Why nothing in your wallet suggest that this story is true? sent1jqapaq49p4d2fel4maa9u7g6walr8pys9tkrhf Or was the attack 1k dvpn in total since 5pm? Also there are no new nodes with unusual high price

blueeyeswhitebaddragon
Why nothing in your wallet suggest that this story...

We can always look at MathNodes metabase. We archive every subscription on the Sentinel network. We'll have to see how many subscriptions were recently made, to what nodes, and what price, and how much data was consumed, and from what wallets the subscriptions took place. Feel free to investigate. Sign-up @ https://meile.app - Its free

freQniK | MathNodes
We can always look at MathNodes metabase. We archi...

Yea most expensive ones are 6k but have been used only a few times over a week ago. Next expensive are 300 which is nothing. I will look again when it updates the data for today but I doubt there will be anything that suggests that there was an attack

I think its better to banned those account, as Indonesian i pretty often found people cheating like that

freQniK | MathNodes
We can always look at MathNodes metabase. We archi...

7100 dvpn were used. No node priced above 15 dvpn

Похожие вопросы

Обсуждают сегодня

A couple thoughts from a random internet stranger: 1. If you want this project to gain traction you cannot keep being negative. If I just came here after finding out about Kd...
Eric Wild
22
Bhai mera Wazirx Account locked kr diya hei inhone to use unlock kese kru ?? Kisi ke ye problem aayi aur solve ho gayi hei to batao ?
Govind Jarwal
33
Hello guys I was wondering whether if it is OK to download the monero block chain without using tor?? Does that effect the privacy of the wallet I want to connect the monero b...
Jackisow
13
Hello, I am Ashamer from UNCX, a DeFi service provider. I am contacting you to ask if there is any room for a potential collaboration. Is there anyone whom I can potentially t...
Ashamer
19
Some news about Ocean or it's still early? 😊
Astronaut.ETH
7
I know it seems like "fud" but its just common sense imho. Blockchains in their fundamental nature distribute the value creation function to the community but in Kadena its...
Bright Uncle Stephen EqualBet
13
Hi @Ben_WG , any ETA for copy traiding or the Launch pad? I thought this was for April?
Tony
13
Hello Marines :) I'm a FTM holder but I'm looking to invest in AI projects build on FTM can anyone suggest me a site where I can see projects like these in FTM network ?
Cryptoogle
8
Is Kadena onto something special? No one really knows. Good luck!
Bright Uncle Stephen EqualBet
40
Hi guys, I want to understand how many onchain transactions I need to participate in veCRV voting/claiming/ezc. Or what is the estimate ETH cost (per month?) in low/medium/hi...
doc
9
Карта сайта