Crypto Bug Hunting by Zcash, EOS, Tron, and a Backdoored Coin

EOS Hack Security
Journalist
Journalist
Sead Fadilpašić
About Author

Sead specializes in writing factual and informative articles to help the public navigate the ever-changing world of crypto. He has extensive experience in the blockchain industry, where he has served...

Last updated: 
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

Following the Cryptopia hack, the crypto community is understandably wary of any talk about security issues. However, those exist, and several have recently been unveiled: from privacy coin Zcash fixing a severe vulnerability that could have allowed malicious actors to counterfeit an infinite number of tokens, over five critical vulnerabilities discovered in smart contract platform EOS since the start of the year, to a backdoored cryptocurrency called Denarius that has been found to serve malware.

Source: iStock/PashaIgnatov

The Zcash fix was a top-secret operation

The team behind privacy coin Zcash ran into a vulnerability so severe that only four people even knew about it before a patch was released at the end of October 2018 to fix it. According to a report published Tuesday, Zcash cryptographer Ariel Gabizon discovered a “subtle” bug a little less than a year ago in zk-SNARKS, the cryptography that the project uses to shield balances and user identities. Although it has since presented no risk at all, the team has kept quiet about the bug until now, writing, “Prior to its remediation, an attacker could have created fake Zcash without being detected. The counterfeiting vulnerability has been fully remediated in Zcash and no action is required by Zcash users.”

“We have found no evidence that the vulnerability was discovered by anyone else or that counterfeiting occurred,” the report further added. In their opinion, this is because “discovery of the vulnerability would have required a high level of technical and cryptographic sophistication that very few people possess.”

The team was applauded for the way they handled the issue, perhaps most notably by infamous NSA whistleblower Edward Snowden, who tweeted: “A lot of people wonder why I like #Zcash despite the Founder’s Reward. Here’s a reason: that tax funds a quality team that catches and kills serious bugs in-house, before they get exploited. Some other projects learn about bugs like this only AFTER people have lost money.”

Not everyone agrees, however:

Zchash price chart:

Bug bounties seem to be a lucrative hobby

Smart contract and dapp (decentralized application) platform EOS is famed for their bug bounties, in which the community gets paid for helping the team find bugs and resolve them. Since the beginning of this year, they have handed over bounties for five critical vulnerabilities, according to public activity on breach disclosure platform HackerOne, which also revealed the bounties.

On January 10th, USD 40,750 was awarded to five white hat hackers on the platform by EOS.io, and the day after, another researcher received a USD 10,000 bounty. Five of a total of eight bounties are equivalent to USD 10,000 each, which is the highest possible payout reserved by the company only for the most critical vulnerabilities.

EOS, however, was not the only platform to pay out their community for bug disclosure this year. Another one of them is blockchain-based protocol TRON, which has awarded four bounties for a total of USD 22,700 in January.

The effort made by projects to stay secure while employing the help of their community is certainly commendable – but the fact that bug bounties can still make their recipients insomuch richer goes to show that these projects still have a way to go.

EOS price chart:

Why you should not reuse your password

Hackers have compromised the GitHub, a web-based hosting service that is most often used for code, account of the Denarius cryptocurrency project lead and have backdoored the Windows client with the AZORult infostealer malware, according to ZDNet. They add that they have also independently confirmed the findings. According to top developer of Denarius, Carsen Klock, the incident occurred because he reused an older password to secure his GitHub account.

Once installed on a user’s computer, this malware AZORult can steal a vast array of user data, such as browser passwords, browser cookies, passwords for FTP clients, chat histories, and most importantly, wallet database files from popular cryptocurrency clients. One security researcher who goes by the Twitter handle @prsecurity_ claims that around 3,200 users were infected. Fortunately, there have not been any 51% attacks against the Denarius blockchain yet.

The most likely scenario, ZDNet reports, is that the hackers have simply emptied users’ wallets of the cryptocurrency. However, as of the time of writing, there have been no indications of how much might have been lost this way.

Logo

Why Trust Cryptonews

2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors
editors
+ 66 More

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,512,155,955,144
13.29
Trending Crypto

More Articles

Crypto Regulation News
Is South Korea’s Digital Asset Committee About to Redefine Crypto Regulation?
Hassan Shittu
Hassan Shittu
2025-05-13 22:20:55
Press Releases
Don’t Just Survive Altcoin Season – Dominate It With Best Wallet’s Smart Tracking Tools
2025-05-13 19:20:12
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors