Connect with us

News

Improving security levels in Blockchain technology

BlockChainGuardian Staff

Published

on

blockchain

Blockchain technology has progressed significantly since the Bitcoin whitepaper was published in 2008. Since then, we have seen numerous cryptocurrencies emergeas well as non-financial projects using blockchain.

Although one of the biggest advantages of blockchain is its security, you need to pay attention to some risks. From phishing attacks to account takeover (ATO) frauds, blockchain projects must work extensively on their security to prevent these attacks from succeeding.

Of course, just as new technologies emerge that aim to protect individuals and businesses, so do new cybersecurity threats. This article will explain blockchain security in depth and analyze some of the most common problems that blockchain faces.

Blockchain security explained

blockchain

A blockchain it is a digital ledger that stores large amounts of transactions and data. The registry is managed by a distributed network of computers we call nodes. The characteristic of the blockchain is that it is decentralized.

Instead of being stored in a single location, the data is dispersed across the aforementioned network of nodes. Decentralization makes the network secure, because even in the event of a failure, the other nodes will still maintain safe and accurate copies of the data. Furthermore, data on the blockchain cannot be tampered with or deleted.

The “cryptocurrency” in “cryptocurrency” refers to the use of cryptographic algorithms that protect every transaction. Each transaction is grouped into “blocks” and is linked to previous blocks, creating a chain of blocks that links back to the first block of the blockchain.

Each block is validated by a number of nodes, preventing any single entity from manipulating the data. How the transaction is agreed upon depends on the blockchain consensus mechanism and the type of blockchain. The two most popular consensus mechanisms are Proof of Work (e.g. Bitcoin) and Proof-of-Stake (e.g. Ethereum).

Public blockchains are transparent and allow anyone to see transaction history. Transparency builds trust among users, although some users may find it intrusive.

The immutability of each transaction is seen as both an advantage and a disadvantage. While this makes transactions quite secure, in the event of an incorrectly executed transaction, the amount of cryptocurrency involved will be lost. Also, if someone takes control of your account and makes a certain transaction, you won’t be able to refund it.

Different types of blockchains and their security

There are different types of blockchains that address security and permissions differently. They are not inherently more or less safe, as each has specific uses and benefits. The two most popular types are public and private blockchains, but we will also touch on the rarer types.

Public blockchains

As the name suggests, anyone can access public blockchains. They are permissionless and anyone with an internet connection and a computer can become a validator. Does this lead to a less safe environment? Not exactly.

Examples of public blockchains are Bitcoin and Ethereum. Since they are open source, anyone can look at the code and collaborate with other developers to improve it. Just like validation, no single entity is responsible for the security of the blockchain.

Instead, developer communities constantly work to improve the code, examine vulnerabilities, and suggest changes. This leads to a network that is highly secure and resistant to different types of attacks.

However, the downside is that hackers and bad actors also have great insight into the code. This means they can also work tirelessly to find vulnerabilities to exploit.

Private blockchains

Opposite the public blockchains, we have the private ones. They are more strictly regulated and not everyone can join them. They are authorized and are not decentralized like public ones.

They are also managed by a single organizationtion. The entity that manages the private blockchain is responsible for its security. Because the network requires users to have permission to participate, private blockchains are much faster than public ones.

Only users who have the appropriate permissions can validate transactions and make changes to the network. This type of blockchain is usually used for internal needs by organizations and companies.

Other types of blockchain

The two least common types of blockchain used are hybrid and consortium blockchains. They do not have a revolutionary, radically different concept. Instead, they are both combinations of private and public blockchains.

A consortium blockchain is a network operated by a number of different organizations. Because they use a combination of private and public concepts, they distribute access across pre-selected nodes. Examples of this blockchain are Quorum and R3.

The hybrid, however, is managed by a single company. However, they selectively use a combination of public and private blockchains. Some data is stored in the public registry, while only some people have private access.

Tracking blockchain transactions

Blockchain security systems present by default are not the only way to protect your project and your users. Concepts like smart contracts and validators do a great job of ensuring security, but sometimes risks can arise from other sources.

One method to increase security is ATO detection. This method uses third-party software that will analyze every transaction that occurs. If you integrate your platform with such software, you can protect your users from becoming victims of malicious individuals.

Transaction monitoring uses a number of factors to decide whether a transaction is fraudulent or not. This may be a transaction involving a significant sum or an irregular transaction frequency.

Hackers can obtain a user’s wallet or account from a platform in numerous ways. They can target a user via phishing attacks or hack them through other means. On the other hand, compromised accounts can be obtained on black markets.

A crypto project is not responsible if a user voluntarily loses their credentials, but should still do what it can to protect the user. Transaction monitoring is there to stop problematic activity and accounts before it’s too late. But before the worst case scenario, it is important to implement strong authentication and educate users.

Risks of blockchain transactions

Hackers often find cryptocurrency projects to be a great way to conduct scams. Malicious actions can be carried out in the form of creating phishing sites based on certain cryptocurrency projects.

On the other hand, crypto projects can themselves be fraudulent. Scammers can create a project, and once it has gained traction and enough investors, they sell their tokens and abandon the project.

From the user’s point of view, he must pay attention to the reviews of a particular project and the people behind it. If there are no people with real experience and social media profiles, the project is likely a scam.

Companies looking to create blockchain-based projects need to put users at ease and follow some transparent practices to ensure trust. In addition to choosing the right type of blockchain and creating a secure website, it is important to have strong cybersecurity protocols.

No external threat should be able to compromise your project and harm your users or the project itself.

Although one of the most important advantages of blockchain is decentralization, there is a certain degree of centralization in crypto projects. The infrastructure that hosts your project needs professionals to maintain it and guarantee high levels of security.

Blockchain compliance

Since blockchain is closely connected to finance, there are many regulations that companies must comply with. In the context of blockchain security, strictly following these regulations will lead to greater security.

Failure to comply with financial regulations can lead to a fine or even closure of your company. Depending on your location, you must adhere to local regulations anti-money laundering (AML) laws.as well as the laws of the countries in which you operate.

Additional security measures, such as transaction monitoring, can significantly help you make your project more compliant overall. There are also industry regulations that may apply to your project.

For example, if you use blockchain in the healthcare industry, your company will also need to deal with regulations related to patient data and healthcare.

Protect your blockchain projects

Using blockchain to improve your company’s security is a viable option. Blockchain offers decentralized, transparent records that are difficult, almost impossible, to tamper with. However, you should always stay updated on the latest trends in cybersecurity and blockchain.

With the advent of artificial intelligence, there are new ways to protect business systems. But the most important thing is to conduct security checks that will help you understand how your company is exposed and which aspects need additional security.

Fuente

We are the editorial team of BlockChainGuardian, where seriousness meets clarity in cryptocurrency analysis. With a robust team of finance and blockchain technology experts, we are dedicated to meticulously exploring complex crypto markets with detailed assessments and an unbiased approach. Our mission is to democratize access to knowledge of emerging financial technologies, ensuring they are understandable and accessible to all. In every article on BlockChainGuardian, we strive to provide content that not only educates, but also empowers our readers, facilitating their integration into the financial digital age.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Información básica sobre protección de datos Ver más

  • Responsable: Miguel Mamador.
  • Finalidad:  Moderar los comentarios.
  • Legitimación:  Por consentimiento del interesado.
  • Destinatarios y encargados de tratamiento:  No se ceden o comunican datos a terceros para prestar este servicio. El Titular ha contratado los servicios de alojamiento web a Banahosting que actúa como encargado de tratamiento.
  • Derechos: Acceder, rectificar y suprimir los datos.
  • Información Adicional: Puede consultar la información detallada en la Política de Privacidad.

News

Terra Can’t Catch a Break as Blockchain Gets $6 Million Exploited

BlockChainGuardian Staff

Published

on

Terra Can't Catch a Break as Blockchain Gets $6 Million Exploited

The attack, which exploited a vulnerability disclosed in April, drained around 60 million ASTRO tokens, sending the price plummeting.

The Terra blockchain has been exploited for over $6 million, forcing developers to take a momentary break the chain.

Beosin Cyber ​​Security Company reported that the protocol lost 60 million ASTRO tokens, 3.5 million USDC, 500,000 USDT, and 2.7 BTC or $180,000.

Terra developers paused the chain on Wednesday morning to apply an emergency patch that would address the attack. Moments later, a 67% majority of validators upgraded their nodes and resumed block production.

The ASTRO token has plunged as much as 75%. It is now trading at $0.03, a 25% decline on the day. Traders who took advantage of the drop are now on 195%.

ASTRO Price ChartASTRO Price

The vulnerability that took down the Cosmos-based blockchain was disclosed in April and involved the deployment of a malicious CosmWasm contract. It opened the door to attacks via what is called an “ibc-hooks callback timeout reentrancy vulnerability,” which is used to invoke contracts and enable cross-chain swaps.

Terra 2.0 also suffered a massive drop in total value locked (TVL) in April, shortly after the vulnerability was discovered. It plunged 80% to $6 million from $30 million in TVL and has since lost nearly half of that value, currently sitting at $3.9 million.

The current Earth chain emerged from the rubble as a hard fork after the original blockchain, now called Terra Classic, collapsed in 2022. Terra collapsed after its algorithmic stablecoin (UST) lost its peg, causing a run on deposits. More than $50 billion of UST’s market cap was wiped out in a matter of days.

Terraform Labs, the company behind the blockchain, has been slowly unravelling its legal woes since its mid-2022 crash. Founder Do Kwon awaits sentencing in Montenegro after he and his company were found liable for $40 billion in customer funds in early April.

On June 12, Terraform Labs settled with the SEC for $4.4 billion, for which the company will pay about $3.59 billion plus interest and a $420 million penalty. Meanwhile, Kwon will pay $204.3 million, including $110 million in restitution, interest and an $80 million penalty, a court filing showed.

Fuente

Continue Reading

News

Google and Coinbase Veterans Raise $5M to Build Icebreaker, Blockchain’s Answer to LinkedIn

BlockChainGuardian Staff

Published

on

Google and Coinbase Veterans Raise $5M to Build Icebreaker, Blockchain's Answer to LinkedIn

Icebreaker: Think LinkedIn but on a Blockchain—announced Wednesday that it has secured $5 million in seed funding. CoinFund led the round, with participation from Accomplice, Anagram, and Legion Capital, among others.

The company, which is valued at $21 million, aims to become the world’s first open-source network for professional connections. Its co-founders, Dan Stone and Jack Dillé, come from Google AND Monetary base; Stone was a product manager at the cryptocurrency giant and also the co-creator of Google’s largest multi-identity measurement and marketing platform, while Dillé was a design manager for Google Working area.

The pair founded Icebreaker on the shared belief that the imprint of one’s digital identity (and reputation) should not be owned by a single entity, but rather publicly owned and accessible to all. Frustrated that platforms like LinkedIn To limit how we leverage our connections, Dillé told Fortune he hopes to remove paywalls and credits, which “force us to pay just to browse our network.” Using blockchain technology, Icebreaker lets users transfer their existing professional profile and network into a single, verified channel.

“Imagine clicking the login button and then seeing your entire network on LinkedIn, ChirpingFarcaster and email? Imagine how many introductions could be routed more effectively if you could see the full picture of how you’re connected to someone,” Stone told Fortune.

Users can instantly prove their credentials and provide verifiable endorsements for people in their network. The idea is to create an “open graph of reputation and identity,” according to the founders. They hope to challenge LinkedIn’s closed network that “secures data,” freeing users to search for candidates and opportunities wherever they are online. By building on-chain, the founders note, they will create a public ledger of shared context and trust.

“Digital networking is increasingly saturated with noise and AI-driven fake personas,” the founders said in a statement. For example: Dillé’s LinkedIn headline reads “CEO of Google,” a small piece of digital performance art to draw attention to unverifiable information on Web2 social networks that can leave both candidates and recruiters vulnerable to false claims.

“Icebreaker was created to enable professionals to seamlessly tap into their existing profiles and networks to surface exceptional people and opportunities, using recent advances in cryptographically verifiable identity,” the company said, adding that the new funding will go towards expanding its team and developing products.

“One of the next significant use cases for cryptocurrency is the development of fundamental social graphs for applications to leverage… We are proud to support Dan, Jack and their team in their mission to bring true professional identity ownership to everyone online,” said CoinFund CIO Alex Felix in a statement.

Learn more about all things cryptocurrency with short, easy-to-read flashcards. Click here to Fortune’s Crash Course in Cryptocurrency.

Fuente

Continue Reading

News

Luxembourg proposes updates to blockchain laws | Insights and resources

BlockChainGuardian Staff

Published

on

Luxembourg proposes updates to blockchain laws | Insights and resources

On July 24, 2024, the Ministry of Finance proposed Blockchain Bill IVwhich will provide greater flexibility and legal certainty for issuers using Distributed Ledger Technology (DLT). The bill will update three of Luxembourg’s financial laws, the Law of 6 April 2013 on dematerialised securitiesTHE Law of 5 April 1993 on the financial sector and the Law of 23 December 1998 establishing a financial sector supervisory commissionThis bill includes the additional option of a supervisory agent role and the inclusion of equity securities in dematerialized form.

DLT and Luxembourg

DLT is increasingly used in the financial and fund management sector in Luxembourg, offering numerous benefits and transforming various aspects of the industry.

Here are some examples:

  • Digital Bonds: Luxembourg has seen multiple digital bond issuances via DLT. For example, the European Investment Bank has issued bonds that are registered, transferred and stored via DLT processes. These bonds are governed by Luxembourg law and registered on proprietary DLT platforms.
  • Fund Administration: DLT can streamline fund administration processes, offering new opportunities and efficiencies for intermediaries, and can do the following:
    • Automate capital calls and distributions using smart contracts,
    • Simplify audits and ensure reporting accuracy through transparent and immutable transaction records.
  • Warranty Management: Luxembourg-based DLT platforms allow clients to swap ownership of baskets of securities between different collateral pools at precise times.
  • Tokenization: DLT is used to tokenize various assets, including real estate and luxury goods, by representing them in a tokenized and fractionalized format on the blockchain. This process can improve the liquidity and accessibility of traditionally illiquid assets.
  • Tokenization of investment funds: DLT is being explored for the tokenization of investment funds, which can streamline the supply chain, reduce costs, and enable faster transactions. DLT can automate various elements of the supply chain, reducing the need for reconciliations between entities such as custodians, administrators, and investment managers.
  • Issuance, settlement and payment platforms:Market participants are developing trusted networks using DLT technology to serve as a single source of shared truth among participants in financial instrument investment ecosystems.
  • Legal framework: Luxembourg has adapted its legal framework to accommodate DLT, recognising the validity and enforceability of DLT-based financial instruments. This includes the following:
    • Allow the use of DLT for the issuance of dematerialized securities,
    • Recognize DLT for the circulation of securities,
    • Enabling financial collateral arrangements on DLT financial instruments.
  • Regulatory compliance: DLT can improve transparency in fund share ownership and regulatory compliance, providing fund managers with new opportunities for liquidity management and operational efficiency.
  • Financial inclusion: By leveraging DLT, Luxembourg aims to promote greater financial inclusion and participation, potentially creating a more diverse and resilient financial system.
  • Governance and ethics:The implementation of DLT can promote higher standards of governance and ethics, contributing to a more sustainable and responsible financial sector.

Luxembourg’s approach to DLT in finance and fund management is characterised by a principle of technology neutrality, recognising that innovative processes and technologies can contribute to improving financial services. This is exemplified by its commitment to creating a compatible legal and regulatory framework.

Short story

Luxembourg has already enacted three major blockchain-related laws, often referred to as Blockchain I, II and III.

Blockchain Law I (2019): This law, passed on March 1, 2019, was one of the first in the EU to recognize blockchain as equivalent to traditional transactions. It allowed the use of DLT for account registration, transfer, and materialization of securities.

Blockchain Law II (2021): Enacted on 22 January 2021, this law strengthened the Luxembourg legal framework on dematerialised securities. It recognised the possibility of using secure electronic registration mechanisms to issue such securities and expanded access for all credit institutions and investment firms.

Blockchain Act III (2023): Also known as Bill 8055, this is the most recent law in the blockchain field and was passed on March 14, 2023. This law has integrated the Luxembourg DLT framework in the following way:

  • Update of the Act of 5 August 2005 on provisions relating to financial collateral to enable the use of electronic DLT as collateral on financial instruments registered in securities accounts,
  • Implementation of EU Regulation 2022/858 on a pilot scheme for DLT-based market infrastructures (DLT Pilot Regulation),
  • Redefining the notion of financial instruments in Law of 5 April 1993 on the financial sector and the Law of 30 May 2018 on financial instruments markets to align with the corresponding European regulations, including MiFID.

The Blockchain III Act strengthened the collateral rules for digital assets and aimed to increase legal certainty by allowing securities accounts on DLT to be pledged, while maintaining the efficient system of the 2005 Act on Financial Collateral Arrangements.

With the Blockchain IV bill, Luxembourg will build on the foundations laid by previous Blockchain laws and aims to consolidate Luxembourg’s position as a leading hub for financial innovation in Europe.

Blockchain Bill IV

The key provisions of the Blockchain IV bill include the following:

  • Expanded scope: The bill expands the Luxembourg DLT legal framework to include equity securities in addition to debt securities. This expansion will allow the fund industry and transfer agents to use DLT to manage registers of shares and units, as well as to process fund shares.
  • New role of the control agent: The bill introduces the role of a control agent as an alternative to the central account custodian for the issuance of dematerialised securities via DLT. This control agent can be an EU investment firm or a credit institution chosen by the issuer. This new role does not replace the current central account custodian, but, like all other roles, it must be notified to the Commission de Surveillance du Secteur Financier (CSSF), which is designated as the competent supervisory authority. The notification must be submitted two months after the control agent starts its activities.
  • Responsibilities of the control agent: The control agent will manage the securities issuance account, verify the consistency between the securities issued and those registered on the DLT network, and supervise the chain of custody of the securities at the account holder and investor level.
  • Simplified payment processesThe bill allows issuers to meet payment obligations under securities (such as interest, dividends or repayments) as soon as they have paid the relevant amounts to the paying agent, settlement agent or central account custodian.
  • Simplified issuance and reconciliationThe bill simplifies the process of issuing, holding and reconciling dematerialized securities through DLT, eliminating the need for a central custodian to have a second level of custody and allowing securities to be credited directly to the accounts of investors or their delegates.
  • Smart Contract Integration:The new processes can be executed using smart contracts with the assistance of the control agent, potentially increasing efficiency and reducing intermediation.

These changes are expected to bring several benefits to the Luxembourg financial sector, including:

  • Fund Operations: Greater efficiency and reduced costs by leveraging DLT for the issuance and transfer of fund shares.
  • Financial transactions: Greater transparency and security.
  • Transparency of the regulatory environment: Increased attractiveness and competitiveness of the Luxembourg financial centre through greater legal clarity and flexibility for issuers and investors using DLT.
  • Smart Contracts: Potential for automation of contractual terms, reduction of intermediaries and improvement of transaction traceability through smart contracts.

Blockchain Bill IV is part of Luxembourg’s ongoing strategy to develop a strong digital ecosystem as part of its economy and maintain its status as a leading hub for financial innovation. Luxembourg is positioning itself at the forefront of Europe’s growing digital financial landscape by constantly updating its regulatory framework.

Local regulations, such as Luxembourg law, complement European regulations by providing a more specific legal framework, adapted to local specificities. These local laws, together with European initiatives, aim to improve both the use and the security of projects involving new technologies. They help establish clear standards and promote consumer trust, while promoting innovation and ensuring better protection against potential risks associated with these emerging technologies. Check out our latest posts on these topics and, for more information on this law, blockchain technology and the tokenization mechanism, do not hesitate to contact us.

We are available to discuss any project related to digital finance, cryptocurrencies and disruptive technologies.

This informational piece, which may be considered advertising under the ethics rules of some jurisdictions, is provided with the understanding that it does not constitute the rendering of legal or other professional advice by Goodwin or its attorneys. Past results do not guarantee a similar outcome.

Fuente

Continue Reading

News

New bill pushes Department of Veterans Affairs to examine how blockchain can improve its work

BlockChainGuardian Staff

Published

on

New bill pushes Department of Veterans Affairs to examine how blockchain can improve its work

The Department of Veterans Affairs would have to evaluate how blockchain technology could be used to improve benefits and services offered to veterans, according to a legislative proposal introduced Tuesday.

The bill, sponsored by Rep. Nancy Mace, R-S.C., would direct the VA to “conduct a comprehensive study of the feasibility, potential benefits, and risks associated with using distributed ledger technology in various programs and services.”

Distributed ledger technology, including blockchain, is used to protect and track information by storing data across multiple computers and keeping a record of its use.

According to the text of the legislation, which Mace’s office shared exclusively with Nextgov/FCW ahead of its publication, blockchain “could significantly improve benefits allocation, insurance program management, and recordkeeping within the Department of Veterans Affairs.”

“We need to bring the federal government into the 21st century,” Mace said in a statement. “This bill will open the door to research on improving outdated systems that fail our veterans because we owe it to them to use every tool at our disposal to improve their lives.”

Within one year of the law taking effect, the Department of Veterans Affairs will be required to submit a report to the House and Senate Veterans Affairs committees detailing its findings, as well as the benefits and risks identified in using the technology.

The mandatory review is expected to include information on how the department’s use of blockchain could improve the way benefits decisions are administered, improve the management and security of veterans’ personal data, streamline the insurance claims process, and “increase transparency and accountability in service delivery.”

The Department of Veterans Affairs has been studying the potential benefits of using distributed ledger technology, with the department emission a request for information in November 2021 seeking input from contractors on how blockchain could be leveraged, in part, to streamline its supply chains and “secure data sharing between institutions.”

The VA’s National Institute of Artificial Intelligence has also valued the use of blockchain, with three of the use cases tested during the 2021 AI tech sprint focused on examining its capabilities.

Mace previously introduced a May bill that would direct Customs and Border Protection to create a public blockchain platform to store and share data collected at U.S. borders.

Lawmakers also proposed additional measures that would push the Department of Veterans Affairs to consider adopting other modernized technologies to improve veteran services.

Rep. David Valadao, R-Calif., introduced legislation in June that would have directed the department to report to lawmakers on how it plans to expand the use of “certain automation tools” to process veterans’ claims. The House of Representatives Subcommittee on Disability Assistance and Memorial Affairs gave a favorable hearing on the congressman’s bill during a Markup of July 23.



Fuente

Continue Reading

Trending

Copyright © 2024 BLOCKCHAINGUARDIAN.NET. All rights reserved. This website provides educational content and highlights that investing involves risks. It is essential to conduct thorough research before investing and to be prepared to assume potential losses. Be sure to fully understand the risks involved before making investment decisions. Important: We do not provide financial or investment advice. All content is presented for educational purposes only.