Supply chain ⛓ Supply Chain

Komodo Third-Party Breach (June 2019)

📅 2019-06-01 🏢 not disclosed
Primary Source ↗

Incident Details

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek. A serious vulnerability has been discovered in a cryptocurrency wallet app, putting millions of dollars’ worth of user cryptocurrency at imminent risk of theft. The vulnerability was discovered in the Agama wallet app, which runs on the Komodo platform, during an independent security audit of the code this week. When alerted to the hack, the Komodo team used the same exploit to take user funds out of compromised accounts and move them to safe storage, a risky tactic that saw them effectively hack their own app to protect users. The tactic appears to have saved some 96 SegWitCoin (BTC), worth around $13 million, before a hacker stumbled over the funds.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
not disclosed
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2019-06-01 Breach occurred
  2. 2019-06-01 Publicly disclosed