Skip to content
Cosmopediaby Unity Nodes
DiscussionsConversationAllnodes white label customers compromisedForum ↗

Allnodes white label customers compromised

Conversation10 posts1,465 views17 likesLast activity Feb 2023
JA
jacobgadikianOP
Jan 2023 5

Hey, I wanted to formally inform the hub community that it is completely possible that there are compromised validators on the hub. Here are some screenshots that can describe the nature of the compromise. This has been confirmed across numerous validators on Luna classic who used Allnodes as a white label provider. 1000001875 1228×1574 216 KB 1000001874 1246×1418 186 KB 1000001877 1178×962 167 KB 1000001878 1440×2121 154 KB I have also produced a Google document, which will later be made a PDF and hosted on the notional github. docs.google.com Allnodes Validators using allnodes have had their keys compromised This document is being updated in real-time. Author: Jacob Gadikian from Notional twitter.com/gadikian twitter.com/notionaldao Table of contents Validators who have been compromised by... I would like to warn the community that it seems evident that allnodes has a practice of: • Validating a new chain • Adding that chain to their orchestration system • Creating tendermint priv-validator-key.json and seed phrase for their customers • Providing neither key to their customers unless requested…

Excerpt (1194 of 3526 characters). Read the whole post on the forum ↗

AL
Alkia
Jan 2023 1

Thanks for the insight Jacob. Leaving Allnodes.

WA
Wafu50
Jan 2023 1

Hi all. I’d like to know how an existing bare metal validator could hand over validator status of their node to a second party with their own setup, without compromising security of keys? Can this be achieved? TIA.

LE
LeonoorsCryptoman
Jan 2023 1

To hand over ownership of the wallet address, you always need to pass the seed phrase.
So both parties will always be able to have a copy of the wallet address, and is hence compromised.

JA
jacobgadikian
Jan 2023 2

Hey just so you know I’m really interested in allowing this to happen by writing the necessary SDK code.

Currently it is not possible.

So right now as @LeonoorsCryptoman mentions, we can’t do that.

JC
Jcook_14
Jan 2023 1

This some next level reporting. Kudos to you. These types of risks go totally under radar without trusted sources like Notional.

SE
serejandmyself
Feb 2023 2

Im in shock that some people still redelgate to them from normal validators

JA
jacobgadikian
Feb 2023

Hey @serejandmyself – I think the reason that this is happening is that they continue to say that their operations are secure. Check out some of the screencaps here:

docs.google.com

Allnodes

Allnodes compromises 100% of their clients on most pos networks therefore there are messes on 67 chains This document originally focused on Luna classic. There is a list of affected chains below. It's everywhere. This document is being updated in...

I hope to have the censure proposal on-chain today.

JD
JD-Lorax
Feb 2023 3
jacobgadikian:

White label providers include

  • Allnodes
  • Coinbase Cloud
  • Figment

I don’t believe that these are the only white label providers on the cosmos hub.

White label validator service providers (stand to be corrected on some):

  • Figment
  • P2P Validator
  • Chorus One
  • Allnodes
  • Swiss Staking (?)
  • Staked
  • Blockdaemon
  • Coinbase Cloud
  • Polkachu (?)

I don’t know a comprehensive list of users of this service. Whitelabel Consumers:

  • Coinbase Exchange (Coinbase Cloud)
  • Kraken (Staked)
  • Zero Knowledge (Chorus One)
  • Ledger (Figment)

There are quite likely others I am not aware of. White label service providers and consumers don’t seem to be very open about their arrangements all the time.

JA
jacobgadikian
Feb 2023 1

Hey this is massively useful information and I think you get it. The lack of transparency is precisely what makes these arrangements dangerous.

← Back to Discussions