McAfee Highlights Emerging Cybersecurity Risks Associated with Blockchain

Raj Samani Chief Scientist and McAfee Fellow, Advanced Threat Research.
6 years ago

McAfee released a report detailing the numerous cybersecurity risks associated with blockchain-based cryptocurrencies, and asserts the necessity of making cybersecurity a top priority as industry builds out the foundations for the widespread implementation of blockchain technologies.

The blockchain technology market is expected to reach $9.6 billion by 2024, McAfee sees tremendous potential for cybersecurity risks that could threaten this revolutionary technology’s rapid growth and its quickly expanding pool of adopters. The company points to security events associated with cryptocurrencies, the area where blockchain technology has been most extensively implemented and used at large scale by millions of people.

According to the McAfee report, bad actors have aggressively sought to take advantage of the rapid adoption of cryptocurrencies and the early adopters who use them. McAfee sees this activity in four key attack vectors: phishing or fraud schemes, malware, implementation exploits, and technology vulnerabilities. Many attacks spanning these categories apply both old and new cybercrime techniques and have proven highly lucrative for cybercriminals.

The McAfee report details a 2017 cryptocurrency phishing scam in which a cybercriminal set up a fraudulent cryptocurrency “wallet” service. After collecting authentication information from the service’s users over the course of six months, the thief drained $4 million from unsuspecting customers’ accounts.

McAfee research illustrates the growing trends of malicious miners and cryptojacking, which create a vector for infection (via malware) and monetization (via mining). Recent McAfee Labs research in this cybercrime category found that total coin miner malware grew a stunning 629% in Q1 2018—from around 400,000 samples in Q4 2017 to more than 2.9 million samples in the first quarter of this year.

“Given blockchain’s potential for creating value, and the tremendous enthusiasm to implement it, cybercriminals will seek every opportunity to strike at all available technical and human vulnerabilities in the emerging blockchain ecosystem. Governments, cybersecurity vendors, and businesses must be diligent in understanding the threats and minimizing the risks. Without adequate education for users and industry, secure implementation best practices, and strong technical security standards, the widespread adoption of blockchain by major industries and governments could end up costing billions of dollars and impacting millions of people.” said Raj Samani, chief scientist at McAfee.