Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • Bitcoin dominance jumps above 50% as market cap enters $1.1 trillion

    TL;DR Breakdown Bitcoin’s dominance has jumped above 50% for the first time in 2 years as its market cap enters $1.1 trillion. Analysts consider factors that affect Bitcoin’s market dominance. Description Bitcoin, the leading cryptocurrency, has crossed a significant milestone as its dominance in the overall crypto market cap exceeded 50%. According to TradingView data, on June 19 at 6 pm UTC, The asset’s dominance reached just above 50%, settling at 49.9% at the time of publication. This means that the asset alone accounts for half … Read more Bitcoin, the leading cryptocurrency, has crossed a significant milestone as its dominance in the overall crypto market cap exceeded 50%. According to TradingView data, on June 19 at 6 pm UTC, The asset’s dominance reached just above 50%, settling at 49.9% at the time of publication. This means that the asset alone accounts for half of the total market capitalization of the crypto market, which currently stands at $1.1 trillion. Its market capitalization is estimated at $519 billion, as per Coingecko. Bitcoins dominance rises by 10.5% in eight months Over the…

    Article 2023年6月23日
  • China is on a mission to spread deflation worldwide

    TL;DR Breakdown China is experiencing a broad deflationary trend across various sectors. Despite rebounds, food products, home appliances, and transport prices continue to drop. China’s falling export prices raise concerns for global economies. Supply chain complexities, from production to retail, affect final consumer prices. Description The very mention of China’s growing influence is enough to get the pulse racing. But here’s the kicker: China isn’t just spreading its influence through investments or technological innovation. No, its modus operandi is far subtler. Now, the world is buzzing with the suspicion that China might be on the brink of triggering a global … Read more The very mention of China’s growing influence is enough to get the pulse racing. But here’s the kicker: China isn’t just spreading its influence through investments or technological innovation. No, its modus operandi is far subtler. Now, the world is buzzing with the suspicion that China might be on the brink of triggering a global deflation wave. Diving into China’s Deflationary Tendencies China is currently experiencing an unusual trend, with negative inflation rates splashed across various price…

    Article 2023年9月21日
  • G7 set for historic AI regulation meeting next week

    TL;DR Breakdown The Group of Seven (G7) nations are set to hold their inaugural meeting to discuss challenges posed by generative artificial intelligence (AI) tools, with topics including intellectual property protection, disinformation, and AI governance. An intergovernmental forum, known as the “Hiroshima AI process,” has been established by the G7 to foster dialogue on these issues. The meeting comes as the European Union is close to implementing significant AI legislation, prompting other governments worldwide to consider their approach to AI regulations. As the march of artificial intelligence (AI) continues globally, the Group of Seven (G7) nations are coming together to address key challenges linked to the fast-paced evolution of AI tools. The inaugural working-level meeting is scheduled to convene next week, in an effort to foster consensus on issues like intellectual property protection, disinformation, and the governance of AI technologies. G7 tackles AI: The Hiroshima AI Process In an international effort to ensure the responsible use of AI, the G7 – a political forum consisting of Canada, France, Germany, Italy, Japan, the United Kingdom, the United States, and the European…

    Article 2023年5月29日
  • Reddit’s Moons token skyrockets after Crypto.com listing

    TL;DR Breakdown Reddit’s Moons token has registered a massive increase in two days after listing on Crypto.com. Users believe the token will become a growing force. Description The native token of cryptocurrency enthusiasts on Reddit, known as Moons, has witnessed a dramatic surge in price following its listing on Crypto.com. The token’s value has soared for two consecutive days, with an impressive 141% increase in a single day, reaching a trading price of $0.41. Moons had already experienced significant gains earlier when … Read more The native token of cryptocurrency enthusiasts on Reddit, known as Moons, has witnessed a dramatic surge in price following its listing on Crypto.com. The token’s value has soared for two consecutive days, with an impressive 141% increase in a single day, reaching a trading price of $0.41. Moons had already experienced significant gains earlier when news of a potential listing on the Kraken crypto exchange surfaced. Moons token registers a 141% increase in one day Crypto.com’s decision to support Moons adds yet another prominent exchange to the list, alongside MEXC, Gate.io, SushiSwap, and RCP Swap….

    Article 2023年7月20日
  • Japan’s crypto exchanges call for relaxed margin trading restrictions to boost market growth

    TL;DR Breakdown Japanese cryptocurrency exchanges are calling for the relaxation of margin trading restrictions on popular cryptocurrencies to boost market growth. The Japan Virtual and Crypto Assets Exchange Association (JVCEA) is proposing higher leverage limits of up to 10 times the principal for retail investors. Regulators will evaluate the proposals while considering market risks and investor protection, potentially attracting institutional investors and enhancing market liquidity. Description Japan’s cryptocurrency exchanges are urging regulators to relax margin trading restrictions on popular cryptocurrencies, such as bitcoin (BTC), to stimulate market growth and attract new participants, according to a report by Bloomberg. However, the Japan Virtual and Crypto Assets Exchange Association (JVCEA), a self-regulated body of local exchanges, has proposed increasing leverage limits for retail … Read more Japan’s cryptocurrency exchanges are urging regulators to relax margin trading restrictions on popular cryptocurrencies, such as bitcoin (BTC), to stimulate market growth and attract new participants, according to a report by Bloomberg. However, the Japan Virtual and Crypto Assets Exchange Association (JVCEA), a self-regulated body of local exchanges, has proposed increasing leverage limits for retail investors…

    Article 2023年6月23日
TOP