Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • Bitcoin is CPI resistant, with a slight drop to around $29.5K

    TL;DR Breakdown Bitcoin seems unaffected by the latest CPI data, which showed a modest amount of CPI growth that was in line with what economists predicted. Aside from macroeconomic factors, analysts continue to debate why Bitcoin won’t budge above $30,000. The U.S. headline CPI released by the Labor Department on Thursday gained 0.2% in July, raising the inflation indicator to 3.2%. Description Bitcoin and ether open unchanged in Asia, undoubtedly unaffected by the latest Consumer Price Index (CPI) data. The two largest cryptocurrencies continue to withstand macro-scale surges. CPI is one of the Federal Reserve’s primary considerations when determining interest rate policy. Last month’s June report was the lowest in two years, and broad expectations point to … Read more Bitcoin and ether open unchanged in Asia, undoubtedly unaffected by the latest Consumer Price Index (CPI) data. The two largest cryptocurrencies continue to withstand macro-scale surges. CPI is one of the Federal Reserve’s primary considerations when determining interest rate policy. Last month’s June report was the lowest in two years, and broad expectations point to another decline in July. And…

    Article 2023年8月11日
  • Has the U.S. economy reached its tipping point?

    TL;DR Breakdown U.S. businesses facing rising costs, labor crunch, supply chain issues. Florida’s economy defies trend, showing robust growth. Aggressive interest rate hikes by Federal Reserve causing concern. Navigating through a tumultuous period marked by surging costs, supply chain hiccups, and a severe labor crunch, businesses across the U.S. are weathering an economic storm. Mike Zaffaroni, the head of Liberty Landscape Supply in northeast Florida, found the past year more grueling than both the Great Recession and the initial impact of the 2020 global pandemic. However, undeterred customers helped the company’s revenue surge by 16% compared to the previous year. Looking into Florida’s robust economy Contrary to the overall U.S. trend, Florida’s economy has been demonstrating incredible resilience. The state, benefitting from its unique geographical and tax advantages, has seen a significant population and business boom, keeping its unemployment rate at a mere 2.6%. Despite this robust performance, the U.S. economy’s tenacity has started to show signs of strain, stoking concerns among analysts and business owners. Mike Zaffaroni’s warning about the precarious future for the second half of 2023 may…

    Article 2023年6月15日
  • US lawmaker grills SEC over SBF’s arrest papers

    TL;DR Breakdown Michigan Representative Bill Huizenga criticizes the SEC for insufficiently providing relevant documents related to SBF’s arrest. He suggests the SEC failed to meet a deadline to produce documents concerning the arrest and charges against SBF, former FTX CEO. The SEC defended its actions, with General Counsel Megan Barbero stating that document compilation was a significant process. Description A palpable tension exists in Washington as Bill Huizenga, the Representative of Michigan, directly challenges the Securities and Exchange Commission (SEC) over its handling of the case involving Sam Bankman-Fried (SBF), the former CEO of FTX. He specifically accused the regulatory body of failing to provide adequate documentation related to SBF’s arrest. Congressional criticism of … Read more A palpable tension exists in Washington as Bill Huizenga, the Representative of Michigan, directly challenges the Securities and Exchange Commission (SEC) over its handling of the case involving Sam Bankman-Fried (SBF), the former CEO of FTX. He specifically accused the regulatory body of failing to provide adequate documentation related to SBF’s arrest. Congressional criticism of SEC efficacy Huizenga, who heads the U.S. House…

    Article 2023年6月25日
  • SEC Vs. Ripple case: Legal experts caution against premature celebrations

    TL;DR Breakdown Ripple achieves a partial victory in the legal battle against the SEC as the court ruling deems past direct XRP sales to institutional clients as securities. Legal experts caution that the fight may not be over, with potential appeals and a shift towards the need for updated regulations in the cryptocurrency space. Market responds positively to Ripple’s win, with XRP price surging and reaching the 38.2% Fibonacci retracement level, while the industry awaits further developments. Description Ripple Labs, the company behind the cryptocurrency XRP, achieved a significant partial victory in its long-standing legal battle against the U.S. Securities and Exchange Commission (SEC). The decision, delivered by Judge Analisa Torres at the United States District Court in the Southern District of New York, sent shockwaves throughout the crypto industry, signaling potential implications … Read more Ripple Labs, the company behind the cryptocurrency XRP, achieved a significant partial victory in its long-standing legal battle against the U.S. Securities and Exchange Commission (SEC). The decision, delivered by Judge Analisa Torres at the United States District Court in the Southern District of…

    Article 2023年7月15日
  • FTX Defended by Sequoia Partner Despite Bankruptcy, Investment Stance Upheld

    TL;DR Breakdown Sequoia Capital’s Alfred Lin reaffirms the firm’s investment in the bankrupt FTX crypto exchange, stating they would make the same decision again if given the opportunity. Despite suffering a financial loss, Sequoia maintains its enthusiasm for the crypto sector, emphasizing the importance of taking calculated risks and trusting visionary founders. Description Venture capitalist Alfred Lin, a partner at Sequoia Capital, recently defended the firm’s significant investment in the now-bankrupt cryptocurrency exchange FTX. Despite the exchange’s collapse and subsequent loss of funds, Lin expressed confidence in the decision, stating that if given the opportunity, Sequoia would likely make the same investment again. This reaffirms Sequoia’s commitment to … Read more Venture capitalist Alfred Lin, a partner at Sequoia Capital, recently defended the firm’s significant investment in the now-bankrupt cryptocurrency exchange FTX. Despite the exchange’s collapse and subsequent loss of funds, Lin expressed confidence in the decision, stating that if given the opportunity, Sequoia would likely make the same investment again. This reaffirms Sequoia’s commitment to trusting founders and taking calculated risks, even in the volatile world of cryptocurrencies.  However,…

    Article 2023年6月26日
TOP