Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • South Korea tightens grip on undeclared overseas crypto worth $99B

    TL;DR Breakdown South Korea’s tax agency reports that citizens and businesses hold around $99 billion in overseas crypto assets. A total of 1,432 individuals and entities are responsible for these crypto holdings. The Financial Services Commission is focusing on over-the-counter cryptocurrency transactions. Description South Korea’s tax agency has reported that citizens and businesses in the country hold approximately 131 trillion won, or around $99 billion, in overseas crypto assets. This staggering figure accounts for 70% of all offshore assets disclosed by South Koreans this year. Moreover, the tax authority revealed that 1,432 individuals and entities are behind these … Read more South Korea’s tax agency has reported that citizens and businesses in the country hold approximately 131 trillion won, or around $99 billion, in overseas crypto assets. This staggering figure accounts for 70% of all offshore assets disclosed by South Koreans this year. Moreover, the tax authority revealed that 1,432 individuals and entities are behind these substantial holdings. Besides crypto assets, the tax agency’s data showed South Koreans have significant investments in stocks, deposits, and savings overseas. 5,419 entities disclosed…

    Article 2023年9月21日
  • Meta slapped with massive $1.3B fine for EU-U.S. data transfers

    TL;DR Breakdown Meta faces a record €1.2 billion ($1.3 billion) fine by EU privacy regulators for user data transfer to the U.S. The decision follows a case arguing that the transfer framework doesn’t protect Europeans from U.S. surveillance. The company is directed to stop future data transfers to the U.S. within five months, but the company plans to appeal. In a landmark development, Meta, the global social media giant, has been dealt a record €1.2 billion ($1.3 billion) blow by European privacy regulators. This ruling is directly linked to the transfer of EU user data to the U.S., a topic that has been a long-standing bone of contention. Dissecting the EU’s unprecedented penalty This monumental decision stems from a case brought forward by Austrian privacy campaigner Max Schrems. He proposed that the existing mechanism for data transfer from the EU to the U.S. failed to adequately safeguard Europeans against American surveillance. Following the argument, numerous mechanisms that facilitated legal transfer of personal data between the U.S. and the EU have come under scrutiny. Privacy Shield, the latest of such mechanisms,…

    Article 2023年5月24日
  • UK carpet retailer adds Bitcoin to its balance sheet

    TL;DR Breakdown UK carpet retailer Flooring Hut has announced the addition of Bitcoin to its balance sheet. The company sees Bitcoin as a tool for capital growth. Description Popular UK carpet retailer, Flooring Hut, based in the United Kingdom, has taken a bold step by investing in Bitcoin and adding it to its balance sheet. Following in the footsteps of companies like Tesla, MicroStrategy, and Real Bedford, Flooring Hut’s CEO, Paul Brewster, sees Bitcoin as a promising asset with significant potential for capital … Read more Popular UK carpet retailer, Flooring Hut, based in the United Kingdom, has taken a bold step by investing in Bitcoin and adding it to its balance sheet. Following in the footsteps of companies like Tesla, MicroStrategy, and Real Bedford, Flooring Hut’s CEO, Paul Brewster, sees Bitcoin as a promising asset with significant potential for capital growth. UK carpet retailer believes the move can benefit customers Brewster explained that the decision to choose Bitcoin over keeping their cash reserves in a bank account was driven by the belief that the cryptocurrency could deliver better returns,…

    Article 2023年7月25日
  • Circle freezes $63M in USDC after Multichain attack

    TL;DR Breakdown According to reports approximately $63 million worth of USDC, part of the assets involved in the alarming outflow, has been frozen as a result of Circle’s response. Circle has blacklisted three wallet addresses associated with a significant outflow of funds from the cross-chain bridge platform. The incident has caused widespread concern, prompting Multichain to urgently advise its users to refrain from using its services until further notice. Description Circle, the issuer of the popular stablecoin USDC, has taken swift action in response to a recent security breach on the Multichain protocol. Following the breach, which resulted in the mysterious transfer of $126 million worth of cryptocurrency assets from Multichain’s bridge deployments on Fantom and Dogechain to third-party wallets, Circle has blacklisted three wallet … Read more Circle, the issuer of the popular stablecoin USDC, has taken swift action in response to a recent security breach on the Multichain protocol. Following the breach, which resulted in the mysterious transfer of $126 million worth of cryptocurrency assets from Multichain’s bridge deployments on Fantom and Dogechain to third-party wallets, Circle has…

    Article 2023年7月9日
  • Louisiana criminalizes AI deepfakes depicting child porn

    TL;DR Breakdown Louisiana has established a new law that will criminalize all acts to depict child porn using deepfakes. Battling deepfake misuse and ensuring accountability. Description Louisiana is set to implement a new law on August 1 that will make the production and possession of deepfakes depicting the sexual abuse of children a criminal offense. Signed into law by Governor John Bel Edwards, Louisiana legislative bill SB175 imposes severe penalties for creating, distributing, or possessing unlawful deepfake images involving minors. Offenders … Read more Louisiana is set to implement a new law on August 1 that will make the production and possession of deepfakes depicting the sexual abuse of children a criminal offense. Signed into law by Governor John Bel Edwards, Louisiana legislative bill SB175 imposes severe penalties for creating, distributing, or possessing unlawful deepfake images involving minors. Offenders could face a mandatory prison sentence of five to 20 years, a fine of up to $10,000, or both. Louisiana to hand offenders 20 years and a $10,000 fine Deepfakes, which are AI-generated videos that manipulate and fabricate individuals, places, and…

    Article 2023年7月10日
TOP