Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • Is the metaverse dead? Investors register 99% losses

    TL;DR Breakdown The September 2023 metaverse market is far off from its peak success in November 2021, and the numbers show painful results. The Sandbox (SAND), Axie Infinity (AXS), Enjin Coin (ENJ), and Decentraland (MANA) arguably dominated the Metaverse and GameFi – not anymore. Description In recent developments, the booming Metaverse market is exhibiting signs of cooling off as it experiences a notable price dip across various digital assets and virtual real estate properties. Once hailed as the ‘Next Frontier’ in technological evolution and a lucrative investment opportunity, the Metaverse is currently navigating through turbulent waters, sparking debates among investors, … Read more In recent developments, the booming Metaverse market is exhibiting signs of cooling off as it experiences a notable price dip across various digital assets and virtual real estate properties. Once hailed as the ‘Next Frontier’ in technological evolution and a lucrative investment opportunity, the Metaverse is currently navigating through turbulent waters, sparking debates among investors, developers, and analysts about the sustainability and long-term prospects of these digital universes.  This downturn has led many to question whether the…

    Article 2023年9月3日
  • Nvidia unveils DGX GH200, supercharges AI development and gaming industry

    TL;DR Breakdown At the Computex event in Taiwan, Nvidia unveiled the DGX GH200, a state-of-the-art AI supercomputer. Alongside the DGX GH200, Nvidia announced Nvidia ACE for Games, a platform that will utilize AI to create game NPCs with more depth and personality. Using AI and metaverse technologies, Nvidia plans to partner with WPP to reduce advertising costs. Nvidia, a forerunner in developing artificial intelligence (AI) tools and applications, has disclosed ambitious plans to roll out an array of innovative AI products. During the Computex event in Taiwan on May 28, Nvidia’s CEO, Jensen Huang, introduced the DGX GH200, a state-of-the-art AI supercomputer designed to assist tech firms in creating advanced versions of the renowned AI chatbot, ChatGPT. Huang expects that leading tech companies such as Meta, Microsoft, and Google’s Alphabet will be among the early adopters of the new AI powerhouse. Alongside this announcement, Huang also revealed Nvidia ACE for Games, a service aimed at the gaming industry. This platform will harness AI to imbue game NPCs with more depth and personality. Nvidia also plans to join forces with communications…

    Article 2023年6月2日
  • Tornado Cash co-founder Roman Storm released on bail following DOJ arrest

    TL;DR Breakdown Tornado Cash co-founder Roman Storm was arrested by the DOJ and later released on bail, raising concerns about the legality of privacy tools in cryptocurrency. The arrest has sparked a debate within the crypto community, with supporters emphasizing the importance of privacy and critics warning against potential misuse for illegal activities. Description Roman Storm, the co-founder of Tornado Cash, who was arrested by the Department of Justice (DOJ) has been released on bail. On August 24, Storm’s lawyer Brian Klein posted on X (formerly known as Twitter) to inform that Storm had been granted bail and released. Klein expressed his ongoing disappointment with the prosecutors’ decision to … Read more Roman Storm, the co-founder of Tornado Cash, who was arrested by the Department of Justice (DOJ) has been released on bail. On August 24, Storm’s lawyer Brian Klein posted on X (formerly known as Twitter) to inform that Storm had been granted bail and released. Pleased to share that my client Roman Storm is already out on bail, although I remain very disappointed that the prosecutors charged him…

    Article 2023年8月26日
  • White House raises concerns about AI surveillance effect

    TL;DR Breakdown The White House has announced plans to hold a listening session with workers to understand their experiences with AI usage by employers for surveillance and evaluation. This initiative follows concerns over potential privacy violations and bias in employment decisions due to AI misuse. The administration will also release an updated roadmap for federal AI investments, request public input on AI risks, and share a new Department of Education report on AI’s impact on education. In a move towards understanding and regulating the implications of artificial intelligence (AI) in the workforce, the White House has announced plans to reach out to employees across various industries. This initiative aims to understand their experiences with the incorporation of AI technology by their employers for monitoring and evaluation purposes. This process comes amidst the exponential rise in AI applications, leading to concerns over privacy breaches and potential misuse. Understanding workers’ experiences with AI The White House’s listening session will include experts in the gig economy, researchers, and policymakers. This collaborative approach intends to foster an environment that promotes understanding of the diverse…

    Article 2023年5月26日
  • Germany’s economic resurgence: What lies ahead?

    Description Germany stands on the precipice of another economic metamorphosis. Not too long ago, the nation was dubbed the “sick man of Europe.” Yet, through sheer determination and meticulous reforms, it rose to the epitome of economic prowess. But as recent times have shown, this powerhouse is not impervious to economic doldrums. With Chancellor Olaf Scholz … Read more Germany stands on the precipice of another economic metamorphosis. Not too long ago, the nation was dubbed the “sick man of Europe.” Yet, through sheer determination and meticulous reforms, it rose to the epitome of economic prowess. But as recent times have shown, this powerhouse is not impervious to economic doldrums. With Chancellor Olaf Scholz unveiling a new growth blueprint, one can’t help but critically ask: Is this enough? Or is history destined to repeat itself? The Promises and Shortcomings of Scholz’s Plan As Germany’s economic performance wanes, echoing somber growth rates and falling behind its major rivals, Chancellor Scholz’s plan is a beacon of hope for many. Yet, a mere allocation of €8bn, accounting for just 0.2% of the nation’s…

    Article 2023年9月3日
TOP