Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • BRICS currency faces challenges in implementation and consensus

    TL;DR Breakdown Russia’s Central Bank Governor recognizes challenges in implementing a common BRICS currency. The proposed currency requires consent from many parties, making it complex. Discussions on the currency expected at the upcoming BRICS summit. Despite the challenges, the shared currency could undermine U.S. dollar dominance. Description The implementation of a shared currency among the BRICS nations – Brazil, Russia, India, China, and South Africa – is currently fraught with difficulties and disagreements, as per the observations made by the Bank of Russia’s Governor. Although this potential monetary development is considered to be noteworthy, it presents considerable challenges, demanding alignment among numerous … Read more The implementation of a shared currency among the BRICS nations – Brazil, Russia, India, China, and South Africa – is currently fraught with difficulties and disagreements, as per the observations made by the Bank of Russia’s Governor. Although this potential monetary development is considered to be noteworthy, it presents considerable challenges, demanding alignment among numerous stakeholders. Struggles for a shared BRICS currency Russia’s Central Bank Governor, Elvira Nabiullina, expressed these concerns during the Financial Congress…

    Article 2023年7月13日
  • Just how important is Bitcoin’s global investment to TradFi?

    TL;DR Breakdown Investors have witnessed a rather lunatic craze around Bitcoin and the crypto industry that begs the question of how much global wealth is invested in BTC.  Bitcoin wealth sits at around 0.11% of the estimated total global wealth worth. September has witnessed historic lows as market sell-off intensifies. Description In the rapidly evolving landscape of financial markets, one term has become increasingly prevalent—Bitcoin. Once dismissed as a speculative bubble or a tool for illicit activity, Bitcoin has matured into a complex, multi-faceted asset that holds transformative potential for traditional financial systems, often referred to as “TradFi” or Traditional Finance.  On September 11, 2023, one … Read more In the rapidly evolving landscape of financial markets, one term has become increasingly prevalent—Bitcoin. Once dismissed as a speculative bubble or a tool for illicit activity, Bitcoin has matured into a complex, multi-faceted asset that holds transformative potential for traditional financial systems, often referred to as “TradFi” or Traditional Finance.  On September 11, 2023, one bitcoin was worth approximately $25,867 per coin. There were over 19,48 million bitcoins in circulation, valuing…

    Article 2023年9月12日
  • Bored Apes Yacht Club Revolutionizes NFT Verification with Cutting-Edge On-Chain Tool

    TL;DR Breakdown Bored Ape Yacht Club (BAYC) collaborates with SaaSy Labs to introduce “Made by Apes,” an on-chain IP verification tool. It will enable BAYC members to authenticate their creations. BAYC floor prices have dropped significantly, but the introduction of “Made by Apes” aims to revitalize interest and strengthen the long-term value of the collection. Description In an exciting development for the Bored Ape Yacht Club (BAYC), one of the most popular NFT collections, the team has announced the upcoming launch of “Made by Apes,” an on-chain intellectual property (IP) verification tool. Developed in partnership with SaaSy Labs, this tool aims to provide a seamless solution for BAYC members to verify … Read more In an exciting development for the Bored Ape Yacht Club (BAYC), one of the most popular NFT collections, the team has announced the upcoming launch of “Made by Apes,” an on-chain intellectual property (IP) verification tool. Developed in partnership with SaaSy Labs, this tool aims to provide a seamless solution for BAYC members to verify their creations and establish an official catalog within the club. As…

    Article 2023年7月12日
  • Bitget announces the launch of its dual-coin crypto loans

    TL;DR Breakdown Bitget has announced the launch of a new dual-coin method of obtaining loans from the platform. The platform wants to dominate the lending market. Description Singapore-based derivatives trading platform Bitget is set to launch a cryptocurrency lending program that allows users to stake their coins in exchange for loans in different digital assets. The platform aims to cater to borrowers who are dissatisfied with traditional lenders and provide them with the opportunity to expand their investment portfolios beyond their current … Read more Singapore-based derivatives trading platform Bitget is set to launch a cryptocurrency lending program that allows users to stake their coins in exchange for loans in different digital assets. The platform aims to cater to borrowers who are dissatisfied with traditional lenders and provide them with the opportunity to expand their investment portfolios beyond their current holdings. Bitget says the program will be flexible for users Bitget’s managing director, Gracy Chen, highlighted the flexibility and enhanced capital utilization that the loan program offers. By allowing users to stake less-demanded coins, borrowers can obtain loans in more…

    Article 2023年7月7日
  • ZA Bank launches retail trading platform in Hong Kong

    TL;DR Breakdown ZA Bank has launched its retail trading platform in Hong Kong following regulatory approval. Hong Kong commits to strengthening regulations to protect retail traders. ZA Bank, based in Hong Kong, has announced its plans to offer retail virtual asset trading in the region. The bank revealed its intentions shortly after the Hong Kong Securities and Futures Commission (SFC) declared its acceptance of license applications for retail virtual asset trading platforms. In order to obtain regulatory approvals, ZA Bank will collaborate with locally licensed virtual asset exchanges, as stated in their announcement. Once the necessary approvals are secured, the bank’s customers will be able to trade virtual assets using fiat currency through the ZA Bank App. ZA Bank floats its virtual asset trading platform This move towards virtual asset trading is part of ZA Bank’s broader strategy, which also includes plans to facilitate trading in United States stocks in the future. The SFC’s decision to accept license applications for retail virtual asset trading platforms was accompanied by the implementation of new guidelines, effective from June, which focus on asset…

    Article 2023年5月27日
TOP