Web3 developer discovers a bug in Celer’s SGN

TL;DR Breakdown

  • Web3 developer Jump Crypto has discovered a bug in Celer’s State Guardian Network.
  • Celer addresses vulnerability and explores bug bounty expansion.

Web3 developer Jump Crypto has recently discovered a critical vulnerability in Celer’s State Guardian Network (SGN), potentially compromising the network and applications dependent on it, including Celer’s cBridge. Jump Crypto’s postmortem report revealed that the vulnerability allowed malicious validators to exploit a bug in the SGN EndBlocker code, enabling them to vote multiple times on the same update.

The Web3 developer releases his report

This flaw in the code allowed malicious actors to amplify their voting power, potentially approving harmful or invalid updates. Celer, a Cosmos-based blockchain facilitating cross-chain communication, released parts of the off-chain SGNv2 code on GitHub, prompting Jump to review the script and privately notify Celer’s protocol team about the vulnerability. Celer promptly addressed the issue, fixing it before any malicious exploitation occurred.

The vulnerability presented a range of options for malicious validators, including the ability to manipulate on-chain events such as bridge transfers, message emissions, and staking and delegation on Celer’s main SGN contract. While Celer had implemented defense mechanisms to prevent the complete theft of bridge funds, the Web3 developer’s report highlighted three specific safeguards. These included a transfer delay triggered by the bridge contract for transfers exceeding a certain value, a volume-control mechanism limiting the extraction of tokens within a short period, and an emergency halt of contracts in response to under-collateralization events caused by malicious transfers.

However, despite these security measures, the report emphasized that the protocol was not entirely protected. The transaction limits are applied per chain and token, meaning that an attacker could potentially exfiltrate tokens with a value of approximately $30 million before the contracts are halted. This amount represents around 23% of Celer’s current total value locked.

Celer tackles the problem and expands its bug bounty program

The Web3 developer’s report further highlighted that while Celer’s built-in mechanisms could protect its bridge contracts, decentralized applications (dApps) built on top of Celer’s inter-chain messaging would remain vulnerable to these types of vulnerabilities by default.

Celer has a bug bounty program offering a $2 million reward for vulnerabilities in its bridge. However, it does not cover off-chain bugs such as the one discovered in the SGNv2 network. Jump Crypto has been engaged in discussions with Celer about adding the SGNv2 network to its bug bounty program, and the potential payout for Jump’s report is currently under evaluation by Celer’s team.

The identification and swift resolution of this vulnerability highlight the importance of rigorous security measures and bug bounty programs in the blockchain industry. By addressing these issues promptly, networks like Celer can enhance their resilience and safeguard user assets in the evolving Web3 landscape.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Web3 developer discovers a bug in Celer’s SGN

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月27日 11:39
Next 2023年5月27日 12:57

Related articles

  • Coinbase’s Base layer-2 network gears up for mainnet launch, strengthened by rigorous security audits

    TL;DR Breakdown Base, a layer 2 blockchain under Coinbase, completes six months of extensive internal and external security assessments. Coinbase hired 100 experts to examine the network’s code as part of an audit contest. The Code4rena challenge lasted 14 days. Base has not provided a date for the mainnet launch and has stated it will not have a native token. Description Base, the layer 2 blockchain developed by Nasdaq-listed crypto exchange Coinbase (COIN), has completed a series of security audits as it prepares to launch its mainnet with the goal of attracting up to 1 million new crypto users in the coming years. The team announced on June 29 that the Optimism-powered, Ethereum-secured network had undergone … Read more Base, the layer 2 blockchain developed by Nasdaq-listed crypto exchange Coinbase (COIN), has completed a series of security audits as it prepares to launch its mainnet with the goal of attracting up to 1 million new crypto users in the coming years. The team announced on June 29 that the Optimism-powered, Ethereum-secured network had undergone six months of extensive internal and…

    Article 2023年7月2日
  • IMF adjusts 2023 global economic growth forecast to reflect 3%

    TL;DR Breakdown The International Monetary Fund (IMF) has raised its projection for global growth this year to 3%, 0.2% points more than its April prediction. IMF also predicts that global headline inflation may drop 6.8% this year from 8.7% in 2022. EMDEs growth outlook has remained stable, with growth of 4.0% in 2023 and 4.1% in 2024. Description The International Monetary Fund (IMF) has raised its projection for global growth this year marginally today, citing the strong economy, especially service sector activity in Q1 2023. The international lender did, however, also issue a warning over the ongoing issues that are dimming the medium-term outlook. IMF projects 3% global economic growth  The IMF predicted … Read more The International Monetary Fund (IMF) has raised its projection for global growth this year marginally today, citing the strong economy, especially service sector activity in Q1 2023. The international lender did, however, also issue a warning over the ongoing issues that are dimming the medium-term outlook. IMF projects 3% global economic growth  The IMF predicted 3% real GDP growth for the whole world this…

    Article 2023年7月26日
  • Genesis extends mediation for the last time, urgency mounts to reach agreement

    TL;DR Breakdown Genesis Global faces insolvency and is racing against time to reach an agreement with creditors. The mediation scheduled to conclude on August 16 is seen as a critical step for Genesis to emerge from bankruptcy. Despite rejection by the official committee of unsecured creditors, the proposed deal enjoys support from major players in the cryptocurrency sector. Description Genesis Global, a cryptocurrency lender facing insolvency, is racing against time to reach an agreement with its creditors. The company’s attorney, Sean O’Neal, informed US Bankruptcy Judge Sean Lane that further extensions would only be sought if progress is made in mediation within the next two weeks. The mediation, set to conclude on August 16, … Read more Genesis Global, a cryptocurrency lender facing insolvency, is racing against time to reach an agreement with its creditors. The company’s attorney, Sean O’Neal, informed US Bankruptcy Judge Sean Lane that further extensions would only be sought if progress is made in mediation within the next two weeks. The mediation, set to conclude on August 16, is seen as a critical step for Genesis…

    Article 2023年8月4日
  • WEX exchange co-founder Alexei Bilyuchenko sentenced in Moscow amid global legal entanglements

    TL;DR Breakdown Alexei Bilyuchenko, former technology administrator of BTC-e and co-founder of WEX, has been sentenced to 3.5 years in prison by a Moscow court for misappropriating exchange funds and fined 3.1 billion rubles ($33 million). The sentencing follows charges by the U.S. Department of Justice against Bilyuchenko for involvement in the 2011 Mt.Gox hacking incident and additional conspiracy charges, adding international complexity to the case. Description Alexei Bilyuchenko, the former technology administrator of BTC-e exchange and co-founder of WEX, has been sentenced by the Meshchansky District Court of Moscow. He will serve 3 years and 6 months in prison for misappropriating the exchange’s funds. Additionally, Bilyuchenko has been slapped with a fine of 3.1 billion rubles, equivalent to around $33 million, … Read more Alexei Bilyuchenko, the former technology administrator of BTC-e exchange and co-founder of WEX, has been sentenced by the Meshchansky District Court of Moscow. He will serve 3 years and 6 months in prison for misappropriating the exchange’s funds. Additionally, Bilyuchenko has been slapped with a fine of 3.1 billion rubles, equivalent to around $33 million,…

    Article 2023年9月25日
  • Cryptocurrency exchange Binance pulls out of the UK market due to regulatory constraints

    TL;DR Breakdown Binance has withdrawn from key regions due to growing regulatory pressure, including the termination of its registration with the FCA in the UK. Binance’s subsidiary, Binance Markets Limited (BML), has been inactive in the UK since its acquisition in 2020. The termination of BML’s registration highlights Binance’s challenges in complying with regulatory requirements. Description Binance, the troubled cryptocurrency exchange, has withdrawn from key regions in response to mounting regulatory pressure. The UK-based subsidiary, Binance Markets Limited (BML), recently terminated its registration with the Financial Conduct Authority (FCA). This prompted the FCA to clarify that no Binance company can provide services in the UK. The FCA fulfilled Binance’s request to … Read more Binance, the troubled cryptocurrency exchange, has withdrawn from key regions in response to mounting regulatory pressure. The UK-based subsidiary, Binance Markets Limited (BML), recently terminated its registration with the Financial Conduct Authority (FCA). This prompted the FCA to clarify that no Binance company can provide services in the UK. The FCA fulfilled Binance’s request to revoke BML’s authorization on May 30, 2023, and confirmed in a…

    Article 2023年6月21日
TOP