BTC $78,422.77 +0.29%
ETH $2,470.08 +0.72%
BNB $693.79 +0.13%
XRP $1.38 -0.76%
SOL $103.69 -1.60%
TRX $0.3383 -0.73%
DOGE $0.0835 -1.77%
ADA $0.1981 -1.57%
BCH $249.19 +0.97%
LINK $11.44 +0.05%
HYPE $80.84 -3.04%
AAVE $124.81 -0.63%
SUI $0.7359 -0.99%
XLM $0.1782 -0.58%
ZEC $862.81 +2.68%
BTC $78,422.77 +0.29%
ETH $2,470.08 +0.72%
BNB $693.79 +0.13%
XRP $1.38 -0.76%
SOL $103.69 -1.60%
TRX $0.3383 -0.73%
DOGE $0.0835 -1.77%
ADA $0.1981 -1.57%
BCH $249.19 +0.97%
LINK $11.44 +0.05%
HYPE $80.84 -3.04%
AAVE $124.81 -0.63%
SUI $0.7359 -0.99%
XLM $0.1782 -0.58%
ZEC $862.81 +2.68%

vulnerabilities

All
Article
Flash

first_img Polygon has fixed security vulnerabilities through two hard forks, which were previously deployed privately

Polygon Labs disclosed that it has fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks, with the related fixes privately deployed before public disclosure. According to a forum post released on Wednesday, the team packaged the fixes into the Austin hard fork of the Bor client and the Kyoto hard fork of the Heimdall client, both of which followed the standard process for fixing issues that affect consensus: first validated on the Amoy testnet, and then publicly disclosed once the mainnet was activated and the network was secure.The Austin fork fixed two denial-of-service paths in block processing, including a vulnerability where malicious block producers could crash peer nodes by filling them with oversized field data. The Kyoto fork addressed a broader range of consensus hardening issues, with the most severe vulnerability allowing an attacker to force the entire validator set to perform costly and coordinated work with just one crafted transaction—the cost of constructing the transaction is low, but the network processing cost is high. Polygon emphasized that none of the vulnerabilities were observed to be exploited on the mainnet and have been proactively addressed. The two upgrades are now mandatory for node operators and have taken effect without the need for state migration or resynchronization.This disclosure comes at a critical transformation period for Polygon, which has completed the migration of the traditional MATIC token to POL as part of a comprehensive overhaul of its network architecture. The news did not boost the price of POL; according to CoinGecko data, POL traded at approximately $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week, and down about 60.8% over the past year, with a market capitalization of approximately $1.07 billion.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

Core Lightning, the Bitcoin Lightning Network software, issued an emergency warning due to the discovery of multiple real vulnerabilities in an AI report

According to CoinDesk, the developers of the Bitcoin Lightning Network payment software Core Lightning (CLN) issued an urgent warning to node operators after the team received a large number of AI-generated security reports, revealing several real vulnerabilities. The development team advised operators not to directly shut down the machine power but to restart the software in "--offline" mode, which stops communication with other Lightning Network nodes while still keeping it operational to continuously monitor the Bitcoin blockchain and protect the funds in the payment channels.The Core Lightning team began receiving a large number of AI-generated vulnerability reports since early August, some of which have been confirmed to be valid. Developers will keep the details confidential for two weeks to complete the patch development and plan to release a signed patch version for operators to verify the source. The source code and vulnerability details will be made public after the confidentiality period ends.This is the second AI-related security incident in the Lightning Network this month. Earlier in early August, BTCPay Server experienced a vulnerability that led to the leakage of credentials for some Lightning Network nodes and theft of funds. Additionally, the "Bitcoin Red Team," composed of 16 developers, used AI models to scan 390 Bitcoin code repositories at the end of July, discovering nearly 5,000 issues, 85 of which were rated as critical.

Maya Protocol Attacked: Six Linked Vulnerabilities Result in Approximately $1.7 Million Stolen, Liquidity Pool Shrinks by $11 Million

The cross-chain liquidity protocol Maya Protocol was attacked on August 18, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets, resulting in a total direct loss of about $1.65 million. The incident led to the suspension of trading on the MAYAChain network, with its token CACAO plummeting nearly 89% from $0.115 to $0.013, before recovering to around $0.03.Technical reviews show that the attack began when MAYAChain mistakenly judged a transaction to be lost and triggered a compensation mechanism, but the mechanism miscalculated, adding about 49 million CACAO to a small liquidity pool, while the protocol's reserves only held about 168,000 CACAO. After the transfer failed, the system incorrectly saved the new balance, and the attacker subsequently deposited a very small amount into the liquidity pool, acquiring over 99% of the pool's share and immediately withdrawing 48.87 million CACAO, which was then exchanged for Bitcoin, Ethereum, and other assets.The incident caused the total value of the Maya Protocol liquidity pool to decrease by about $10.9 million, of which approximately $6.4 million was due to the depreciation of CACAO, and about $2.9 million came from arbitrage trading. The team expressed hope that the attacker would return the funds in the form of a bug bounty; otherwise, they would seek to recover losses through investments in channels like Aztec Chain. Maya Protocol has not yet announced a specific time for resuming trading. This incident once again exposed the security risks within the complex logic of DeFi protocols.

Bitcoin Red Team has completed a foundational scan of the Bitcoin open-source ecosystem and discovered a large number of serious and high-risk vulnerabilities

Bitcoin News posted on the X platform that after two weeks of using cutting-edge AI to scan almost the entire Bitcoin open-source ecosystem for vulnerabilities, Bitcoin Red Team member @callebtc stated, "The easily discoverable vulnerabilities have been addressed," and maintainers are verifying "a large number" of serious and high-risk vulnerabilities.@callebtc indicated that the main findings include: decades of accumulated open-source technical debt are being exposed alongside AI capabilities that can discover vulnerabilities at speeds and scales unattainable by human researchers; Lightning seems particularly vulnerable, with its complexity meaning its security status is "worse than average"; unmaintained Bitcoin projects should be considered vulnerable until their security is confirmed.Projects that began building AI security and auditing processes months ago are now in a completely different position compared to those that have been waiting until now. The Bitcoin Red Team has now completed a foundational scan of almost the entire Bitcoin open-source ecosystem. Easily discoverable vulnerabilities have mostly been addressed, but as AI capabilities improve, external red team testing may need to continue indefinitely. Despite discovering and reporting "a large number" of real serious and high-risk vulnerabilities, @callebtc believes this process will ultimately make Bitcoin stronger. The same AI security review will soon expand to areas far beyond Bitcoin.
app_icon
ChainCatcher Building the Web3 world with innovations.