$32M vulnerability in Perpetual Protocol uncovered by Chainlight nets $10k in white hat rewards

cyptouser1 years agoCryptocurrencies News190

Blockchain security firm Chainlight said it received a $10,000 bounty for uncovering a potential vulnerability that could have jeopardized $32 million in customer funds on Optimism-based decentralized exchange (DEX) Perpetual Protocol.

In a Nov. 9 post on social media platform X (formerly Twitter), Chainlight detailed how it reported a critical bug in Perpetual Protocol’s “AccountBalance” contract last year. According to the firm, the contract is a pivotal component that “serves as the protocol’s brain for calculating position values.”

The vulnerability posed a severe threat to the DEX, placing the entire $32 million USDC held by the protocol at risk of being misappropriated.

This flaw had the potential to allow bad actors to swiftly move the entire $32 million within a five-minute timeframe, leaving the protocol with insufficient time to deploy effective security measures.

The white-hat hacker detailed that an attacker could manipulate asset prices through a pump-and-dump strategy, exploiting volatile price actions to place position orders outside the permissible range and immediately profit, resulting in the protocol’s bad debt.

In acknowledgment of its efforts, Chainlight said it got $10,000 worth of Perpetual Protocol’s native PERP tokens.

Perpetual Protocol’s low bounty draws critics

The $10,000 bounty has generated several reactions from the crypto community, who argue it was insufficient considering the protected amount.

Trust, the head of security at blockchain auditing firm TrustSec, labeled the reward as another instance of a bounty scam, asserting that it did not adequately reflect the gravity of the situation.

Protocol Specialist at Coinbase, Viktor Bunin, also questioned why the bounty was so low.

Juancito, a blockchain security researcher, criticized the meager bounty offer, suggesting that white-hat hackers’ contributions to the ecosystem are not appropriately valued.

Similarly, Blurpoint noted that white-hat efforts often go unappreciated, emphasizing the importance of acknowledging and adequately compensating these contributions.

Web3 security expert CryptoBandit shared a comparable experience, recounting how he shared a critical vulnerability that could have led to $40 million in losses with the DEX but only got $30,000 as bounty rewards.

This situation underscores the challenges white-hat hackers face within the industry, as they are not properly incentivized to help crypto platforms expose vulnerabilities within their codes.

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Dubai’s DIFC passes comprehensive digital asset law, new security law

Dubai’s DIFC passes comprehensive digital asset law, new security law

25cc9d4a˃The Dubai International Financial Centre (DIFC), a special economic zone with over 5,000 re...

AI integration is changing creature-catching games in Web3: Here’s how

AI integration is changing creature-catching games in Web3: Here’s how

1205f261˃With the goal of transforming creature-catching games by blending AI and Web3 technologies,...

Filing suggests SEC is exploring grounds to deny spot Ether ETFs

Filing suggests SEC is exploring grounds to deny spot Ether ETFs

55966e89˃Analysts have unearthed details from a March filing with the United States Securities and E...

Marc Cuban wallet seen dumping NFTs after 2 years of inactivity

Marc Cuban wallet seen dumping NFTs after 2 years of inactivity

55966e89˃A crypto wallet belonging to billionaire Marc Cuban was spotted selling non-fungible tokens...

Bitcoin accumulation sees slowdown amid August market downturn

Bitcoin accumulation sees slowdown amid August market downturn

The Accumulation Trend Score, created by Glassnode, offers a detailed breakdown of the cryptocu...

UAE central bank approves licensing system for stablecoins

UAE central bank approves licensing system for stablecoins

55966e89˃The board of directors of the Central Bank of the United Arab Emirates (CBUAE) approved the...