Arbitrum Rewards Hacker With 400 ETH For Detecting a Critical $400M Vulnerability

0

[ad_1]

On September 19, Arbitrum, one of the most popular Layer 2 solutions for Ethereum, paid 400 ETH (about $560,000) to a white hat hacker who found a potential vulnerability in its code.

The white hat hacker, known on Twitter as Riptide, finds vulnerabilities within smart contracts written in Solidity. Riptide said the “multi-million dollar vulnerability” could potentially affect anyone who wanted to exchange funds from Ethereum to Arbitrum Nitro.

Arbitrum Prevented Millions of Dollars in Losses

The hacker thoroughly scanned the Arbitrum Nitro code a few weeks before it was released, checking the contracts so they could “see if the update had been a success.”

After the upgrade, Riptide noticed some errors that prevented the bridge from working correctly. Upon further inspection, Riptide noticed that the inbox sequencer was experiencing a delay.

“A client can send a message to the Sequencer by signing and publishing an L1 transaction in the Arbitrum chain’s Delayed Inbox. This functionality is most commonly used for depositing ETH or tokens via a bridge.”

After rescanning the contract, Riptide confirmed that the inbox sequencer bug allowed a critical vulnerability in the contract by which Riptide or another malicious hacker could have obtained millions of dollars by diverting incoming ETH deposits from the L1 to the L2 bridge into their wallets before being detected.

However, Riptide decided to report the vulnerability and apply for a reward instead, which to their surprise, was just 400 ETH instead of the $2 million reward Arbitrum offered as its maximum tier. Upon receiving the reward, the hacker argued that it was not in line with the importance of the bug and the risk it entailed.

It is worth mentioning that in March 2022, Arbitrum was the victim of an exploit in which a hacker or a group of hackers stole more than 100 NFT from TreasureDAO, with a valuation of at least $1.4 million.

White Hat Hackers: A Lucrative Business in Crypto-Land

Independent auditing is of huge importance in the crypto ecosystem. Over the course of the year, several platforms have opted to pay bounties to white hat hackers who report potential vulnerabilities in their code or smart contracts.

For example, in mid-February, Coinbase paid “the largest bounty in its history” ($250,000) to a hacker named “Tree of Alpha” for saving them from a billion-dollar loss due to a flaw in the “Advanced Trading” feature.

At the time, Tree of Alpha was grateful for the payment stating that it could serve him well in retirement; however, like Riptide, he noted that “a higher bounty might have been smart to deter more gray hats from exploiting vulnerabilities.”

Also,  Jay “Saurik” Freeman —who works with the decentralized VPN protocol Orchid and is a legend in the iOS jailbreak community—received over $2 million for reporting a vulnerability in Optimism, a “layer 2 scaling solution” for Ethereum.

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
tron
TRON (TRX) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
monero
Monero (XMR) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
rain
Rain (RAIN) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
Shares