Blockchain

The Bridge Between Ethereum And Arbitrum Nitro Discovered Security Vulnerability

A Twitter account with the name ‘riptide’ posted an article regarding a vulnerability in the bridge between Ethereum and Arbitrum Nitro.

This person then quickly contacted Arbitrum’s team, thereby fixing the above vulnerability and receiving a bug bounty on ImmuneFi.

Accordingly, this vulnerability could allow hackers to steal the entire amount of ETH loaded into the bridge between Ethereum Layer-1 and Layer-2 (here is the Arbitrum Nitro version).

This white hat hacker said that the initialize() function that helps users sign transactions and sends encryption requests to Sequencers (validation units) has encountered a few vulnerabilities. The first 2 storage spaces (positions 0 and 1) of this function are empty, which means that the hacker can impersonate the user and then send the authentication message to the Sequencer.

This initialization-related vulnerability previously appeared in Nomad’s smart contract. This vulnerability was quickly identified by the Arbitrum team and a 400 ETH reward was sent to the aforementioned white hat hacker.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join CoinCu Telegram to keep track of news: https://t.me/coincunews

Follow CoinCu Youtube Channel | Follow CoinCu Facebook page

Harold

CoinCu News

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

FSOCIETY Threatens Massive Bitfinex Data Leak: 400,000 Users At Risk

Bitfinex data leak allegedly by FSOCIETY includes 2.5TB of exchange data and 400K users' details.…

27 mins ago

Disappointment Clouds Friend Tech v2 Launch Despite Exciting New Features

According to Parsec, Friend Tech v2's launch disappointed many, with 95% users unable to claim…

51 mins ago

LayerZero Sybil Airdrop Farmers Are Now Being Drastically Blocked For Fraud

LayerZero sybil airdrop farmers offered a 15% allocation incentive; non-compliance results in an 85% reduction.

11 hours ago

New MakerDAO Tokens Are Launched To Promote Protocol Governance

New MakerDAO tokens, NewStable and NewGovToken, were introduced to improve stability and governance.

12 hours ago

Sui Turns One: Debut Year of Growth and Tech Breakthroughs Puts Sui at Forefront of Web3

Grand Cayman, Cayman Islands, May 3rd, 2024, ChainwireProtocol launches, growth trajectory, and industry-leading technology point…

20 hours ago

$2.4B Bitcoin And Ethereum Options Set To Expire, Volatility Expected: Report

Bitcoin and Ethereum options contracts worth $2.4bn expire on May 3, potentially causing market volatility.…

20 hours ago

This website uses cookies.