News

Wormhole rewarded $10 million to a white hat hacker who reported a bug

The Wormhole cross-chain bridge just spent $10 million on a white hat hacker who discovered a vulnerability in the product’s Ethereum smart contract in February.
An individual with the codename satya0x who discovered the vulnerability and received the Wormhole reward

According to an announcement from Immunefi (the bug bounty co-organizer with Wormhole), an individual with the code name satya0x is the one who discovered the vulnerability and received the aforementioned reward.

Wormhole unveiled the scheme in February, shortly after losing over $323 million in ETH to a hacker in one of the largest DeFi protocol attacks to date. Soon after, it refilled its blockchain bridge, promising the attacker $10 million in exchange for the funds.

Wormhole’s bug bounty program has different tiers, depending on the severity of the discovered vulnerability. Specifically, with a “low risk” level, a contract error can only bring in a reward of $2,500. Meanwhile, the reward that satya0x received is $10 million because the level of risk is at the system level.

Hacker satya0x said:

“I am proud to have played a role in mitigating a serious vulnerability and a systemic threat to the ecosystem.”

The Immunefi side stated that the user’s assets were still safe at the time the aforementioned bug was discovered. Soon after, Wormhole quickly deployed the update and patched it the same day.

“Wormhole is sending a clear message with this payout to the best, most talented whitehats on the planet that if they responsibly disclose security vulnerabilities to Wormhole, they’ll be well taken care of,” Immunefi said.

On its Twitter and medium pages, Immunefi also published a detailed report on the vulnerabilities in the aforementioned case.

The bug was related to Wormhole’s ability to upgrade smart contracts. Essentially, it could potentially allow a hacker to take control of those contracts. In a blog post, Immunefi provided a detailed breakdown of the issue that led to the security vulnerability and how it was fixed.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join CoinCu Telegram to keep track of news: https://t.me/coincunews

Follow CoinCu Youtube Channel | Follow CoinCu Facebook page

Harold

CoinCu News

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

LayerZero Sybil Airdrop Farmers Are Now Being Drastically Blocked For Fraud

LayerZero sybil airdrop farmers offered a 15% allocation incentive; non-compliance results in an 85% reduction.

9 hours ago

New MakerDAO Tokens Are Launched To Promote Protocol Governance

New MakerDAO tokens, NewStable and NewGovToken, were introduced to improve stability and governance.

10 hours ago

Sui Turns One: Debut Year of Growth and Tech Breakthroughs Puts Sui at Forefront of Web3

Grand Cayman, Cayman Islands, May 3rd, 2024, ChainwireProtocol launches, growth trajectory, and industry-leading technology point…

17 hours ago

$2.4B Bitcoin And Ethereum Options Set To Expire, Volatility Expected: Report

Bitcoin and Ethereum options contracts worth $2.4bn expire on May 3, potentially causing market volatility.…

18 hours ago

Robinhood Connect In The Uniswap Mobile App Now Supports Users Buying Crypto

The integration helps users with a $10 USDC reward for purchasing at least $10 of…

19 hours ago

Singapore Crypto Poker Robbery Results In 11 Victims Losing Millions Of Dollars

11 people lost property worth NT$4.34m in a Singapore crypto poker robbery, including $3.58m SGD…

21 hours ago

This website uses cookies.