Telegram (AI) YouTube Facebook X
Ру
Optimism team pays out over $2 million for disclosed vulnerability

Optimism team pays out over $2 million for disclosed vulnerability

The Optimism developers, layer-2 scaling solution for Ethereum, patched a critical vulnerability.

The bug was discovered by programmer Jay Freeman in the Geth client fork code for Optimism. According to the description, the vulnerability allowed creating ETH in the protocol, repeatedly triggering the SELFDESTRUCT function.

Freeman reported the bug to the Optimism team on February 2. For disclosure he received the maximum bounty of $2,000,042.

A retrospective analysis showed that the bug was not exploited, except for a random activation by an Ethereum-explorer employee at Etherscan. No coins were minted.

“The fix has been tested and deployed in the Optimism Kovan and mainnet networks (including all infrastructure providers) within a few hours after the disclosure,” the team wrote.

The developers also cautioned several vulnerable Optimism forks and bridge providers about the issue. All projects applied the necessary fixes.

The Optimism team stressed that the incident underscored the importance of bug-bounty programs. Around this time, the Wormhole cross-chain bridge was hacked for 120,000 ETH (~$319 million), prompting the project to consider launching a $3.5 million bounty initiative, the developers noted.

In October 2021, the Polygon team behind the layer-2 solution paid out the maximum $2 million under its bug-bounty program for disclosing a vulnerability that threatened losses of $850 million.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK