Polygon Technology Pays $ 2 Million Bounty To Protect $ 850 Million Crypto Fund

[ad_1]

Immunefi announced that a researcher named Gerhard Wagner was awarded $ 2 million for a vulnerability affecting the decentralized financial platform Polygon Technology. It’s believed to be the highest bug bounty ever paid, Immunefi said, and that’s because the flaw puts an estimated $ 850 million worth of cryptocurrency at risk.

The vulnerability was found in one of the bridges between the Polygon and Ethereum blockchains. “A bridge is basically a set of contracts that help move assets from the root chain to the child chain,” Polygon explains in their documents, and users can tap either the plasma bridge or the proof of stake bridge to move. their assets.

Plasma Bridge is supposed to be more secure, but Wagner discovered a loophole that could be exploited to remove up to 223 times an amount of ETH deposited as a polygon. Here’s how Immunefi explained the feat in their article:

Deposit a large amount of ETH / tokens on Polygon via the Plasma Bridge After confirming the availability of funds on the Polygon, start the withdrawal process Wait seven days for an exit to be valid Resubmit the exit payload but with a modified first byte branch mask. The same valid transaction can be resubmitted up to 223 times with different values ​​for the first byte of the HP encoded path.

The good news was that exploiting this vulnerability requires an initial investment. The Immunefi example showed that a person depositing $ 100,000 of ETH could withdraw $ 22.3 million from Polygon. Succeeding with $ 850 million from Polygon would first require around $ 3.8 million from ETH.

Immunefi said that Wagner disclosed this vulnerability on October 5 and that it only took Polygon Technology a week to pay the premium, pay the commission to Immunefi, test a patch to resolve the issue, and deploy this patch. on its main network. This is not surprising when you consider that almost a billion dollars was at stake.

Many companies offer bug bounty programs, and particularly nasty vulnerabilities can be worth a little. Apple pays up to $ 1 million for security breaches on the iPhone, for example, and Google will match that amount for issues affecting the Pixel Titan M chip. But the vast majority of bug bounty programs offer payouts significantly. lower.

Other researchers have been less ethical in revealing the flaws of decentralized financial platforms. The Poly Network hacker set an example by stealing around $ 600 million worth of various cryptocurrencies only to return the loot a few days later, after refusing Poly Network’s offer of a bounty of 500. $ 000 for revealing the flaw.

Wagner won four times as much for showing that kind of theft was possible in the Plasma Bridge than the Poly Network hacker would have actually stolen $ 600 million. This could be the rare example of more lucrative responsible disclosure than exploiting the bug or selling it to a vulnerability broker.

More information on the vulnerability, how it could be exploited and how Wagner discovered it can be found in his article on the process on Medium.

Sources

1/ https://Google.com/

2/ https://www.tomshardware.com/news/polygon-pays-2-million-bounty

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts