Connect with us

Hi, what are you looking for?

Investing

White Hat Hackers Awarded $300K After Uncovering Critical Chainlink VRF Vulnerability

White hat hackers earn $300K Chainlink bounty for responsibly disclosing critical VRF vulnerability. Image by ZayNyi, Adobe Stock.

Decentralized oracle network Chainlink recently awarded white hat hackers Zach Obront and Or Cyngiser of Trust $300,000 for uncovering a critical vulnerability in its Verifiable Random Function (VRF) product. VRF allows smart contracts to access tamper-proof random values while maintaining security.

The bug discovery comes amid Chainlink’s increased institutional adoption of its Cross-Chain Interoperability Protocol (CCIP) technology. Major traditional institutions like Swift, Vodafone and South Korea’s largest gaming company have utilized Chainlink’s technology in recent months.

Uncovered Potential for Manipulation


According to Chainlink Labs, Obront and Cyngiser identified an issue where a malicious VRF subscription owner could potentially prevent users from getting proper randomness rolls by blocking and rerolling until a desired outcome occurred. The team categorized it as a critical smart contract vulnerability.

Although the conditions required to exploit this loophole were specific, it still compromised the core functionality of Chainlink VRF in providing transparent and verifiable on-chain randomness. The primary risk came from a compromised or malicious subscription owner, a role typically controlled by the decentralized app using VRF.

Mitigation Implemented, $300K Bounty Paid


After consulting the researchers, Chainlink implemented a fix to guarantee randomness delivery even if the subscription owner tries exploiting the vulnerability. Obront and Cyngiser received $300,000 for responsibly disclosing the issue, positioning the bounty among the top 10 payouts in Immunefi’s history.

Big win for #BlockchainSecurity! Zach Obront and Or Cyngiser, white hat hackers, bagged a hefty $300K bounty from Chainlink for uncovering a critical bug in their VRF system.

This bug, if exploited, could’ve twisted the randomness in VRF, a key element for #FairPlay in… pic.twitter.com/hVDwtX7PC5

— BlockVoyager (@BlockVoyagerAIO) November 15, 2023

Chainlink runs bug bounty programs on HackerOne and Immunefi, awarding security researchers who help identify weaknesses in its systems. The network has paid out over $500,000 to date across 75+ resolved reports.

Crowdsourced audits on Code4rena have also been conducted to further strengthen security. The decentralized platform continues taking steps to secure its reputation for reliability and transparency amid growing adoption.

Increasing Real-World Use Cases


Chainlink’s VRF is used by dApps like Axie Infinity, PancakeSwap, and Aavegotchi to protect smart contracts. The company’s CCIP allows communication between different blockchains, eliminating a major obstacle in decentralized finance. Its adoption by institutional giants like Swift and Vodafone for tokenization indicates growing trust in the technology.

With decentralized finance expanding rapidly, Chainlink’s security and interoperability solutions are likely to see increased real-world application. Responsible disclosure and mitigation of issues like the recent VRF vulnerability will prove critical for maintaining reliability as use cases scale up.

The post White Hat Hackers Awarded $300K After Uncovering Critical Chainlink VRF Vulnerability appeared first on Cryptonews.

Enter Your Information Below To Receive Free Trading Ideas, Latest News And Articles.







    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Learn Trading With Online Courses, Classes, & Lessons

    You May Also Like

    Investing

    Here is our weekly collection of digital asset listing and delisting, trading pair-related announcements by crypto exchanges that we found last week and today....

    Investing

    Source: Pexels Web3 development protocol Envision Blockchain Solutions has partnered with the HBAR Foundation to create a blockchain-centric system for handling the carbon markets....

    Latest News

    President Biden’s ghostwriter will not face charges despite deleting evidence of the sharing of classified material during the investigation. Mark Zwonitzer — who collaborated...

    Stock

    Union members at Ford, Stellantis and General Motors have ratified a new 4½-year contract, locking in at 11% pay increases secured after a six-week...

    Disclaimer: economicedgex.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.


    Copyright © 2024 economicedgex.com