BTC PULSE
No Result
View All Result
Play Now
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

Two Vulnerabilities Picked Out in This interoperable Blockchain

by Chiwuike Owunwa
Jan 31, 2023 - 12:00 am
in Blockchain
Two Vulnerabilities Picked Out in This interoperable Blockchain

On the 30th of January 2023, James Prestwich called public attention to two critical blindspots in LayerZero smart contracts.

Hello, today we are disclosing two critical trusted-party vulnerabilities in the LayerZero smart contracts. These issues allow the LayerZero team to completely bypass the Oracle and Relayer for most applications (including stargate).https://t.co/C7Gh6ns56S

— James Prestwich (@_prestwich) January 30, 2023

James Prestwich, founder, and CTO of Nomad, a cross-chain bridging service disclosed in his tweet, two major trusted-party vulnerabilities in LayerZero smart contracts which he mentioned to exist in the endpoint contract and another in the UltraLightNodeV2 contract.

  1. LayerZero is an omnichain interoperable User application, designed to convey lightweight messages across chains. Its core concept is demonstrated by its reliance on two parties including oracle and the relayer of applications like Stargate, in order to convey messages across on-chain endpoints.

He alleges that these two vulnerabilities confer the LayerZero team the ability to exploit user applications. Allowing it to bypass the Oracle and relayer when passing arbitrary information to an application.

Outlining his findings, Prestwich proceeded to explain that a trusted-party vulnerability has access to a back door. This undisclosed capability allows a trusted party to compromise the functionality of a system. Insinuating that LayerZero has the ability to exclusively steal or transfer secured funds without permission from platforms that utilize bridging services.

He claimed that a driving force toward this full disclosure is the fact that the LayerZero team seems to be aware of these vulnerabilities and yet they let it remain undisclosed in order to actively exploit them instead. He believes that they are also deliberately hiding the extent of their control over the applications so prompt mitigation from every application integrating LayerZero might be the best solution.

He further explained that the LayerZero upgradability pattern allows vulnerabilities by exploiting a drag-along mechanism to bypass all security checks without compromising any protocol actor.

He outlined two criteria. Criteria 1, involves default-configured apps. The layerZero has the ability to randomly submit messages through Endpoint by changing the default Receiving library which is an easily exploitative venture that allows fraudulent messages across local applications bypassing the oracle and relayer’s 2-of-2 multisig completely.

In Criteria 2, the LayerZero Multisig could also randomly modify message payloads while being processed by UltraLightNode even after the oracle and relayer sign off, which is also a critical vulnerability that can be exploited in the same way.

Prestwich proceeds to mention that a form of mitigation would be to design a new version of the UltraLightNode contract which doesn’t involve an automatic upgrade but this would ultimately address only criteria 2 and not criteria 1.

Tags: LayerZero
Chiwuike Owunwa

Chiwuike Owunwa

Chiwuike is a frontend programmer and writer with 3 years experience in the Web3. He's meticulous researcher, enthusiastic about Blockchain and the future of crypto, DeFi, and the Metaverse.

Related Posts

Crypto VC funding trends in June 2025 highlighting DeFi, AI, and hybrid exchanges

Massachusetts Sues Kalshi Over Alleged Unlicensed Sports Betting

September 13, 2025

Massachusetts accuses Kalshi of illegal sports wagering. The company defends its operations, citing federal CFTC oversight of prediction...

Chart showing Bitcoin mining difficulty reaching an all-time high

Aethir Price Surges 43% Amid DePIN Market Rally

September 8, 2025

Aethir surged 43% to $0.045, outpacing DePIN peers like Bittensor and Render as crypto markets rose ahead of...

Image of the SEC headquarters building displaying a "Closed" sign, symbolizing recent resignations and turmoil.

SEC Eyes Crypto Integration with Wall Street in Policy Shake-Up

September 4, 2025

SEC unveils plan to integrate crypto into Wall Street with clear rules on issuance, custody, and trading, ending...

Blockchain tokenization drives energy, AI and credit market innovation with VC support

VC Roundup: VCs Fuel Energy Tokenization, AI Datachains, Programmable Credit

September 4, 2025

VCs back startups tokenizing energy, building AI-focused datachains, launching programmable credit protocols and expanding stablecoin infrastructure.

Press Releases

png 115

BTC Miner: Earn $100-$100,000 Daily – The Fastest Growing Crypto Mining Platform of 2025!

June 25, 2025

BTC Miner, the fastest growing platform in 2025, opens a new era of inclusive cryptocurrency mining, allowing everyone to participate...

image2

Could XYZVerse Overtake DOGE and SHIB? Analysts Say $0.003333 Could Explode to $10!

March 30, 2025

XYZVerse aims to outpace DOGE and SHIB, with bold $10 price goals, strong community rewards, and rising demand as it...

image1 1

Massive Institutional BTC Buys Could Launch the Next Bull Market: 5 Altcoins to Watch

March 29, 2025

Institutional Bitcoin buys may trigger a market surge. Five altcoins, including $XYZ, stand to gain—early investors could see major ROI...

image1

XRP Faces Strong Resistance While XYZVerse Gains Early Investor Attention With 10 Billion $XYZ Airdrop

March 28, 2025

XRP struggles at resistance, while XYZVerse grabs early investor attention with a 10B token airdrop and rapid growth toward a...

View All
BTC-Pulse LogoTransparent

© 2024 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

©2024 BTC-PULSE – All right Reserved.

No Result
View All Result
  • About Us
  • Advertise
  • BTC-PULSE
  • Contact Us
  • Events
  • Privacy Policy
  • Sitemap
  • Terms of Service