BTC PULSE
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
Play Now
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

Two Vulnerabilities Picked Out in This interoperable Blockchain

by Chiwuike Owunwa
Jan 31, 2023 - 12:00 am
in Blockchain
Two Vulnerabilities Picked Out in This interoperable Blockchain

On the 30th of January 2023, James Prestwich called public attention to two critical blindspots in LayerZero smart contracts.

Hello, today we are disclosing two critical trusted-party vulnerabilities in the LayerZero smart contracts. These issues allow the LayerZero team to completely bypass the Oracle and Relayer for most applications (including stargate).https://t.co/C7Gh6ns56S

— James Prestwich (@_prestwich) January 30, 2023

James Prestwich, founder, and CTO of Nomad, a cross-chain bridging service disclosed in his tweet, two major trusted-party vulnerabilities in LayerZero smart contracts which he mentioned to exist in the endpoint contract and another in the UltraLightNodeV2 contract.

  1. LayerZero is an omnichain interoperable User application, designed to convey lightweight messages across chains. Its core concept is demonstrated by its reliance on two parties including oracle and the relayer of applications like Stargate, in order to convey messages across on-chain endpoints.

He alleges that these two vulnerabilities confer the LayerZero team the ability to exploit user applications. Allowing it to bypass the Oracle and relayer when passing arbitrary information to an application.

Outlining his findings, Prestwich proceeded to explain that a trusted-party vulnerability has access to a back door. This undisclosed capability allows a trusted party to compromise the functionality of a system. Insinuating that LayerZero has the ability to exclusively steal or transfer secured funds without permission from platforms that utilize bridging services.

He claimed that a driving force toward this full disclosure is the fact that the LayerZero team seems to be aware of these vulnerabilities and yet they let it remain undisclosed in order to actively exploit them instead. He believes that they are also deliberately hiding the extent of their control over the applications so prompt mitigation from every application integrating LayerZero might be the best solution.

He further explained that the LayerZero upgradability pattern allows vulnerabilities by exploiting a drag-along mechanism to bypass all security checks without compromising any protocol actor.

He outlined two criteria. Criteria 1, involves default-configured apps. The layerZero has the ability to randomly submit messages through Endpoint by changing the default Receiving library which is an easily exploitative venture that allows fraudulent messages across local applications bypassing the oracle and relayer’s 2-of-2 multisig completely.

In Criteria 2, the LayerZero Multisig could also randomly modify message payloads while being processed by UltraLightNode even after the oracle and relayer sign off, which is also a critical vulnerability that can be exploited in the same way.

Prestwich proceeds to mention that a form of mitigation would be to design a new version of the UltraLightNode contract which doesn’t involve an automatic upgrade but this would ultimately address only criteria 2 and not criteria 1.

Tags: LayerZero
Chiwuike Owunwa

Chiwuike Owunwa

Chiwuike is a frontend programmer and writer with 3 years experience in the Web3. He's meticulous researcher, enthusiastic about Blockchain and the future of crypto, DeFi, and the Metaverse.

Related Posts

Graph illustrating institutional investors' shift from Bitcoin and Ethereum to stablecoins in Bybit's report.

Bybit Report: Institutional Investors Favoring Stablecoins Over Bitcoin, But Not for Long

December 4, 2023

Bybit's report reveals a significant move of institutional investors towards stablecoins, with a potential shift back to Bitcoin...

Graphic showing Arbitrum DAO's budget increase and the funded blockchain projects.

Arbitrum DAO Boosts Grant Program Budget by $23M to Support 56 Projects

December 4, 2023

Arbitrum DAO's decision to expand its grant budget by $23.4 million marks a really significant step in supporting...

Graphic representation of the address poisoning technique used in Safe Wallet crypto scam.

Safe Wallet Users Lose $2M to Address Poisoning Scam in One Week

December 4, 2023

A crypto hacker stole over $2 million from Safe Wallet users in a single week using address poisoning...

An illustration showing the integration of OKX Wallet with DeSyn DeFi protocol.

OKX Wallet Integrates DeSyn DeFi Protocol to Enhance User Experience

December 3, 2023

OKX Wallet's integration with DeSyn DeFi protocol marks a significant step in offering advanced decentralized financial services to...

Press Releases

David Ferrucci next to the Elemental Cognition brand emblem.

BM Watson’s Lead Developer Secures $60M for New AI Venture, Elemental Cognition

August 18, 2023

David Ferrucci, has raised a remarkable $60M for his AI startup. The company brings forward two pioneering chatbot solutions designed...

pulse5

Amsterdam Gets with the Dutch Blockchain Days the Biggest Event of the Benelux in the Field of Blockchain, Crypto Currencies, NFTs and Other Web3 Developments

May 8, 2023

Discover the future of blockchain, crypto, NFTs, and Web3 at Dutch Blockchain Days, the largest event in Benelux.

pulse4

Korea Blockchain Week 2023 Set to Push the Boundaries after Record-Breaking 2022 Event

May 8, 2023

Korea Blockchain Week 2023 returns after a highly successful 2022 event, featuring leading experts and the latest trends in blockchain...

pulse3

Istanbul Will Be Hosting Eurasia’s Largest Blockchain Event Once again on May 8–11, 2023

May 8, 2023

Join Eurasia's largest blockchain event, the Blockchain Economy Istanbul Summit, May 8-11, 2023, and discover the future of financial technology.

View All
BTC-Pulse LogoTransparent

© 2023 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

©2023 BTC-PULSE – All right Reserved.

No Result
View All Result
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise