$32M vulnerability in Perpetual Protocol uncovered by Chainlight nets $10k in white hat rewards

Share This Post

Blockchain security firm Chainlight said it received a $10,000 bounty for uncovering a potential vulnerability that could have jeopardized $32 million in customer funds on Optimism-based decentralized exchange (DEX) Perpetual Protocol.

In a Nov. 9 post on social media platform X (formerly Twitter), Chainlight detailed how it reported a critical bug in Perpetual Protocol’s “AccountBalance” contract last year. According to the firm, the contract is a pivotal component that “serves as the protocol’s brain for calculating position values.”

The vulnerability posed a severe threat to the DEX, placing the entire $32 million USDC held by the protocol at risk of being misappropriated.

This flaw had the potential to allow bad actors to swiftly move the entire $32 million within a five-minute timeframe, leaving the protocol with insufficient time to deploy effective security measures.

The white-hat hacker detailed that an attacker could manipulate asset prices through a pump-and-dump strategy, exploiting volatile price actions to place position orders outside the permissible range and immediately profit, resulting in the protocol’s bad debt.

In acknowledgment of its efforts, Chainlight said it got $10,000 worth of Perpetual Protocol’s native PERP tokens.

Perpetual Protocol’s low bounty draws critics

The $10,000 bounty has generated several reactions from the crypto community, who argue it was insufficient considering the protected amount.

Trust, the head of security at blockchain auditing firm TrustSec, labeled the reward as another instance of a bounty scam, asserting that it did not adequately reflect the gravity of the situation.

Protocol Specialist at Coinbase, Viktor Bunin, also questioned why the bounty was so low.

Juancito, a blockchain security researcher, criticized the meager bounty offer, suggesting that white-hat hackers’ contributions to the ecosystem are not appropriately valued.

Similarly, Blurpoint noted that white-hat efforts often go unappreciated, emphasizing the importance of acknowledging and adequately compensating these contributions.

Web3 security expert CryptoBandit shared a comparable experience, recounting how he shared a critical vulnerability that could have led to $40 million in losses with the DEX but only got $30,000 as bounty rewards.

This situation underscores the challenges white-hat hackers face within the industry, as they are not properly incentivized to help crypto platforms expose vulnerabilities within their codes.

The post $32M vulnerability in Perpetual Protocol uncovered by Chainlight nets $10k in white hat rewards appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

QCP Capital: Crypto Rally Extends, Supported by ETF Inflows

Bitcoin (BTC) and ether (ETH) surged for a third consecutive day, supported by strong inflows into spot exchange-traded funds (ETFs), according to a weekend analysis by QCP Capital The firm reported

SUI Continues Bullish Run, Surges 45% In The Past Week — What Next?

The interest rate cut by the US Federal Reserve has been one of the biggest stories in the crypto space this week, with most large-cap assets making something of a recovery in the past few days As a

NFT Sales Climb 7.33%, Mythos, Blast, and Solana Lead the Charge

Non-fungible tokens (NFTs) had quite the boost this week, with sales climbing by 733% compared to the previous one, totaling $7713 million The number of NFT sellers skyrocketed by 9568%, while buyers

BlackRock Receives SEC Greenlight For Spot Bitcoin ETF Options

The United States Securities and Exchange Commission (SEC) has approved BlackRock’s proposal to offer options trading for its spot Bitcoin ETF (exchange-traded fund) BlackRock’s ETF

Stablecoin Market Adds $1B in Six Days as Major Tokens Expand

In the past month, the stablecoin market has kept its upward momentum, with four out of the top five US dollar-pegged tokens increasing in supply Since Sept 15, the stablecoin economy has expanded by

Bitcoin Indicator Signals ‘Shift To Bullish Territory’ – Can BTC Break Past $65,000?

Bitcoin has experienced a significant price surge since Tuesday, following the Federal Reserve’s announcement of a 50 bps interest rate cut This move pushed BTC past the critical $62,000 mark,