Hacker Scoops Up $2 Million Bounty After Spotting Fatal Flaw In Ethereum Rollup

Share This Post

A hacker has made off with $2 million in bug bounty after finding an alarming vulnerability with the Ethereum network. This bug could have been very bad if it had been found by black hat hackers who could have exploited the digital asset for billions of dollars worth of ETH. Instead, a ‘grey hat’ hacker popularly known as Saurik informed the Ethereum team of the vulnerability, netting himself a sizable reward in return.

Finding The Vulnerability On Ethereum

Hacker Saurik had found the vulnerability on Optimism, an Ethereum layer 2 rollup solution. The hacker himself published a report as to how he found the vulnerability on the solution. Looking through nano payments protocols on the rollup, he had found a vulnerability that could allow an attacker to withdraw unbridled a ‘virtually unlimited’ amount of ETH from the solution.

Related Reading | TA: Ethereum Overcome Hurdles, Why 100 SMA Is The Key

It was similar to the attack method deployed on popular smart contracts blockchain Solana that resulted in the $353 million hacks on Wormhole. Optimism, like Wormhole, mint what are known as “Wrapped Ether.”  Users deposit their Ether on the smart contract to basically serve as collateral and they are even these tokens that only exist on Optimism’s network. They then use nano payments protocol to make transactions faster and quicker.

ETH recovers above $3,100 | Source: ETHUSD on TradingView.com

Saurik who is famously known for developing the Jailbroken iOS had confirmed the vulnerability. However, instead of exploiting the vulnerability for his own personal gain, the self-styled grey hat hacker had reported it to the Optimism devs. In return, Saurik was rewarded with a $2 million bounty for his altruism, which has helped to make the network and layer 2 rollup safer for users.

Debunking Popular Rumors

After news of the vulnerability and subsequent bounty payment broke, there have been rumors circulating regarding what an attacker could have done with it if they chose to not report it to the devs. The most popular of these has been that the attacker would have been able to withdraw an unlimited amount of ETH from the network. While this has some merit to it, it is largely false.

Firstly, the vulnerability exists on a layer 2 rollup solution Optimism. While the protocol exists on the ethereum network, it is not the network itself. This means that the vulnerability was localized to the protocol alone. So while an attacker would have been able to exploit this to withdraw an ‘unlimited’ amount of ETH, they could only withdraw the available balance on the Optimism address.

Related Reading | Will Ethereum Hit $7k This Year? Finder’s Panel Says Yes

Nevertheless, it is still no secret that the results would have been devastating for users of the layer 2 protocol if a black hat hacker had found the vulnerability. This event speaks volumes about the usefulness of bug bounties. While the rewards for these bounties may seem too large at first, one must think about what the alternative would be if there was no incentive for hackers to come forward with their findings. White hat hackers no doubt help to save millions, if not billions, of dollars every year.

Featured image from Gagadget, chart from TradingView.com

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

UBS Predicts ‘No Landing’ for US Economy — What It Means for Markets and Inflation

Global investment bank UBS is forecasting a “no landing” scenario for the US economy, where growth continues and inflation remains stable, defying predictions of recession With

Shiba Inu To Double? Analyst Predicts 200% Price Hike – Details

Although flying under the radar concerning price movements during Bitcoin’s recent bull run, the dog-themed cryptocurrency Shiba Inu (SHIB) was able to appreciate 818% in the last week while

Going Crypto: Putin Reveals BRICS’ Shift Toward Digital Currency In Investment Strategy

Adopting crypto has been one of the key discussions among BRICS member states in a business forum held in Moscow on Friday The BRICS (Brаzil, Russiа, Indiа, Chinа, аnd South Africа) bloc seeks

Russia Vows to Launch Domestic Payment System to Render Western Sanctions Obsolete

Russia is determined to create a domestic payment system to conduct trade and international transactions free from current disruptions Mikhail Mishustin, Prime Minister of Russia, stated that this

Bitcoin Powers Wealth: Nearly 50% Of Crypto Millionaires Owe Success To BTC

Between 2023 and 2024, the number of Bitcoin millionaires climbed by almost 111%, reaching 85,400 or 496% of all crypto millionaires in 2024 Regarding cryptocurrency billionaires, five of the six

FLOKI Breaks Out Of Downtrend: Analyst Predicts 200% Rally To New All-Time High

Meme coin FLOKI has also benefited from recent inflows into the crypto markets, which has left many cryptocurrencies posting gains in both the 24-hour and seven-day timeframes  Notably, this inflow