Aurora pays $6M bug bounty to ethical security hacker through Immunefi

Share This Post

Over $200 million worth of users’ funds could have been at risk if the whitehat chose to exploit the vulnerability for personal gain instead of reporting it to developers.

On Tuesday, Ethereum (ETH) bridging and scaling solution Aurora announced it had paid out a $6 million bounty to ethical security hacker pwning.eth, who discovered a critical vulnerability in the Aurora Engine. The exploit allegedly placed over $200 million worth of capital at risk. The sum was paid in collaboration with Immunefi, a leading platform for Web 3.0 bug bounties, with $145+ million bounties available and $45+ million bounties paid out.

On April 26, Immunefi received a report from pwning.eth about a critical flaw in the Aurora Engine that would have enabled the infinite minting of ETH in the Aurora Ethereum Virtual Machine as to drain and siphon the corresponding nested ETH (nETH) pool on NEAR. At the time of discovery, the pool contained more than 70,000 ETH worth at least $200 million.

Mitchell Amador, founder and CEO at Immunefi, said: “Hats off to Aurora and pwning.eth for the flawless overall processing of the report. The bug was quickly patched, with no user funds lost.” Aurora had launched a bug bounty program with Immunefi just one week before discovering the security vulnerability. Meanwhile, Frank Braun, head of security at Aurora Labs, commented: “We look at the bug bounty program as the last step in a layered defense approach and will use this bug as a learning opportunity to improve earlier steps, like internal reviews and external audits.

Though arguably innovative, cross-chain communication protocols have been a prime target of hackers as of late. In February, one of the largest decentralized finance hacks occurred when the Wormhole token bridge was drained of over $321 million in digital assets after hackers exploited an infinite minting glitch between its wrapped ETH and ETH pool. 

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Crypto Shorts Suffer $147 Million Squeeze As Bitcoin Returns Above $63,000

Data shows the cryptocurrency sector as a whole has witnessed a high amount of liquidations following the volatility Bitcoin and others have gone through Bitcoin Has Recovered Back Above The $63,000

Boerse Stuttgart Digital, DZ Bank Expand Crypto Access to 700 German Banks

Boerse Stuttgart Digital is collaborating with DZ Bank to bring secure cryptocurrency trading and storage to over 700 cooperative banks across Germany The move marks a significant step toward

Bitcoin Price Rally Faces Key Resistance: Will Whale Shorts Trigger A Market Pullback?

As the broader cryptocurrency market experiences notable gains following the Federal Reserve’s rate cuts, Bitcoin (BTC) has reached a price of $63,670 on Thursday, marking substantial bullish

German Authorities Shut Down 47 Crypto Exchange Services in Cybercrime Crackdown

German authorities have dismantled 47 exchange services involved in facilitating anonymous crypto transactions for criminal activities These platforms bypassed anti-money laundering protocols,

SEC Reviews Proposal for New Bitcoin, Ether ETF Custodians

The US Securities and Exchange Commission (SEC) is seeking public input on a proposal by Cboe BZX Exchange to add new custodians for bitcoin and ethereum exchange-traded funds (ETFs) The plan aims to

Terraform Labs secures court approval to wind-down operations after settling with SEC

Terraform Labs received court approval to wind down its operations in bankruptcy after settling a US Securities and Exchange Commission (SEC) lawsuit, Reuters reported Sept 19 US Bankruptcy Judge