iOS jailbreak dev wins $2M bounty for finding critical Optimism bug

Share This Post

Ethereum scaling startup Optimism disclosed a “critical bug” fix in the project’s Geth fork that would have allowed malicious hackers to create infinite ETH

Developers from the Ethereum Layer 2 scaling project Optimism announced that a “critical bug” had been identified and subsequently patched earlier this month.

The bug, which could have enabled hackers to create as much ‘ETH’ in a Optimism account balance as they wished, was first discovered by white hat hacker and iOS jailbreak software Cydia developer Jay Freeman.

In a deep-dive blog post, Freeman explained that the bug, “would allow an attacker to replicate money on any chain using their ‘OVM 2.0’ fork of go-ethereum”. For his efforts Freeman was awarded one of largest bug bounties to date, netting a total reward amount of $2,000,042

According to the Optimism team, “The bug made it possible to create ETH on Optimism by repeatedly triggering the SELFDESTRUCT opcode on a contract that held an ETH balance.”

In a blog post, the Optimism team noted that its chain history showed that the bug had not been exploited, except for an accidental activation by a staffer at Ethereum data startup Etherscan, but “no usable excess was generated.”

“A fix for the issue was tested and deployed to Optimism’s Kovan and Mainnet networks (including all infrastructure providers) within hours of confirmation,” the team said, thanking Infura, QuickNode, and Alchemy for their fast response times.

“We also alerted multiple vulnerable Optimism forks and bridge providers to the presence of the issue. These projects have all applied the required fix.”

Late last year Optimism removed its whitelist, allowing for any developer to start building projects on the Optimism network. Prior to this, the network was only accessible to specific projects such as Uniswap and Synthetix. This limitation made it easier for developers to detect and resolve potential bugs

Related: MakerDAO launches biggest ever bug bounty with $10M reward

Optimism is a Layer 2 scaling solution for the Ethereum network, employing “optimistic rollups” that aggregate transactions outside of the Ethereum blockchain.

This provides the benefits of reducing slippage, decreasing transaction costs and vastly improving transaction speeds. However, as this bug has made clear, while Layer 2 protocols offer improvements in efficiency, security during ongoing development remains a common point of concern.

While this bounty is one the largest to have been paid out so far, MakerDAO has just announced that it will be offering a maximum bounty of $10M to anyone who can point out critical security threats in its smart contracts. This is the largest series of bug bounties ever to have been hosted on bug bounty platform Immunefi.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

UBS Predicts ‘No Landing’ for US Economy — What It Means for Markets and Inflation

Global investment bank UBS is forecasting a “no landing” scenario for the US economy, where growth continues and inflation remains stable, defying predictions of recession With

Shiba Inu To Double? Analyst Predicts 200% Price Hike – Details

Although flying under the radar concerning price movements during Bitcoin’s recent bull run, the dog-themed cryptocurrency Shiba Inu (SHIB) was able to appreciate 818% in the last week while

Going Crypto: Putin Reveals BRICS’ Shift Toward Digital Currency In Investment Strategy

Adopting crypto has been one of the key discussions among BRICS member states in a business forum held in Moscow on Friday The BRICS (Brаzil, Russiа, Indiа, Chinа, аnd South Africа) bloc seeks

Russia Vows to Launch Domestic Payment System to Render Western Sanctions Obsolete

Russia is determined to create a domestic payment system to conduct trade and international transactions free from current disruptions Mikhail Mishustin, Prime Minister of Russia, stated that this

Bitcoin Powers Wealth: Nearly 50% Of Crypto Millionaires Owe Success To BTC

Between 2023 and 2024, the number of Bitcoin millionaires climbed by almost 111%, reaching 85,400 or 496% of all crypto millionaires in 2024 Regarding cryptocurrency billionaires, five of the six

FLOKI Breaks Out Of Downtrend: Analyst Predicts 200% Rally To New All-Time High

Meme coin FLOKI has also benefited from recent inflows into the crypto markets, which has left many cryptocurrencies posting gains in both the 24-hour and seven-day timeframes  Notably, this inflow