• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M
CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

user avatar

by Eve Adams

2 years ago


CertiK, a blockchain security platform, reported discovering a vulnerability in the Wormhole system on the Aptos network that could potentially have led to financial losses amounting to $5 million. The flaw was detected and rectified in a timely manner after notifying the Wormhole team, preventing possible exploitation by malicious actors.

According to CertiK, the issue arose due to incorrect implementation of the public(friend) and entry modifiers in the MOVE programming language. The public(friend) modifier restricted function calls to other functions within the same module or specified external accounts, while the entry modifier allowed the function to be called from any external account.

This configuration enabled attackers to create fictitious transactions that would move tokens between accounts without actually transferring funds. This could allow the Ethereum bridge to issue or unlock tokens without the backing of real deposits on the Aptos side. Ultimately, malicious actors could have caused damage up to $5 million had the vulnerability not been identified and addressed promptly.

CertiK provided a detailed report on the vulnerability in video format, enhancing awareness and attention to security issues within the blockchain community.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

VOOI Price Predictions Amid Market Volatility

chest

Experts provide various price predictions for the VOOI token as it launches amidst a weak crypto market.

user avatarKenji Takahashi

Uniswap Community to Vote on Burning 100 Million UNI Tokens

chest

The Uniswap community is preparing for a historic governance vote to burn 100 million UNI tokens and activate a new fee mechanism.

user avatarDiego Alvarez

Binance Alpha Introduces RTX Token for Early Crypto Investors

chest

Binance Alpha has added the RTX token to its exclusive onchain trading service, providing early access to promising crypto projects.

user avatarMaria Fernandez

Caroline Ellison Transferred to Community Confinement Following 11 Months in Prison.

chest

Caroline Ellison, former CEO of Alameda Research, was moved to community confinement after serving 11 months of her two-year sentence.

user avatarGustavo Mendoza

China's Mining Crackdown Causes Bitcoin Hashrate to Plummet

chest

Bitcoin miners in China's Xinjiang province are shutting down operations due to renewed regulatory pressure from Beijing, leading to a significant drop in hashrate.

user avatarRajesh Kumar

Investors Urged to Consider Hidden Costs in Index Fund Evaluation

chest

Investors are encouraged to consider tracking difference and tracking error as critical metrics for evaluating index fund performance.

user avatarLuis Flores

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.