CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

user avatar

by Eve Adams

2 years ago


CertiK, a blockchain security platform, reported discovering a vulnerability in the Wormhole system on the Aptos network that could potentially have led to financial losses amounting to $5 million. The flaw was detected and rectified in a timely manner after notifying the Wormhole team, preventing possible exploitation by malicious actors.

According to CertiK, the issue arose due to incorrect implementation of the public(friend) and entry modifiers in the MOVE programming language. The public(friend) modifier restricted function calls to other functions within the same module or specified external accounts, while the entry modifier allowed the function to be called from any external account.

This configuration enabled attackers to create fictitious transactions that would move tokens between accounts without actually transferring funds. This could allow the Ethereum bridge to issue or unlock tokens without the backing of real deposits on the Aptos side. Ultimately, malicious actors could have caused damage up to $5 million had the vulnerability not been identified and addressed promptly.

CertiK provided a detailed report on the vulnerability in video format, enhancing awareness and attention to security issues within the blockchain community.

Tier I

Sector: #18291

Sealed Cache Room

Resource Cache

Resource Cache

Tier I

Requires 25% Tier Progress to Claim
Meme Cache

Meme Cache

Tier I

Requires 50% Tier Progress to Claim
Equipment Cache

Equipment Cache

Tier I

Requires 75% Tier Progress to Claim

After collecting, caches will be stored in your inventory and can be opened with Keys.

Other news

Bitcoin Red Team Established to Tackle AI-Driven Security Threats

chest

The Bitcoin Red Team has been established to proactively identify AI-assisted security vulnerabilities in the Bitcoin ecosystem.

user avatarTando Nkube

TON Validators Prepare for Configuration Vote on New Collator Architecture

chest

TON validators are updating their node software and mytonctrl tooling for a configuration vote on a new collator architecture scheduled for August 21 at 0800 UTC.

user avatarKofi Adjeman

Aave's EMode: Efficiency and Risk in DeFi Lending

chest

Aave's EMode feature allows for efficient borrowing among correlated assets but also increases the risk of liquidation during market stress.

user avatarSatoshi Nakamura

Avalanche Surpasses $3 Billion in Tokenized Real-World Assets

chest

Avalanche's tokenized real-world asset value has surpassed $3 billion, marking a significant milestone in its development as a platform for institutional finance.

user avatarNguyen Van Long

Aave's Debt Concentration Raises Concerns Amid Ethereum Volatility

chest

Aave's debt profile shows that a small number of loan positions account for a significant portion of its total outstanding debt, raising concerns about risk concentration.

user avatarJesper Sørensen

Shift in Airdrop Strategy Reflects Changing Market Dynamics

chest

Optimism's decision to reallocate tokens indicates a shift away from broad airdrops towards more strategic ecosystem investments.

user avatarLucas Weissmann

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.