• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M
CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

CertiK Discovers a Security Flaw in the Wormhole System on the Aptos Network

user avatar

by Eve Adams

2 years ago


CertiK, a blockchain security platform, reported discovering a vulnerability in the Wormhole system on the Aptos network that could potentially have led to financial losses amounting to $5 million. The flaw was detected and rectified in a timely manner after notifying the Wormhole team, preventing possible exploitation by malicious actors.

According to CertiK, the issue arose due to incorrect implementation of the public(friend) and entry modifiers in the MOVE programming language. The public(friend) modifier restricted function calls to other functions within the same module or specified external accounts, while the entry modifier allowed the function to be called from any external account.

This configuration enabled attackers to create fictitious transactions that would move tokens between accounts without actually transferring funds. This could allow the Ethereum bridge to issue or unlock tokens without the backing of real deposits on the Aptos side. Ultimately, malicious actors could have caused damage up to $5 million had the vulnerability not been identified and addressed promptly.

CertiK provided a detailed report on the vulnerability in video format, enhancing awareness and attention to security issues within the blockchain community.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Arbitrum Governance Proposes Major Funding for Foundation

chest

Arbitrum governance is evaluating a funding proposal for the Arbitrum Foundation, seeking 16 million in real-world assets, 1,700 ETH, and 230 million ARB tokens to support its operations for another year.

user avatarLuis Flores

Crypto Scammers Target 2026 World Cup Fans

chest

TRM Labs warns of emerging crypto scams targeting fans of the 2026 World Cup, including fake ticketing and speculative tokens.

user avatarArif Mukhtar

Ethereum Researchers Introduce SPHINCS for Quantum-Resistant Signatures

chest

Ethereum researchers introduce SPHINCS, a post-quantum signature design for enhancing wallet security against quantum computing threats.

user avatarDavid Robinson

Bitcoin Faces Major Liquidation Event Amid Price Fluctuations

chest

Bitcoin traders faced significant liquidations as the price fluctuated sharply, resulting in nearly $980 million in liquidations within 24 hours.

user avatarMaria Gutierrez

Sky Governance Forum Emphasizes Editorial Policy

chest

The Sky Governance Forum has established a strict editorial policy that focuses on accuracy, relevance, and impartiality.

user avatarAndrew Smith

Ethereum Derivatives Show Bearish Sentiment as Funding Turns Negative

chest

Ethereum derivatives have experienced negative funding rates since June 5, indicating a bearish bias in the market.

user avatarJacob Williams

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.