TonBit announced the prevention of a crash in the TON Virtual Machine after discovering a serious vulnerability on Monday, July 21.
Discovery of Vulnerability
TonBit reported a critical vulnerability that could have led to denial-of-service attacks across the network. The bug involved the INMSGPARAM instruction, which could be exploited to inject false message parameters, allowing attackers to crash the virtual machine at runtime.
Impact on Ecosystem
Exploiting this vulnerability could halt the execution of smart contracts and disrupt decentralized applications (dApps) operating on TON. This would significantly affect the large miniapp ecosystem on Telegram, many of which rely on TON for their infrastructure.
Reward for Efforts
For their work, TonBit earned a bug bounty from the TON Core development team. This was the third time the firm received such recognition, as they were able to deliver patches before malicious actors were aware of the vulnerabilities.
Ensuring the security and robustness of the TON ecosystem remains a top priority for TonBit, emphasizing the importance of collaboration with the TON Core team.