You can check the website statistics yourself or request them from us at [email protected]
On this platform, only organic high-quality traffic
Bitcoin
$ 30,725

White Hat Hackers Awarded $300K After Uncovering Critical Chainlink VRF Vulnerability

Decentralized oracle network Chainlink has recognized white hat hackers Zach Obront and Or Cyngiser of Trust by awarding them $300,000 for identifying a critical vulnerability in its Verifiable Random Function (VRF) product. The VRF feature enables smart contracts to access tamper-proof random values while maintaining a high level of security.

This discovery of a significant bug comes at a time when Chainlink is experiencing increased institutional adoption of its Cross-Chain Interoperability Protocol (CCIP) technology. Noteworthy traditional institutions, including Swift, Vodafone, and South Korea’s largest gaming company, have recently embraced Chainlink’s technology. The vulnerability identification and subsequent reward underline the importance of ongoing security efforts in the blockchain and decentralized finance space.

Uncovered Potential for Manipulation

Chainlink Labs reported that Obront and Cyngiser discovered a critical issue in which a malicious VRF subscription owner could potentially disrupt the proper generation of random values for users. This could be achieved by blocking and rerolling until a desired outcome occurred, posing a significant smart contract vulnerability.

While the specific conditions needed to exploit this loophole were somewhat specific, the vulnerability compromised the fundamental functionality of Chainlink VRF, which is to provide transparent and verifiable on-chain randomness. The primary risk stemmed from a compromised or malicious subscription owner, a role typically controlled by the decentralized app utilizing VRF. The identified vulnerability underscores the importance of continuous vigilance and prompt action in maintaining the security of decentralized systems.

Mitigation Implemented, $300K Bounty Paid

Following consultations with the researchers, Chainlink swiftly implemented a fix to ensure the delivery of randomness, even if a subscription owner attempts to exploit the vulnerability. In recognition of their responsible disclosure, Obront and Cyngiser were awarded $300,000, a payout that ranks among the top 10 in Immunefi’s history.

Chainlink actively runs bug bounty programs on platforms like HackerOne and Immunefi, providing incentives for security researchers to identify and report vulnerabilities in its systems. The network has disbursed over $500,000 to date across more than 75 resolved reports.

In addition to bug bounty programs, Chainlink has engaged in crowdsourced audits on platforms like Code4rena to further bolster security measures. These proactive steps highlight Chainlink’s commitment to securing its reputation for reliability and transparency, especially as it experiences increased adoption in the decentralized finance and blockchain space.

Increasing Real-World Use Cases

Chainlink’s Verifiable Random Function (VRF) is a crucial component for decentralized applications (dApps) like Axie Infinity, PancakeSwap, and Aavegotchi, providing a layer of security for smart contracts. Additionally, Chainlink’s Cross-Chain Interoperability Protocol (CCIP) facilitates communication between different blockchains, overcoming a significant hurdle in decentralized finance (DeFi). Notably, major institutions such as Swift and Vodafone have adopted Chainlink’s technology for tokenization, indicating a growing trust in its capabilities.

As decentralized finance continues its rapid expansion, the security and interoperability solutions offered by Chainlink are likely to see increased real-world application. Responsible disclosure and timely mitigation of issues, such as the recent VRF vulnerability, are crucial for maintaining reliability, especially as the use cases for Chainlink’s technology scale up in the evolving landscape of decentralized finance.

Related Posts

Leave a Reply

Confirm now and stay with our news

What we write about

I want to save money. Will cryptocurrency work?

Cryptocurrency is essentially virtual money that operates in a decentralized manner, not through a bank but directly on multiple independent computers.

Every cryptocurrency has two main components: the units of digital exchange called “coins” and the network within which the exchange takes place. These units can be transferred between wallets and exchanged on exchanges. The networks in which these coins exist are called blockchains, which translates to “chains of blocks.”

Latest Articles

Crypto Loans Platform Nexo Integrates Koinly to Ease User Tax Obligations
04.12.2023By
Digital Ruble Will Spark Russia’s ‘Biggest Monetary Reforms Since the 1990s’
04.12.2023By
Credefi Finance Integrates with XRP Ledger
04.12.2023By

Latest news

Crypto Loans Platform Nexo Integrates Koinly to Ease User Tax Obligations
04.12.2023
Digital Ruble Will Spark Russia’s ‘Biggest Monetary Reforms Since the 1990s’
04.12.2023
Credefi Finance Integrates with XRP Ledger
04.12.2023
The global token and blockchain platform CROWN Token Project announced a new NFT collection on its ADOT platform
04.12.2023
Ethereum Exchange Outflows Exceed $1 Billion in 3 Weeks, IntoTheBlock Reports
04.12.2023
Bitcoin Miners Hut 8 and USBTC Complete Merger, Forming New Hut 8 Corp for Upcoming Halving
04.12.2023
Bitcoin Price Nears $41,000 Amid Broader Crypto Rally
04.12.2023
Talos and Uniswap Forge Landmark Deal to Boost DeFi Access for Institutions – Adoption on the Rise?
03.12.2023
Solana DeFi Platform Jupiter Shares Airdrop Allocations – Here’s How to Check Eligibility
03.12.2023
JPMorgan Report Highlights Resurgence in DeFi and NFT Sectors
03.12.2023