Eco

mirror.xyz · merkle_bonsai · 4 hours ago · bug-bounty
0 net
AI Summary

A collection of blockchain security research and bug reports covering vulnerabilities in Oasys L2 blockchain, Eco's lockup contracts, and hybrid NFT attacks on Ocean Protocol. Multiple issues were identified and reported through Immunefi's bug bounty program.

Entities
Oasys Ethereum Immunefi Bandai Namco DoubleJump.japan Eco Ocean Protocol Merkle Bonsai
About Activity Share Home Explore New post Dashboard Newsletter Search... Ctrl + K Merkle Bonsai More from Merkle Bonsai Merkle Bonsai Jan 25 Oasys blockchain report study. Everybody goes to jail IntroWhat is Oasys? It is both L2 blockchain and ecosystem that is based on forked Ethereum protocol. It is super-limited, with no possibility to deploy custom contracts, and is specifically aimed to solve blockchain gaming stuff. I guess they are actually based in Japan, as they have events in Tokyo and Japanese partnerships, like Bandai Namco (guys who own Pacman and Gundam) and DoubleJump.japan. Their bug bounty was present at Immunefi in first half of 2023; sadly, they decided to - tempor... B Merkle Bonsai Jul 13 Bug report study: Eco Lockup contract Storytelling partAt the moment of publication Eco is using new contracts which are not impacted by both of vulnerabilities; fix is covered with this PR dated Dec 10, 2022.2 bugs are covered within this article. I reported high (as I considered) bug last December, but project told they already fixed several things, including this issue, after another bug report, and their actual addresses are handling all of cases properly.Well, it happensHowever, their Immunefi Bug Bounty page and GitHub repo... Merkle Bonsai Nov 8 There's plenty of DIDs in the Ocean: Hybrid NFT on Ocean Protocol bug report The bugs sometimes hide in interesting places. Hybrid attacks are very interesting things, where projects rely on on-chain data that may be actually modified. I wrote about Ocean Protocol design before, in this article, so you can use it for some extra explanations. Let’s take e.g. this dataset. If you will enable debug mode, you will see its Data Description Object, or DDO (maybe it’s Data Description, but you got the idea) that looks like JSON below. It is mostly stored on a blockchain, and... View more Sign in Smart contract & blockchain whitehat Subscribe Subscribe to Merkle Bonsai Subscribe <100 subscribers