blockchain

8 articles
Sort: New Top Best
clear filter
0 6/10
Sui
vulnerability

A high-severity DoS vulnerability in Sui's Narwhal consensus layer allowed attackers to crash validator nodes via Out-of-Memory (OOM) attacks by sending a single malicious request with 1.2M certificate digests (37MB payload), bypassing the absence of response limits and timeout handling in the get_certificates() function. The vulnerability was patched by removing the vulnerable GetCertificates and GetPayloadAvailability handlers, with the researcher earning a $50,000 SUI bounty.

Sui Immunefi @F4lt Narwhal Bullshark Move MystenLabs
immunefi.com · unknown · 4 hours ago · details
0 8/10
vulnerability

Acala's Homa staking protocol contained an unbounded loop in the process_redeem_requests function that could be exploited by an attacker with 12,000+ DOT to create 22,000 redemption requests, causing the validator's on_initialize function to exceed block finalization time limits and halt the entire parachain's block production.

Acala Polkadot Homa Immunefi @Lastc0de Acala Foundation
immunefi.com · Lastc0de · 4 hours ago · details
0
news

This appears to be a landing page or navigation hub for Fraxlend, a DeFi lending protocol, featuring content from Obsidian Audits. The page lacks substantive technical content about specific vulnerabilities or findings.

Fraxlend Obsidian Audits
mirror.xyz · Juan · 4 hours ago · details
0
bug-report

Security researcher Merkle Bonsai documents a hybrid NFT vulnerability in Ocean Protocol where on-chain Data Description Objects (DDOs) can be modified to enable attacks, exploiting the protocol's reliance on modifiable on-chain data structures. The article discusses how these hybrid attacks work and references previous analysis of Ocean Protocol's design vulnerabilities.

Ocean Protocol Merkle Bonsai Immunefi Oasys Ethereum Eco Bandai Namco DoubleJump.japan
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
Eco
bug-bounty

A collection of blockchain security research and bug reports covering vulnerabilities in Oasys L2 blockchain, Eco's lockup contracts, and hybrid NFT attacks on Ocean Protocol. Multiple issues were identified and reported through Immunefi's bug bounty program.

Oasys Ethereum Immunefi Bandai Namco DoubleJump.japan Eco Ocean Protocol Merkle Bonsai
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
bug-bounty

A collection of security research articles covering vulnerabilities in blockchain projects including Oasys (a gaming-focused Ethereum L2), Eco's lockup contracts, and Ocean Protocol's hybrid NFT implementation where on-chain data modifications can be exploited. Multiple bugs are documented with disclosure timelines and remediation details.

Oasys Merkle Bonsai Immunefi Bandai Namco DoubleJump.japan Eco Ocean Protocol
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
bug-report

Security research analyzing a hybrid NFT vulnerability in Ocean Protocol where on-chain Data Description Objects (DDOs) stored on blockchain can be modified to enable attacks. The article discusses design flaws and issues discovered in Ocean Protocol's implementation, with bug bounty disclosures via Immunefi.

Ocean Protocol Immunefi Merkle Bonsai Oasys Eco Bandai Namco DoubleJump.japan
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
postmortem

Story Network's postmortem analysis reveals two critical vulnerabilities discovered during mainnet launch. The first issue allowed attackers to create arbitrarily large EVM transaction payloads (>4MB) that would cause validator crashes and network shutdown through JSON marshalling inefficiencies and inadequate block size validation inherited from Octane codebase.

Story Network Story Foundation Cantina Octane Omni Geth CometBFT
story.foundation · WhiteHatMage · 4 hours ago · details