evm

5 articles
Sort: New Top Best
clear filter
0
RAI
research

An analysis of how bug-fix attempts in the RAI protocol's debt auctions introduced critical vulnerabilities while addressing low-severity issues, alongside technical exploration of EVM bit masking operations and assembly-level smart contract optimization techniques.

VNMRTZ RAI Benjamin Franklin Carl Sagan
mirror.xyz · vnmrtz.eth · 4 hours ago · details
0
vulnerability

A low-severity bug in the TypedMemView library's isValid function was caused by incorrect use of the bitwise NOT instruction instead of the ISZERO instruction in Yul assembly, causing the function to always return true regardless of whether memory bounds were valid. The bug was responsibly disclosed to Nomad, patched by replacing 'not' with 'iszero', and publicly documented.

TypedMemView Nomad Nikita Stupin Immunefi Center for Contemplative Research summa-tx/memview-sol
nikitastupin.com · Nikita Stupin · 4 hours ago · details
0
postmortem

Story Network's postmortem analysis reveals two critical vulnerabilities discovered during mainnet launch. The first issue allowed attackers to create arbitrarily large EVM transaction payloads (>4MB) that would cause validator crashes and network shutdown through JSON marshalling inefficiencies and inadequate block size validation inherited from Octane codebase.

Story Network Story Foundation Cantina Octane Omni Geth CometBFT
story.foundation · WhiteHatMage · 4 hours ago · details
0

A security researcher disclosed critical vulnerabilities in Moonbeam and Aurora EVM-based networks, protecting over $100M in DeFi assets and earning $1M+ in bug bounties through the discovery of delegatecall misuse and design flaws in layer-2 solutions. The article also discusses potential insolvency risks in wrapped token protocols like WETH.

Polkadot Frontier EVM Moonbeam Moonwell Aurora NEAR Protocol WETH Immunefi pwning.eth Ethereum
pwning.mirror.xyz · pwning.eth · 4 hours ago · details
0
bug-bounty

A security researcher disclosed critical vulnerabilities in Moonbeam and Aurora Engine smart contracts, earning record bug bounties ($1M from Moonbeam, $6M from Aurora) by identifying delegatecall misuse and design flaws that put over $100M in DeFi assets at risk.

Moonbeam Aurora Engine NEAR Protocol Moonwell Immunefi WETH pwning.eth
pwning.mirror.xyz · pwning.eth · 4 hours ago · details