Arbitrum Pays 400 $ETH Vulnerability Bounty to Anonymous Whitehat 0xriptide

An anonymous whitehat, "0xriptide," has been rewarded 400 $ETH (about $520,000) for discovering a vulnerability in Arbitrum's payment code that could have resulted in the loss of $250 million. 0xriptide said his initial search for the Arbitrum exploit began a few weeks ago ahead of the Arbitrum Nitro upgrade. Upon his initial investigation, he found a vulnerability where the bridging contract was able to accept deposits, even though the contract was initialized previously. After digging into the uninitialized address, 0xriptide found that a hacker would be able to set their own address as the bridge, mimicking the actual contract, and steal all the incoming $ETH deposits from Etheruem to Arbitrum Nitro.

Source

Arbitrum

Ethereum

Security Incidents

In This Article

Related News
US spot Ethereum ETFs see largest outflows since late July US spot Ethereum ETFs see largest outflows since late July
US spot bitcoin ETFs logged $52.8 million in net outflows yesterday, breaking four-day streak of inflows US spot bitcoin ETFs logged $52.8 million in net outflows yesterday, breaking four-day streak of inflows
US spot Bitcoin ETFs logged $187 million in net inflows yesterday as BTC hovers around $60,000 US spot Bitcoin ETFs logged $187 million in net inflows yesterday as BTC hovers around $60,000
US spot bitcoin ETFs return to positive flows, adding $28 million US spot bitcoin ETFs return to positive flows, adding $28 million
Bitcoin, ether remain subdued as markets process underwhelming US economic data Bitcoin, ether remain subdued as markets process underwhelming US economic data
Latest News More More
1 Day Ago Mt. Gox pushes repayment plan deadline to October 2025
1 Day Ago Ripple co-founder donates $1 million in XRP to Harris campaign
2 Days Ago Web3 momentum accelerates at Binance Blockchain Week 2024 in Dubai
2 Days Ago Justin Sun elected Prime Minister of Liberland micronation
3 Days Ago Cardano hosts first smart contract legally enforceable in Argentina
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open