Critical $5 Million Security Flaw in Aptos Wormhole Bridge - Certik (2024)

CertiK discovered and patched a major security flaw in the Wormhole bridge on the Aptos network, potentially saving $5 million.

This vulnerability could have let an attacker create fake token transfers, but CertiK’s swift action secured users’ funds.

Aptos’ Wormhole Bridge $5M Security Flaw Discovered

CertiK found the flaw in the Wormhole bridge on Aptos and reported it to the Wormhole team. The problem stemmed from incorrectly implementing the MOVE programming language’s ‘public(friend)’ and ‘entry’ modifiers.

The ‘public(friend)’ modifier allows functions to be called by others within the same module or by specified external accounts. In contrast, the ‘entry’ modifier allows any external account to call a function.

The bridge had a function called ‘publish_event,’ meant to announce events like token transfers. This function should only have been callable by other functions within the same module or certain specified external entities. However, the function was modified by both ‘public(friend)’ and ‘entry,’ making it possible for anyone to call ‘publish_event,’ even if they were not approved.

This flaw could have let an attacker create fake transactions, appearing to move tokens from one account to another without moving actual tokens. These fake events could have caused the Ethereum version of the bridge to mint or unlock tokens without real deposits backing them on the Aptos side, potentially draining up to $5 million.

CertiK’s Rapid Action to Patch and Secure the Wormhole Bridge

After discovering the flaw, CertiK immediately informed the Wormhole team on December 5, 2023. The team developed and tested a patch to close the security loophole. They informed the protocol’s Guardians, who approved the patch through a multi-signature vote. The protocol’s Aptos contract was then upgraded, securing the bridge. This process took approximately three hours.

Read more: Crypto Scam Projects: How To Spot Fake Tokens

Sponsored

Sponsored

Besides removing the ‘entry’ keyword from the publish_event function, the new patch also restricted the ‘governor rate limits’ on Aptos from $5 million to $1 million. This strategic move aimed to limit potential losses from future exploits. CertiK noted that current usage is below $1 million daily, so the rate limit should not affect most users.

“This case study not only underscores the critical role of proactive security practices but also celebrates the power of open source software in raising security and transparency standards across the Web3 world,” CertiK added.

Wormhole also conducted a retrospective analysis to check if the issue affected any user funds. The study confirmed no funds were illicitly transferred, and users’ balances remained safe.

This isn’t the first time Wormhole has faced security challenges. In 2022, the bridge lost over $321 million due to a bug in the Solana part of the bridge, allowing an attacker to mint unbacked tokens. Despite this setback, Wormhole improved its security practices and reclaimed $1 billion in total value locked.

Trusted

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that ourTerms and Conditions,Privacy Policy, andDisclaimershave been updated.

Critical $5 Million Security Flaw in Aptos Wormhole Bridge - Certik (2024)
Top Articles
Top 5 Reasons Why People Blog
Enabling TLS 1.2 on web browsers
Star Wars Mongol Heleer
Www.craigslist Virginia
Katmoie
Aadya Bazaar
Usborne Links
Jesus Calling December 1 2022
Shorthand: The Write Way to Speed Up Communication
A Complete Guide To Major Scales
Women's Beauty Parlour Near Me
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Best Cheap Action Camera
Rubfinder
Horned Stone Skull Cozy Grove
How Many Cc's Is A 96 Cubic Inch Engine
WWE-Heldin Nikki A.S.H. verzückt Fans und Kollegen
Jvid Rina Sauce
24 Hour Walmart Detroit Mi
Missed Connections Dayton Ohio
Driving Directions To Bed Bath & Beyond
Gemita Alvarez Desnuda
Free Online Games on CrazyGames | Play Now!
Morristown Daily Record Obituary
Fsga Golf
Qual o significado log out?
Craigslist Northfield Vt
Www.dunkinbaskinrunsonyou.con
Renfield Showtimes Near Paragon Theaters - Coral Square
Strange World Showtimes Near Savoy 16
Papa Johns Mear Me
Dal Tadka Recipe - Punjabi Dhaba Style
Desales Field Hockey Schedule
Kiddie Jungle Parma
Productos para el Cuidado del Cabello Después de un Alisado: Tips y Consejos
Flixtor Nu Not Working
Smartfind Express Henrico
Cruise Ships Archives
Jefferson Parish Dump Wall Blvd
Weather Underground Corvallis
Pro-Ject’s T2 Super Phono Turntable Is a Super Performer, and It’s a Super Bargain Too
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Ladyva Is She Married
How Big Is 776 000 Acres On A Map
Craigslist Woodward
Ucla Basketball Bruinzone
Unblocked Games 6X Snow Rider
Sapphire Pine Grove
Nurses May Be Entitled to Overtime Despite Yearly Salary
Join MileSplit to get access to the latest news, films, and events!
Peugeot-dealer Hedin Automotive: alles onder één dak | Hedin
Electronics coupons, offers & promotions | The Los Angeles Times
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5760

Rating: 4.1 / 5 (42 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.