• Login
Crypto Newsmart
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • ALTCOIN
    • ETEREUM
    • NFT’s
    • CRYPTO PRICE ANALYSIS
  • LEARN CRYPTO
  • CRYPTO EXCHANGES
  • BLOCKCHAIN
  • MINING
  • SCAM ALERT
  • PRESS RELEASE
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • ALTCOIN
    • ETEREUM
    • NFT’s
    • CRYPTO PRICE ANALYSIS
  • LEARN CRYPTO
  • CRYPTO EXCHANGES
  • BLOCKCHAIN
  • MINING
  • SCAM ALERT
  • PRESS RELEASE
No Result
View All Result
Crypto Newsmart
No Result
View All Result

Secured #5: Public Vulnerability Disclosures Update

6 days ago
in Ethereum
Reading Time: 3 mins read
Secured #5: Public Vulnerability Disclosures Update
4
VIEWS
Share on Facebook

Today, we have disclosed the second set of vulnerabilities from the Ethereum Foundation Bug Bounty Program! 🥳 These vulnerabilities were previously discovered and reported directly to the Ethereum Foundation.

When bugs are reported and validated, the Ethereum Foundation coordinates disclosures to affected teams and helps cross-check vulnerabilities across all clients. The Bug Bounty Program currently accepts reports for the following client software:

  • Erigon
  • Go Ethereum
  • Lodestar
  • Nethermind
  • Lighthouse
  • Prysm
  • Teku
  • Besu
  • Nimbus

In addition to client software, the Bug Bounty Program also covers the Deposit Contract, Execution Layer & Consensus Layer Specifications and Solidity. 🙏

Repository & vulnerability list

Since the last vulnerability disclosure has been quite eventful with events such as the Merge 🐼 and the max bounty reward increase to $250,000. 💰

The highest paid reward during this period was $50,000. This was awarded to scio for reporting an issue in which Lighthouse beacon nodes crashed via malicious BlocksByRange messages containing an overly large count value. You can read more about this specific vulnerability here. 💥

Another notable set of vulnerabilites has been around fork choice attacks. EF researchers and client teams investigated and patched attacks that were able to cause long reorgs. 👀

Guido Vranken holds the top spot most positive reports in this period. At the same time, Guido managed to collect the most points for the Bug Bounty Leaderboard! 🏆

We also have two bounty hunters who decided to donate their rewards to charities: nrv and PwningEth! 🔥

The full list of new vulnerabilities, along with full details, can be found in the disclosures repository.

All vulnerabilities added to the disclosures catalogue were patched prior to the latest hardforks on the Execution Layer and Consensus Layer.

For more information, and to learn more about disclosure policies, timelines, and cataloging, head over to the disclosures repository.

Thank you 🙏

We would like to give a massive shout out to everyone involved in the discovery and reporting of vulnerabilities, as well as to the teams responsible for fixing them. While we have attempted to include the names or aliases of all reporters, there are many developers and researchers within the client teams and in the Ethereum Foundation who found and corrected vulnerabilities outside of the bounty program. There are also many unsung heroes such as client team developers, community members, and many more who have spent countless hours triaging, cross-checking, and mitigating vulnerabilities before they could be exploited.

Your immense efforts have been instrumental to ensuring Ethereum’s security. Thank you!



Source link

Tags: DisclosurespublicSecuredUpdatevulnerability

Related Posts

Lido Community Weighing On-Chain Vote to Deploy Version 2 on Ethereum
Ethereum

Lido Community Weighing On-Chain Vote to Deploy Version 2 on Ethereum

27 May 2023
Asymmetry, ‘ETF’ for Liquid Staking Tokens, Raises $3M Round From Ecco Capital, Ankr and Others
Ethereum

Asymmetry, ‘ETF’ for Liquid Staking Tokens, Raises $3M Round From Ecco Capital, Ankr and Others

17 May 2023
Ethereum Protocol Fellowship: Third Cohort Recap
Ethereum

Ethereum Protocol Fellowship: Third Cohort Recap

12 May 2023
Scouting for the Future: Technology and the Scouting Movement
Ethereum

Scouting for the Future: Technology and the Scouting Movement

2 May 2023
Devconnect is back! See you this year in Istanbul.
Ethereum

Devconnect is back! See you this year in Istanbul.

22 April 2023
Olympus DAO Votes to Buy More ETH for Treasury Backing OHM Token
Ethereum

Olympus DAO Votes to Buy More ETH for Treasury Backing OHM Token

17 April 2023


  • Trending
  • Comments
  • Latest
LUNC Burn Tax Set To Rise To 0.5% As KuCoin Proposal Receives Approval

LUNC Burn Tax Set To Rise To 0.5% As KuCoin Proposal Receives Approval

20 May 2023
Wombat Web 3 Gaming Platform (WOMBAT) Price Prediction 2023 2024 2025 2026

Wombat Web 3 Gaming Platform (WOMBAT) Price Prediction 2023 2024 2025 2026

25 May 2023
When Bitcoin Meets Artificial Intelligence: Woke Madness Or Awakened Sanity?

When Bitcoin Meets Artificial Intelligence: Woke Madness Or Awakened Sanity?

24 May 2023
Amazon Is Testing Digital Euro Prototypes

Amazon Is Testing Digital Euro Prototypes

17 September 2022
Do Kwon’s Bail Revoked; Terra Execs to Stay in Jail in Montenegro: Bloomberg

Do Kwon’s Bail Revoked; Terra Execs to Stay in Jail in Montenegro: Bloomberg

25 May 2023
How Bitcoin Can Preserve The Life Savings Of Refugees

How Bitcoin Can Preserve The Life Savings Of Refugees

28 May 2023
Kava (KAVA) Price Rallies 10% In 7 Days

Kava (KAVA) Price Rallies 10% In 7 Days

28 May 2023
How I Preserve My Wealth With Bitcoin

How I Preserve My Wealth With Bitcoin

27 May 2023
Bitcoin Price (BTC) Falls to $26K; Is $24K Next?

Bitcoin Price (BTC) Falls to $26K; Is $24K Next?

27 May 2023
Lido Community Weighing On-Chain Vote to Deploy Version 2 on Ethereum

Lido Community Weighing On-Chain Vote to Deploy Version 2 on Ethereum

27 May 2023

  • Home
  • Disclaimer
  • Privacy Policy
  • Digital Millennium Copyright Act Policy (DMCA)
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us
CRYPTO NEWSMART

Copyright © 2021 Crypto Newsmart.

No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • ALTCOIN
    • ETEREUM
    • NFT’s
    • CRYPTO PRICE ANALYSIS
  • LEARN CRYPTO
  • CRYPTO EXCHANGES
  • BLOCKCHAIN
  • MINING
  • SCAM ALERT
  • PRESS RELEASE

Copyright © 2021 Crypto Newsmart.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Manage Cookie Consent

We use cookies to optimise our website and our service.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage vendors Read more about these purposes
Preferences
{title} {title} {title}