Sunday, April 2, 2023
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • en English
    ar Arabicbg Bulgarianzh-CN Chinese (Simplified)nl Dutchen Englishfr Frenchde Germanit Italianpt Portugueseru Russianes Spanish
Crypto Miracles
Advertisement
  • Home
  • Crypto News
    • Bitcoin
    • Ethereum
    • Dogecoin
    • Litecoin
    • Ripple
    • Altcoin
    • Press Release
  • Blockchain
  • People
    • Opinion
    • Interview
  • Business
  • Technology
  • Market
  • Analysis
  • Live Price
  • Regulation
  • Guide
No Result
View All Result
  • Home
  • Crypto News
    • Bitcoin
    • Ethereum
    • Dogecoin
    • Litecoin
    • Ripple
    • Altcoin
    • Press Release
  • Blockchain
  • People
    • Opinion
    • Interview
  • Business
  • Technology
  • Market
  • Analysis
  • Live Price
  • Regulation
  • Guide
No Result
View All Result
Crypto Miracles
No Result
View All Result
Home Market

Verichains issues security advisories on security vulnerabilities on Tendermint Core

March 8, 2023
in Market
Reading Time: 2 mins read
0
Verichains issues security advisories on security vulnerabilities on Tendermint Core
Share on FacebookShare on TwitterPinShare on Reddit


  • Verichains has identified several significant vulnerabilities on Tendermint Core
  • Projects using IAVL proof verification in Tendermint Core are advised to secure their assets to mitigate exploitation.
  • Many popular projects including BNB Smart Chain (BSC) are built on Tendermint

Leading blockchain security firm Verichains has identified several significant vulnerabilities in Tendermint Core and as part of its Responsible Vulnerability Disclosure Policy has released two public advisories.

The first advisory titled VSA-2022-100 discusses a critical Empty Merkle Tree vulnerability in the IAVL proof. The second advisory is titled VSA-2022-101 and discusses a critical IAVL Spoofing Attack via multiple vulnerabilities on Tendermint Core.

Verichain advises that projects using IAVL-proof verification in Tendermint Core should secure their assets to mitigate exploitation risks.

Linked to recent BNB Chain bridge hack

Tendermint BFT consensus engine and Cosmos SDK are popular blockchain platforms that are used by several popular blockchain projects including the now defunct Terra (LUNA), Band Chain, OKX Chain, and BNB Smart Chain (BSC).

Verichains indicated that it discovered the Tendermint Core vulnerabilities while working on the BNB Chain bridge hack that took place in October last year. Security specialists, who identified the critical IAVL Spoofing Attack via multiple vulnerabilities found in BNB Chain and Tendermint, say it could have resulted in a significant loss of funds.

However, although the vulnerabilities were disclosed to the Tendermint/Cosmos maintainer, no patch was released for the Tendermint Core library since the Cosmos-SDK and IBC had migrated from IAVL Merkle proof verification to ICS-23.

Verichains Responsible Vulnerability Disclosure Policy

Verichains followed its Responsible Vulnerability Disclosure Policy to notify the public after the requisite 120 days. If not fixed, the critical nature of the bugs may lead to further hacks and consequent loss of funds, which in some cases could result in millions or even billions of dollars lost.

Verichains regularly posts the Security flaws and vulnerabilities that it identifies on its website for public consumption.


Share this article

Categories



Source link

Related articles

US government to sell 41,490 BTC connected to Silk Road

US government to sell 41,490 BTC connected to Silk Road

March 31, 2023
SOL price up 110% in Q1 2023 for best quarter since Q2 2021?

SOL price up 110% in Q1 2023 for best quarter since Q2 2021?

March 31, 2023
Share2Tweet1PinShare
Previous Post

The 7 Best New ICOs To Buy in 2023

Next Post

Biggest Movers: XRP Hits 2-Week High, SHIB Marginally Higher – Market Updates Bitcoin News

Related Posts

US government to sell 41,490 BTC connected to Silk Road

US government to sell 41,490 BTC connected to Silk Road

by cryptomiracles
March 31, 2023

The US government sold 9,861 bitcoin on 14 March, netting over $215 million. 41,490 BTC remain from over 51,000 seized...

SOL price up 110% in Q1 2023 for best quarter since Q2 2021?

SOL price up 110% in Q1 2023 for best quarter since Q2 2021?

by cryptomiracles
March 31, 2023

Solana price is up 110% in the past three months. SOL closed in the red in February and is likely...

Crypto prices: Bitcoin on cusp of historic quarterly close

Crypto prices: Bitcoin on cusp of historic quarterly close

by cryptomiracles
March 31, 2023

The cryptocurrency market cap was around $1.24 trillion as Bitcoin price reclaimed the $28,500 level, with crypto poised to end...

Ethereum price update: Here's hoe ETC could dump 22%

Ethereum price update: Here’s hoe ETC could dump 22%

by cryptomiracles
March 30, 2023

Ethereum Classic price is down 2.5% in the past 24 hours. ETC has failed to ride broader market sentiment, currently...

bitcoin regaining safe-haven asset

Is Bitcoin regaining its status as a safe-haven asset?

by cryptomiracles
March 30, 2023

Bitcoin is on track for its third consecutive month of positive gains as investors continue to see it as a...

Load More
Next Post
Biggest Movers: XRP Hits 2-Week High, SHIB Marginally Higher – Market Updates Bitcoin News

Biggest Movers: XRP Hits 2-Week High, SHIB Marginally Higher – Market Updates Bitcoin News

Crypto News Shows Broader Market Stall, But Investors Are Still Swarming To Metacade

Crypto News Shows Broader Market Stall, But Investors Are Still Swarming To Metacade

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions.

5 × 2 =

Crypto Miracles

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics, and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Business
  • Dogecoin
  • Ethereum
  • Guide
  • Interview
  • Litecoin
  • Market
  • Opinion
  • Press Release
  • Regulation
  • Ripple
  • Technology
  • Uncategorized

Recent Posts

  • Elon Musk Asks Judge to Dismiss $258B Dogecoin Lawsuit — Insists Tweeting Support for DOGE Isn’t Unlawful – Featured Bitcoin News
  • Bitcoin Profits Deemed Taxable by Denmark’s Supreme Court – Taxes Bitcoin News
  • FTX EU Launches New Website for Withdrawals as Subsidiary Starts Returning Funds to Customers – Bitcoin News

Newsletter

    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions

    cryptomiracles.com © 2021 All rights reserved.

    No Result
    View All Result
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Dogecoin
      • Litecoin
      • Ripple
      • Altcoin
      • Press Release
    • Blockchain
    • People
      • Opinion
      • Interview
    • Business
    • Technology
    • Market
    • Analysis
    • Live Price
    • Regulation
    • Guide

    cryptomiracles.com © 2021 All rights reserved.

    This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.