Friday, May 15, 2026
No Result
View All Result
Coins League
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis
No Result
View All Result
Coins League
No Result
View All Result

Chainlink VRF vulnerability thwarted by white hat hackers with $300K reward

November 16, 2023
in Web3
Reading Time: 2 mins read
0 0
A A
0
Home Web3
Share on FacebookShare on TwitterShare on E Mail



Decentralized oracle community Chainlink (LINK) paid a $300,000 bounty to white hat hackers Zach Obront and Or Cyngiser (Belief), who uncovered a essential bug that might have skewed its Verifiable Random Operate (VRF).

The bug

VRF is a random quantity generator (RNG) that permits sensible contracts to entry random values with out compromising safety.

The product is utilized by a number of crypto tasks, together with Axie Infinity, PancakeSwap, and Aavegotchi, to guard their sensible contract with tamper-proof randomness that can’t be manipulated and guarantee verifiable outcomes utilizing cryptographic proofs.

Final yr, Belief and Obront submitted a report on how a malicious VRF subscription proprietor may have prevented customers from getting this impartial randomness roll by blocking and rerolling randomness till they obtained a desired worth.

In line with the Chainlink group, this bug was categorized as a critical-impact sensible contract vulnerability, including that:

“Whereas it may compromise Chainlink VRF’s meant use of offering transparently verifiable tamper-resistant onchain randomness, the exploitable situation required quite a few particular situations to be met and can be detectable onchain. Most notably, the subscription proprietor—a task usually managed by the group behind the dApp utilizing VRF—have to be malicious or compromised.”

Following the incident, Chainlink carried out a safety characteristic to stop malicious VRF house owners from exploiting the problem.

Chainlink having fun with institutional curiosity

Chainlink’s Cross-Chain Interoperability Protocol (CCIP) know-how has seen a rise in adoption from adoption from main conventional establishments.

The worldwide monetary messaging community Swift used the know-how in a tokenization experiment that concerned the switch of tokens throughout a number of blockchains in August. South Korean gaming big additionally used it to energy an interoperable Web3 gaming ecosystem in October.

Additionally, Hong Kong authorities adopted it for worth change in its Central Financial institution Digital Foreign money (CBDC) trials.

Because of this, Chainlink’s native LINK token and Grayscale’s Chainlink Belief (GLNK), an institutional funding car, have seen their worth surge to new highs.



Source link

Tags: 300KChainlinkhackersHatrewardthwartedVRFVulnerabilityWhite
Previous Post

Watsonx: a game changer for embedding generative AI into commercial solutions

Next Post

Non-KYC & AML Bitcoin and Altcoin Exchanges: Top 5 for 2023 | by Will Grimes | The Dark Side | Nov, 2023

Related Posts

CFTC No-Action Letter on Prediction Markets Streamlines Swap Data Reporting
Web3

CFTC No-Action Letter on Prediction Markets Streamlines Swap Data Reporting

May 14, 2026
Hackers Insert Malware Into Mistral AI Software Download
Web3

Hackers Insert Malware Into Mistral AI Software Download

May 13, 2026
OpenAI Launches Daybreak as AI Firms Expand Into Cybersecurity
Web3

OpenAI Launches Daybreak as AI Firms Expand Into Cybersecurity

May 11, 2026
Tether launches decentralized local AI using Isaac Asimov’s Psychohistory straight out of Foundation
Web3

Tether launches decentralized local AI using Isaac Asimov’s Psychohistory straight out of Foundation

May 12, 2026
Chainlink emerges as the unlikely $3B winner of KelpDAO exploit as DeFi projects dump LayerZero
Web3

Chainlink emerges as the unlikely $3B winner of KelpDAO exploit as DeFi projects dump LayerZero

May 13, 2026
AI Models Scheme, Betray and Vote Each Other Out in Survivor-Style Game
Web3

AI Models Scheme, Betray and Vote Each Other Out in Survivor-Style Game

May 10, 2026
Next Post
Non-KYC & AML Bitcoin and Altcoin Exchanges: Top 5 for 2023 | by Will Grimes | The Dark Side | Nov, 2023

Non-KYC & AML Bitcoin and Altcoin Exchanges: Top 5 for 2023 | by Will Grimes | The Dark Side | Nov, 2023

Top Trader Predicts Bullish Continuation for Solana After Corrective Move, Says SOL Remains in Monster Uptrend

Top Trader Predicts Bullish Continuation for Solana After Corrective Move, Says SOL Remains in Monster Uptrend

How Singapore’s Bold Moves Pave the Way

How Singapore's Bold Moves Pave the Way

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn RSS Telegram
Coins League

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at Coins League

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITEMAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Metaverse
  • Web3
  • Scam Alert
  • Regulations
  • Analysis

Copyright © 2023 Coins League.
Coins League is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In