Polygon pays $2M bounty on bug which could have compromised $850M in user funds

Polygon pays $2M bounty on bug which could have compromised $850M in user funds

White hat hacker Gerhard Wagner has earned $2 million after reporting a solution to a potentially costly “double-spend” bug on the Polygon network.

In an Oct. 21 blog post from Immunefi, a security service that helps facilitate bug reports in decentralized finance projects, Polygon network’s Plasma Bridge was at risk of having $850 million removed by a knowledgeable hacker. According to the project, the vulnerability would have allowed attackers to exit their burn transaction from the bridge up to 223 times, quickly turning an amount like $4,500 into $1 million profi.

Our top trading bots

Immunefi reported the double-spend exploit worked by first depositing Ether (ETH) through the Plasma Bridge and starting the withdrawal process after the transaction was confirmed. A hacker could then wait a week and resubmit the same withdrawals with the exception of "a modified first byte of the branch mask." Provided the hacker was able to begin with $3.8 million, they could have potentially depleted all $850 funds from the bridge’s deposit manager at the time.

Polygon agreed to pay its maximum amount for a bug bounty report — $2 million — following Wagner’s initial report on Oct. 5. According to the platform, the bug has already been deployed on the mainnet after testing, Wagner has received the funds, claimed to be “the highest bounty ever paid out in history,” and no user funds were lost with the exploit.

Wagner speculated on his Medium page that the bug might be due to “using someone else’s code and not having a 100% understanding of what it does.” He added the solution was “not very elegant” but did fix the double-spend exploit.

Related: White hat hacker paid DeFi’s largest reported bounty fee

Before this latest $2 million payout, the largest bounty for a white hat hacker had gone towards programmer Alexander Schlindwein, who in September discovered a vulnerability in Belt Finance’s protocol and was awarded $1.05 million. However, the U.S. Department of State may topple that record if a hacker is able pass on information on terrorist suspects, extremists and state-sponsored hackers — the government said it would be offering rewards of up to $10 million.

Keep reading relating to Cointelegraph
President Bukele hits out at Bitcoin Bond 'FUD' as CZ jets in to El Salvador
El Salvador President Nayib Bukele took to Twitter on Wednesday evening, hitting out at a Reuters report claiming Binance CEO Changpeng Zhao (CZ) was flying...
Nifty News: Snoop Dogg and Gary V have $95M in NFTs, Dolly Parton’s Dollyverse and more…
According to data from DappRadar, the NFT portfolios belonging to Iconic rapper Snoop Dogg and popular entrepreneur Gary Vaynerchuck are worth a combined...
Indian parliament's agenda for winter session no longer includes crypto bill
The Indian government may still be considering a bill that could ban certain cryptocurrencies in the country, but lawmakers are unlikely to vote on any...
Binance partners with Indonesian telco to develop new crypto exchange
Major cryptocurrency exchange Binance has partnered with MDI Ventures, PT Telkom Indonesia’s venture capital arm, to establish a crypto exchange platform.According...
Bitcoin tumbles below $60,000 as US regulation and China crackdown weighs
By Samuel IndykInvesting.com – The price of Bitcoin fell back below $60,000 on Tuesday for the first time since 1st November as the passage of the US infrastructure...
Robinhood launches 24/7 phone support, crypto users included
Popular trading app Robinhood announced Tuesday that it has launched round-the-clock phone support to better serve its ever-growing userbase, including...
Binance to cease crypto futures and options in Australia
Binance, the world’s largest cryptocurrency exchange by trading volume, continues limiting its services amid the ongoing global regulatory scrutiny, announcing...
There's a Bitcoin boom among Baby Boomers reports BTC Markets
Australian cryptocurrency exchange BTC Markets has observed a significant uptick in older clients using its platform over the past financial year.More older...
Fantom price gains 100% after launching a 370M FTM incentive program
The Ethereum network continues to enjoy being the top smart contract platform in the blockchain industry. However, the competition is slowly gaining market...
Alabama regulators accuse BlockFi of offering unregistered securities
The state of Alabama has become the second state in the United States to raise concerns over BlockFi, a major cryptocurrency lending platform.The Alabama...
Capital International Group purchases 12.2% stake in MicroStrategy
Capital International Group, a $2.3 trillion asset manager headquartered in Los Angeles, has acquired a 12.2% stake in MicroStrategy — making it one of...
Jack Dorsey notes lobbying efforts to get Ethiopian gov't to embrace Bitcoin
Twitter CEO and crypto proponent Jack Dorsey has highlighted the efforts of a lobby group pushing the Ethiopian government to embrace Bitcoin (BTC).In a...
IBM contributes blockchain platform code to Hyperledger to drive enterprise blockchain adoption
The global blockchain technology market size is projected to reach $72 billion in the next five years. In order to ensure this growth, however, blockchain...
There are now 6,710 Cardano millionaires following latest ADA surge
Cardano has rewarded its investors with significant gains this year, with a growing number of holders joining the coveted millionaires’ club following the...
Bitcoin Era Success Story: Teen Hits Jackpot With Crypto Trading
17-Year Old Hits The Jackpot With Cryptocurrency Trading Venture The news media has been swept up in a tornado with the latest news of a 17-year-old boy...