Close Menu
    Track all markets on TradingView
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Term And Conditions
    • Disclaimer
    • About us
    • Contact us
    Facebook X (Twitter) Instagram
    WSJ-Crypto
    • Home
    • Bitcoin
    • Ethereum
    • Blockchain
    • Crypto Mining
    • Economy and markets
    WSJ-Crypto
    Home ยป Public Vulnerability Disclosures: A Fresh Update on Secured #5
    Ethereum

    Public Vulnerability Disclosures: A Fresh Update on Secured #5

    wsjcryptoBy wsjcrypto8 Dicembre 2024Nessun commento3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Today, we have revealed the second batch of vulnerabilities from the Ethereum Foundation Bug Bounty Program! ๐Ÿฅณ These vulnerabilities were previously identified and directly reported to the Ethereum Foundation.

    When bugs are submitted and confirmed, the Ethereum Foundation facilitates disclosures to impacted teams and assists in validating vulnerabilities across all clients. The Bug Bounty Program currently receives reports for the following client applications:

    • Erigon
    • Go Ethereum
    • Lodestar
    • Nethermind
    • Lighthouse
    • Prysm
    • Teku
    • Besu
    • Nimbus

    Alongside client software, the Bug Bounty Program also encompasses the Deposit Contract, Execution Layer & Consensus Layer Specifications, and Solidity. ๐Ÿ™

    Repository & vulnerability list

    Since the last vulnerability announcement has been quite eventful with occasions such as the Merge ๐Ÿผ and the maximum bounty reward raised to $250,000. ๐Ÿ’ฐ

    The largest paid reward during this timeframe was $50,000. This was conferred to scio for reporting an issue that resulted in Lighthouse beacon nodes crashing due to malicious BlocksByRange messages containing a excessively large count value. More information about this specific vulnerability can be found here. ๐Ÿ’ฅ

    Another significant range of vulnerabilities has emerged regarding fork choice attacks. EF researchers and client teams investigated and resolved attacks that could induce lengthy reorgs. ๐Ÿ‘€

    Guido Vranken maintains the top ranking for the most positive reports in this timeframe. Concurrently, Guido succeeded in accumulating the most points for the Bug Bounty Leaderboard! ๐Ÿ†

    We also have two bounty hunters who opted to donate their rewards to charitable organizations: nrv and PwningEth! ๐Ÿ”ฅ

    The complete list of new vulnerabilities, with full details, can be accessed in the disclosures repository.

    All vulnerabilities included in the disclosures catalogue have been resolved before the recent hardforks on the Execution Layer and Consensus Layer.

    For additional information, and to learn more about disclosure policies, timelines, and cataloging, please visit the disclosures repository.

    Thank you ๐Ÿ™

    We would like to extend our heartfelt thanks to everyone involved in the discovery and reporting of vulnerabilities, as well as to the teams responsible for addressing them. While we have aimed to include the names or aliases of all reporters, there are numerous developers and researchers within the client teams and the Ethereum Foundation who identified and rectified vulnerabilities outside of the bounty initiative. Additionally, many unsung heroes such as client team developers, community members, and numerous others have invested countless hours on triaging, validating, and mitigating vulnerabilities before they could be exploited.

    Your tremendous efforts have been crucial in ensuring Ethereum’s security. Thank you!



    Source link

    return a list of comma separated tags from this title: Secured #5: Public Vulnerability Disclosures Update
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    wsjcrypto

    Related Posts

    Bringing Ethereum Back Together as One Chain

    18 Novembre 2025

    Navigating the Future: Insights from Checkpoint #7 – November 2025

    15 Novembre 2025

    Fusaka Mainnet Launch: A New Era for Ethereum Enthusiasts

    6 Novembre 2025

    Countdown to Devconnect: Your Essential Guide for the Next Two Weeks

    4 Novembre 2025
    Add A Comment

    Comments are closed.

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Top Coins
    # Name Price Changes 24h Market CAPVolumeSupply
    WSJ-Crypto
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Term And Conditions
    • Disclaimer
    • About us
    • Contact us
    ©Copyright 2025 . Designed by WSJ-Crypto

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version