Cross-Chain Bridge Exploit via Improper Signature Verification
11/28/2023
A critical vulnerability was discovered in a popular cross-chain bridge allowing attackers to forge transaction signatures and withdraw unauthorized funds.
Overview
A critical vulnerability was identified in a major cross-chain bridge protocol that allowed attackers to forge
transaction signatures due to improper signature verification mechanisms, resulting in an $18 million exploit.
Technical Details
The vulnerability stemmed from the bridge's validator node implementation that failed to properly verify the v
parameter in ECDSA signatures. This allowed attackers to craft malicious signature objects that would pass verification
checks despite not being authentic.
Solidity
test123
Vulnerability Details
- Category
- Bridge
- Chain
- BNB
- Affected Systems
- Cross-Chain Bridges
- Discovered By
- Independent Security Researcher
- Contract/Token
- Alkimiya_io
- Financial Loss
- $18M
- Exploit Status
- Previously Exploited
Related Vulnerabilities
Similar security issues you should know about
Stay Protected
Get notified about new vulnerabilities
Subscribe to our security alerts to receive timely notifications about new vulnerabilities and exploits.
Subscribe to Alerts