• About Cryptocurrency Prices List
  • Privacy Policy
Newsletter
cryptocurrency prices list
Advertisement
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • About CCLP
  • Contact Us
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • About CCLP
  • Contact Us
No Result
View All Result
cryptocurrency prices list
No Result
View All Result
Home blog

Cydia Dev Discloses Ethereum L2 Bug – Optimism Attacker Could Have “Printed Arbitrary Amount of Tokens” CryptoGlobe

Vladislav Sopov by Vladislav Sopov
February 13, 2022
in blog
0
Cydia Dev Discloses Ethereum L2 Bug – Optimism Attacker Could Have “Printed Arbitrary Amount of Tokens” CryptoGlobe

Related articles

Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

August 7, 2022
Miner data shows Bitcoin could have bottomed

Miner data shows Bitcoin could have bottomed

August 7, 2022


Cydia Dev Discloses Ethereum L2 Bug - Optimism Attacker Could Have

On February 10, well-known Cydia and iOS Jailbreak developer Jay Freeman, otherwise known as Saurik, posted a Twitter thread about a bug he found in the Layer-2 scaling protocol. (L2) known as Optimism. According to Freeman, the vulnerability, which has been patched, could have allowed an attacker to create an infinite amount of tokens.

Cydia Creator ‘Saurik’ Discovers Optimism L2 Vulnerability

Jay Freeman is a prominent software developer well known for his iOS Jailbreak and Cydia tools. Freeman’s Cydia Graphical User Interface (GUI) was released in February 2008 and gives users of jailbroken iPhones the ability to download unauthorized software for the iOS operating system of Apple smartphones. Freeman recently published a blog post titled “Attacking an Ethereum L2 with Unbridled Optimism,” which explains how he reported a critical security issue to the developers of the L2 Optimism scaling solution.

Optimism’s L2 solution allows users to move Ethereum for a fraction of the cost. Currently, moving Ether using Optimism can cost $0.56 per transfer, unlike the current L1 gas fee which is $3.29 per transaction. To trade coins on-chain using L1, it will cost a user $16.47 in ether, but using Optimism to trade coins will cost $0.83. Freeman reported the Optimism vulnerability on February 2, 2022, and the bug has since been fixed.

The attack would have allowed “an attacker to replicate money on any chain using their ‘OVM 2.0’ fork of go-ethereum (which they call l2geth),” Freeman said. The developer further explained that he plans to talk about the Optimism vulnerability on February 18 at Ethdenver 2022. Freeman was also reward a bounty of $2,000,042 for discovering the bug and disclosing it to the team. The software engineer’s blog post describes how the attacker could hit an arbitrary amount of tokens before the bug was fixed.

“The bug presented here – which I dub ‘Unbridled Optimism’ – can perhaps (roughly) be modeled as a bug across a ‘bridge,'” Freeman wrote. “But it’s actually a bug in the virtual machine that runs the smart contracts on Optimism. Exploiting this allows the attacker to gain access to an effectively unlimited number of tokens (aka, IOUs) across the bridge. I argue that this is more dangerous than simply tricking the reserves into allowing a withdrawal. The developer continued:

Additionally, with your unlimited supply of IOUs, you can go to any decentralized exchanges operating on the L2 and waste their savings, buying large amounts of other tokens while devaluing the chain’s own currency. Using your access to infinite capital, you can further manipulate on-chain pricing oracles to take advantage of other attacks; and, until someone finally realizes your money is counterfeit, arbitrageurs will flock to the network to sell you their assets.

The pessimism surrounding cross-chain apps

In addition to the vulnerability found in Optimism, Freeman discussed the cross-chain bridge technology in detail. The developer mentioned that the same day he disclosed the bug to Optimism, the Wormhole Bridge was attacked. Freeman also touched on the Poly Network hack in his post. “Even when hackers steal money from a bridge, the ramifications are limited,” Freeman’s blog post explains.

Freeman discovering the optimism bug comes on the heels of the slew of cross-chain bridge hacks and new community concern over the security of this burgeoning technology. The Cydia developer’s blog post mentions concepts such as “‘insurance policies’ against crypto hacks”. Additionally, Ethereum (ETH) co-founder Vitalik Buterin recently spoke about the security concerns of cross-chain bridge platforms. “I’m pessimistic about cross-chain apps,” says a recent Reddit post from Buterin.

Keywords in this story

1 million players, binance follows hackers, Blockchain, Blog Post, Cryptocurrencies, Cydia Dev, Cydia Developer, Developer, Ethereum, Ethereum (ETH), Hacker, iOS Jailbreak, Jay Freeman, L2, L2 scaling, Optimism, Optimism bug, Optimism bug patched, Optimism vulnerability, scaling, tokens, Vitalik Buterin

What do you think of Jay Freeman’s discovery of the Optimism bug? Let us know what you think about this topic in the comments section below.

Jamie Redman

Jamie Redman is the news manager for Bitcoin.com News and a fintech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He is passionate about Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written over 5,000 articles for Bitcoin.com News about disruptive protocols emerging today.




Image credits: Shutterstock, Pixabay, Wiki Commons

Warning: This article is for informational purposes only. This is not a direct offer or the solicitation of an offer to buy or sell, or a recommendation or endorsement of any product, service or company. Bitcoin.com does not provide investment, tax, legal or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.

Most Popular News

In case you missed it



Related Posts

Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

by Vladislav Sopov
August 7, 2022
0

Select altcoins such as FLOW, THETA, QNT, and MKR could rally if Bitcoin breaks above the stiff overhead resistance at...

Miner data shows Bitcoin could have bottomed

Miner data shows Bitcoin could have bottomed

by Vladislav Sopov
August 7, 2022
0

Catching the coveted Bitcoin bottom requires analyzing more than just its price. One of the most reliable indicators of market...

Tinder Distances Itself From Metaverse After Dissapointing Results

Tinder Distances Itself From Metaverse After Dissapointing Results

by Vladislav Sopov
August 7, 2022
0

Dating giant Match Group has announced several modifications to its management team alongside disappointing second-quarter earnings. The CEO, Renate Nyborg,...

Acala Token (ACA) Price Prediction 2022, 2023, 2024, 2025

Acala Token (ACA) Price Prediction 2022, 2023, 2024, 2025

by Vladislav Sopov
August 7, 2022
0

Over the past two years, the parabolic run of cryptocurrencies has resulted in significant awareness of the crypto-verse. Acala is...

Bitcoin Users Are Building The Future – Bitcoin Magazine

Bitcoin Users Are Building The Future – Bitcoin Magazine

by Vladislav Sopov
August 7, 2022
0

This is an opinion editorial by Captain Sidd, finance writer and contributor to Bitcoin Magazine.“When deeds speak, words are nothing.”...

Load More
Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

Top 5 cryptocurrencies to watch this week: BTC, FLOW, THETA, QNT, MKR

August 7, 2022
Miner data shows Bitcoin could have bottomed

Miner data shows Bitcoin could have bottomed

August 7, 2022
Tinder Distances Itself From Metaverse After Dissapointing Results

Tinder Distances Itself From Metaverse After Dissapointing Results

August 7, 2022
Acala Token (ACA) Price Prediction 2022, 2023, 2024, 2025

Acala Token (ACA) Price Prediction 2022, 2023, 2024, 2025

August 7, 2022

© 2020 CCPL - ( Cryptocurrency Prices List )

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2020 CRYPTO, CRYPTOCURRENCY PRICES LIST.