• About
  • Landing Page
  • Buy JNews
Newsletter
Impact Crypto News
Advertisement
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
Impact Crypto News
No Result
View All Result
Home Crypto News Ethereum

Secured #5: Public Vulnerability Disclosures Update

IMPACTCRYPTO by IMPACTCRYPTO
May 3, 2023
in Ethereum
55 3
0
Secured #5: Public Vulnerability Disclosures Update
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Secured #5: Public Vulnerability Disclosures Update

Today, we have disclosed the second set of vulnerabilities from the Ethereum Foundation Bug Bounty Program! 🥳 These vulnerabilities were previously discovered and reported directly to the Ethereum Foundation.

When bugs are reported and validated, the Ethereum Foundation coordinates disclosures to affected teams and helps cross-check vulnerabilities across all clients. The Bug Bounty Program currently accepts reports for the following client software:

  • Erigon
  • Go Ethereum
  • Lodestar
  • Nethermind
  • Lighthouse
  • Prysm
  • Teku
  • Besu
  • Nimbus

In addition to client software, the Bug Bounty Program also covers the Deposit Contract, Execution Layer & Consensus Layer Specifications and Solidity. 🙏

Repository & vulnerability list

Since the last vulnerability disclosure has been quite eventful with events such as the Merge 🐼 and the max bounty reward increase to $250,000. 💰

The highest paid reward during this period was $50,000. This was awarded to scio for reporting an issue in which Lighthouse beacon nodes crashed via malicious BlocksByRange messages containing an overly large count value. You can read more about this specific vulnerability here. 💥

Another notable set of vulnerabilites has been around fork choice attacks. EF researchers and client teams investigated and patched attacks that were able to cause long reorgs. 👀

Guido Vranken holds the top spot most positive reports in this period. At the same time, Guido managed to collect the most points for the Bug Bounty Leaderboard! 🏆

We also have two bounty hunters who decided to donate their rewards to charities: nrv and PwningEth! 🔥

The full list of new vulnerabilities, along with full details, can be found in the disclosures repository.

All vulnerabilities added to the disclosures catalogue were patched prior to the latest hardforks on the Execution Layer and Consensus Layer.

For more information, and to learn more about disclosure policies, timelines, and cataloging, head over to the disclosures repository.

Thank you 🙏

We would like to give a massive shout out to everyone involved in the discovery and reporting of vulnerabilities, as well as to the teams responsible for fixing them. While we have attempted to include the names or aliases of all reporters, there are many developers and researchers within the client teams and in the Ethereum Foundation who found and corrected vulnerabilities outside of the bounty program. There are also many unsung heroes such as client team developers, community members, and many more who have spent countless hours triaging, cross-checking, and mitigating vulnerabilities before they could be exploited.

Your immense efforts have been instrumental to ensuring Ethereum’s security. Thank you!



Source link

Related articles

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

December 10, 2025
BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

December 8, 2025
Tags: bitcoin newscrypto analysiscrypto newsDisclosuresEthoz EdgeLatest bitcoin newslatest crypto newsPublicSecuredUpdateVulnerability
Share76Tweet47

Related Posts

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

by IMPACTCRYPTO
December 10, 2025
0

oskar thorén is one of the leads in ethereum foundation's newest IPTF, or institutional privacy task force. he's a freedom...

BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

by IMPACTCRYPTO
December 8, 2025
0

Belize City, Belize, December 8th, 2025, Chainwire As Bitcoin MENA 2025, Solana Breakpoint 2025 and the Global Blockchain Show bring...

Hotstuff Labs launches Hotstuff, a DeFi native Layer 1 connecting On-Chain Trading with Global Fiat Rails

Hotstuff Labs launches Hotstuff, a DeFi native Layer 1 connecting On-Chain Trading with Global Fiat Rails

by IMPACTCRYPTO
December 5, 2025
0

Singapore, Singapore, December 5th, 2025, Chainwire Hotstuff Labs today announced the public testnet for Hotstuff L1, a DeFi Layer 1...

Devconnect Argentina Recap | Ethereum Foundation Blog

Devconnect Argentina Recap | Ethereum Foundation Blog

by IMPACTCRYPTO
December 4, 2025
0

Devconnect Buenos Aires wrapped up as the largest Ethereum Foundation event yet, bringing together a global mix of developers, founders,...

Chainlink ETF Lists on NYSE Arca After ICE Partnership

Chainlink ETF Lists on NYSE Arca After ICE Partnership

by IMPACTCRYPTO
December 3, 2025
0

Key Points The Chainlink ETF recorded $9.8 million in trading volume on its first day with shares closing up approximately...

Load More

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0

© 2018 JNews by Jegtheme.