White Hat Hacker Finds Main Vulnerability in Ethereum DApp Augur

von Satoshi Nakamoto

White Hat Hacker Finds Main Vulnerability in Ethereum DApp Augur


augur bug



A white hat hacker has found a serious vulnerability in decentralized prediction market Augur, maybe essentially the most highly-touted decentralized utility (dApp) constructed on the Ethereum community.


The bug, disclosed by means of bug bounty platform HackerOne by safety researcher Viacheslav Sniezhkov, would have allowed an attacker to inject fraudulent knowledge into Augur’s consumer interface, doubtlessly resulting in a big lack of funds on the a part of affected customers.


This exploit was made doable as a result of whereas Augur’s core performance — an uncensorable prediction market that enables customers to guess on the end result of nearly any occasion — is secured by the decentralized Ethereum blockchain, UI configuration recordsdata are saved regionally on a consumer’s pc.


Consequently, hackers might deploy malicious web sites that serve hidden iframes and, unbeknownst to the consumer, modify the configuration settings saved in these native recordsdata such that an Augur UI would serve up fraudulent knowledge, doubtlessly tricking a consumer into sending funds to a hacker-controlled handle.


augurAs a decentralized prediction market platform, this dApp permits cryptocurrency customers to create prediction markets for nearly any occasion.

To reiterate, the bug was not within the Augur good contract, as was the case with the high-profile Parity and DAO incidents. Nonetheless, that doesn't imply that the vulnerability was not severe.


As Sniezhkov defined:


“A 3rd occasion web site can embody a hidden iframe which might override “augur-node” configuration variable of a operating augur utility. This variable is endured in localStorage. Within the case of browser web page reload (consumer motion or browser/OS crash), the traditional “augur-node” websockets endpoint will probably be changed with the supplied by attacker so that each one the markets knowledge, addresses and transactions might be masqueraded.”


After sparring with Snizhkov for a number of days over the severity of vulnerability (specifically whether or not it constituted a UI bug or one thing extra severe), the Forecast Basis, which oversees the event of the Augur protocol, finally awarded Sniezhkov $5,000 for disclosing the bug, which has since been patched.


At current, there isn't a indication that the exploit has been efficiently manipulated to steal consumer funds. Nonetheless, the Forecast Basis has suggested customers to replace to the newest model of the software program consumer, notably for the reason that vulnerability has now been made public.


As CCN reported, the protocol’s builders initially managed a “kill swap” that might be used to successfully shut down the prediction market’s platform if a important bug was found within the Augur good contract within the two weeks following the dApp’s launch. When no important bugs have been discovered, they successfully destroyed the kill swap by transferring possession of it to a “burn handle.”


Featured Picture from Shutterstock


Observe us on Telegram or subscribe to our publication right here.
• Be a part of CCN's crypto group for $9.99 per thirty days, click on right here.
• Need unique evaluation and crypto insights from Hacked.com? Click on right here.
• Open Positions at CCN: Full Time and Half Time Journalists Needed.
Commercial





Source link



Read the full article
Porträt von Satoshi Nakamoto

Satoshi Nakamoto

Zur Person

Satoshi Nakamoto