White Hat Hacker Discovers Doubtlessly 'Crippling' Bug in Augur Cryptocurrency Platform • Dwell Bitcoin Information

von Satoshi Nakamoto

White Hat Hacker Discovers Doubtlessly 'Crippling' Bug in Augur Cryptocurrency Platform • Dwell Bitcoin Information

Software program and coding bugs can have an effect on any platform or mission. Within the cryptocurrency world, such issues affecting prediction markets might be very problematic. Augur customers barely escaped a serious vulnerability that would have doubtlessly crippled the betting platform and resulted in important monetary losses.


The Augur Vulnerability Defined

Prediction markets attempt to harness the knowledge of the group. Customers can place “bets’ on the end result of real-world occasions and main choices. This enterprise mannequin can solely work if the data shared with the platform is totally real. For Augur, it appears there's a vulnerability which permits for pretend information to be shared with customers. Sadly, this problem extends to any and all info displayed on the decentralized prediction market’s app.


Researchers have dubbed this assault as “frame-jacking”. It's a technique pertaining to manipulating HTML code depicting how information is exhibited to customers. That is very totally different from a pretend Augur utility making the rounds, as that's not the case by any means. As an alternative, the prediction markets’ sourcing of exterior information may end up in pretend info being proven. That information doesn't originate from Augur itself, albeit it will seem in any other case.


The vulnerability might be quite crippling for Augur. Body-jacking can modify market information, Ethereum addresses, and so forth. It's a very problematic improvement for a platform which absolutely depends on correct up-to-date info. This exploit has been reported to the builders and an up to date shopper has been launched. Customers are suggested to replace their utility accordingly.


The Augur Vulnerability Explained


Not a Trustless Surroundings

Incidents like these spotlight key flaws with platforms which require inherent belief. Regardless of being decentralized, Augur can not function with out belief. If the sourced info can't be relied upon, tasks like these may have no long-term future. The very fact this info might be manipulated so simply exhibits there’s nonetheless loads of work to be accomplished.


The Augur builders purposefully retailer some UI info domestically – sadly, this follow can typically result in single factors of failure, which may make the platform weak. Fortunately, a safety researcher working by HackerOne’s bug bounty platform found the flaw, quite than an precise felony.


The “white hat hacker” summed up the consequences of the vulnerability:


Consumer visits a hyperlink from web, his Augur utility information is changed by an attacker then – market information, Ethereum addresses, all the things.


He then goes on to elucidate in additional element:


Within the case it's found by somebody not collaborating in bug bounty program. What would he do? Properly, the logical step within the case somebody wished to take advantage of it will be, for instance, sending out phishing hyperlinks to Augur customers … changing all of the Ethereum addresses together with his personal, fund loss.


Somebody may discover it and simply create put up a Medium or some place else, describing how is it straightforward to hijack Augur’s UI information.


This silly, easy, small, and significant bug was present in Augur’s bug bounty program, the one with very excessive bonuses for vital bugs and really low expectations of such bugs being really discovered.


How such a key problem was allowed to ship as a part of the Augur app stays unknown. Though the mission’s underlying platform stays unaffected, it's nonetheless a gross oversight.


The researcher who uncovered the exploit was rewarded a $5,000 bug bounty reward ultimately – a value properly price stopping the potential lack of tens of millions of {dollars} in each consumer and platform funds.


What do you consider the concept of the “white hat hacker”? What ought to Augur builders do sooner or later to stop additional vulnerabilities? Tell us within the feedback beneath.


Pictures courtesy of Shutterstock





Tags: Augur, Prediction market, vulnerability, White Hat Hackers














Source link

Read the full article
Porträt von Satoshi Nakamoto

Satoshi Nakamoto

Zur Person

Satoshi Nakamoto