Arbitrum Saved From Major ETH Loss by White Hat Hacker

An anonymous developer effectively saved Arbitrum from a $250 million loss

article-image

Blockworks Exclusive art by axel rangel

share

key takeaways

  • Arbitrum paid 400 ETH via ImmuneFi to white hat hacker
  • Arbitrum bridge bug was caused by bad initializers in the contract code

Another cryptocurrency vulnerability has been uncovered by a so-called white hat hacker, who found an exploitable bug in the bridge between Ethereum and Arbitrum Nitro.

The hacker, known as riptide on Twitter, outlined their discovery, which comes on the heels of an escalating series of hacks in the bridges that connect different blockchains, which collectively have been drained of hundreds of millions of dollars of predominantly user funds this year. 

Arbitrum, the layer-2 Ethereum scaling solution, paid riptide a bounty of 400 ether (ETH) as a reward via the bug bounty platform ImmuneFi.

The multi-million dollar vulnerability, as riptide called it, would have allowed an attacker to steal all incoming ether deposits from users attempting to bridge their assets between Ethereum layer-1 and layer-2 protocols to Arbitrum.

The initialization-related vulnerability, according to the white hat hacker, would have enabled any nefarious actor to impersonate a user and send the authentication message to the “sequencerInbox” function to execute the vulnerability. 

The largest deposit recorded on the inbox contract was 168,000 ETH, around $250 million, with average deposits ranging from 1,000 to 5,000 ETH in a 24-hour period, riptide said. 

Loading Tweet..

Another Twitter user, smartcontracts.eth, commented that “rollups are still heavily in development,” cautioning his followers to be careful on layer-2 protocols. A layer-2 refers to a mechanism built on top of a blockchain’s core layer, typically to increase scalability or speed, plus introduce additional features. 

A similar bug was seen in the token bridge Nomad’s smart contract, which cost the protocol  $190 million in cryptocurrency in the third-biggest cryptocurrency hack of the year.

Arbitrum recently launched Nitro exactly one year after the rollup’s now-defunct first iteration and ahead of the Merge.

Arbitrum NFTs

Additionally, Arbitrum plans to integrate with NFT marketplace OpenSea on Wednesday. 

A slew of NFT collections built on Arbitrum will be available to buy and sell directly on OpenSea.

OpenSea tweeted that creators would need to find their collections and set their creator fees directly. 

The marketplace recently added the royalties percentages front-and-center on a collection’s page.

Loading Tweet..

Don’t miss the next big story – join our free daily newsletter.

Follow Sam Bankman-Fried’s trial with the latest news from the courtroom

Tags

Upcoming Events

MON - WED, MARCH 18 - 20, 2024

Blockworks’ Digital Asset Summit (DAS) will take place March 18-20, 2024 at The Hilton London Metropole. Why London? Momentum.  London has become one of the world’s hottest crypto hubs.  Innovation is thriving, new institutional investors are flocking in, and regulators like […]

recent research

l1 cover.png

Research

This analysis focuses on financial metrics for general-purpose L1 blockchains. In many ways, L1s should be viewed as an entirely new asset class more comparable to digital economies than traditional businesses. L1s are the core infrastructure enabling the creation of new-age businesses like onchain protocols.

article-image

Ripple previously announced its intent to acquire Fortress on Sept. 8

article-image

Four patent applications were published since Sept. 21, suggesting that PayPal is taking a close look at distributed ledger tech

article-image

If the market wasn’t quite so boring, perhaps BitBoy’s flameout would have been a little less fiery

article-image

Developers have a new testnet running, but devnet testing the Dencun upgrade is running behind schedule

article-image

A handful of Democrats are joining the anti-Gensler and pro-crypto movement

article-image

The Bank of International Settlements conducted the project in partnership with central banks from France, Singapore and Switzerland