• Latest
MakerDAO Bounty Program Catches ‚Critical‘ Bug Before Launch

MakerDAO Bounty Program Catches ‚Critical‘ Bug Before Launch

Oktober 3, 2019
6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

März 31, 2023
Judge denies SEC motion to keep Hinman docs secret in Ripple case

Judge denies SEC motion to keep Hinman docs secret in Ripple case

März 31, 2023
The ultimate guide to Miami – Cointelegraph Magazine

The ultimate guide to Miami – Cointelegraph Magazine

März 31, 2023
Dr. Jane Thomason – Cointelegraph Magazine

Dr. Jane Thomason – Cointelegraph Magazine

März 31, 2023
1658007797 celsius is bankrupt with 12b balance sheet hole su zhu.jpg

Celsius is bankrupt with $1.2B balance sheet hole, Su Zhu returns to Twitter and OpenSea purges 20% of employees: Hodler’s Digest, July 10-16

März 31, 2023
6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

März 31, 2023
Jed McCaleb empties XRP wallet after eight-year selloff

Jed McCaleb empties XRP wallet after eight-year selloff

März 31, 2023
Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

März 31, 2023
The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

März 31, 2023
SEC objects to XRP holders aiding Ripple defense

SEC objects to XRP holders aiding Ripple defense

März 31, 2023
Blockchain technology is transforming the real estate market – Cointelegraph Magazine

Blockchain technology is transforming the real estate market – Cointelegraph Magazine

März 31, 2023
1658612147 nfts banned in minecraft sec lists 9 tokens as securities.jpg

NFTs banned in Minecraft, SEC lists 9 tokens as securities and 3AC founder blames cockyness for company meltdown: Hodler’s Digest, July 17-23

März 31, 2023
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
CoinNewsDaily
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
CoinNewsDaily
No Result
View All Result
Home Business

MakerDAO Bounty Program Catches ‚Critical‘ Bug Before Launch

coinnewsdaily by coinnewsdaily
Oktober 3, 2019
in Business
0
MakerDAO Bounty Program Catches ‚Critical‘ Bug Before Launch
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

MakerDAO has patched a “critical” bug in its yet-to-be-launched Multi-Collateral Dai (MCD) upgrade that could have put more than 10% of the system’s total collateral at risk.

The bug was caught by HackerOne user lucash-dev, who reported it via the HackerOne forum and received a $50,000 bounty for uncovering the potentially devastating flaw.

Related articles

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

Juli 26, 2022
ygg sea surpasses 10,000 scholarships in just six months of launch

YGG SEA Surpasses 10,000 Scholarships in Just Six Months of Launch

Mai 6, 2022

“Our auction system allowed the potential attacker to create a fake auction, basically offering very little collateral for a large amount of DAI,” Chris Smith, a senior software engineer for MakerDAO, told CoinDesk. “The system would trust that number and use it as credit against collateral in the system, allowing the hacker to basically take that other collateral out of the system.”

The bug could have devastated MakerDAO’s planned MCD. Lucash-dev said in his report that it “allows an attacker to steal ALL collateral stored in the MCD system during the liquidation phase – possibly within a single transaction.”

Lucash-dev told CoinDesk:

“That would be disastrous if it ever happened in a live environment.”

But neither the bug nor the MCD upgrade host ever went live – it was caught during the testing phase, before any users had access to the system.

Both lucash-dev and MakerDAO engineers told CoinDesk that no user funds were ever placed at risk.

Under the new MCD, users will be able to stake cryptocurrencies other than ETH as collateral to issue new Dai. The value of these “collateralized debt positions” has to match the Dai in circulation as Dai is a representative currency – much like the US dollar was when it was backed by gold. Certain users can trigger a liquidation mode to balance out the system.

Lucash-dev told CoinDesk that the system had a fault:

“The new Multi-collateral DAI contracts can enter a ‘liquidation mode’ – that means that everyone who own DAI will just collect the collateral tokens corresponding to their DAI stake. The bug allows an attacker to trick the system to give them any number of DAI (only during the liquidation mode), which can in turn be exchanged by all tokens held as collateral!”

The bug exploited MCD’s kick contract implementation that allowed users to post phony auctions, issue DAI, and then cash out collateral.

Wouter Kampmann, head of engineering for MakerDAO, said that bug tracking events like this were routine.

“Its through processes like these that you get through the system and make sure that it’s absolutely as secure as possible before you launch it.”

The bug was posted on August 28 and patched by September 26. Lucash-dev disclosed it to the public on October 1.

Hacker image via Shutterstock

Credit: Source link

Tags: BusinessCryptoCrypto Business
Share76Tweet48
Previous Post

Algorand Integrates Tech to Bring Users Detailed Analysis of Largest Blockchains

Next Post

Ohio Treasurer Suspends Predecessor’s Bitcoin Tax Payment Service

coinnewsdaily

coinnewsdaily

CoinNewsDaily.com is an online Crypto Coin News Website that aims to provide latest trendy news from market and around the world.

Related Posts

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses
Business

IoTeX’s MachineFi Lab challenges Big Tech by democratizing IoT to benefit users and businesses

Juli 26, 2022
ygg sea surpasses 10,000 scholarships in just six months of launch
Alt Coin

YGG SEA Surpasses 10,000 Scholarships in Just Six Months of Launch

Mai 6, 2022
5 projects enabling smart contract development on bitcoin
Alt Coin

5 Projects Enabling Smart Contract Development on Bitcoin

April 29, 2022
cross chain services play a crucial role in facilitating continued adoption of defi applications
Alt Coin

Cross-Chain Services Play a Crucial Role in Facilitating Continued Adoption of DeFi Applications

April 26, 2022
justin sun launches usdd, integrating the blockchain world and the real world with the decentralized stablecoin
Alt Coin

Justin Sun Launches USDD, Integrating the Blockchain World and the Real World with the Decentralized Stablecoin

April 25, 2022
what are wrapped tokens?
Bitcoin

What Are Wrapped Tokens?

April 23, 2022
Load More
Next Post
Ohio Treasurer Suspends Predecessor’s Bitcoin Tax Payment Service

Ohio Treasurer Suspends Predecessor's Bitcoin Tax Payment Service

Kategorien

  • Alt Coin
  • Bitcoin
  • Business
  • Ethereum
  • ICO
  • Litecoin
  • Mining
  • NFT
  • Ripple
  • Tech
  • Trading

What New here?

  • 6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine
  • Judge denies SEC motion to keep Hinman docs secret in Ripple case
  • The ultimate guide to Miami – Cointelegraph Magazine
  • About Us
  • Contact Us
  • Privacy & Policy

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev

Please enter CoinMarketCap Free Api Key to get this plugin works.
✕
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev