300750 CONTEMPORARY AMPEREX TECHNOLOGY CO

Verichains Discloses Blockchain security Vulnerabilities,urges action

Verichains
Verichains Discloses Blockchain security Vulnerabilities,urges action

08-March-2023 / 15:50 CET/CEST
The issuer is solely responsible for the content of this announcement.


Verichains Discloses Blockchain Security Vulnerabilities, Urges Action

NEWS RELEASE BY VERICHAINS

 

HO CHI MINH CITY, VIETNAM | March 08, 2023 08:54 AM Eastern Standard Time

Leading blockchain security firm Verichains has urged projects using IAVL proof verification in Tendermint Core to secure their assets and mitigate exploitation risks after identifying several significant vulnerabilities.

As part of its Responsible Vulnerability Disclosure Policy, Verichains has released two related public advisories,, on a critical Empty Merkle Tree vulnerability in the IAVL proof and  on a critical IAVL Spoofing Attack via multiple vulnerabilities on Tendermint Core.

Tendermint BFT consensus engine and Cosmos-SDK are popular blockchain platforms with which numerous popular projects have been built, such as BNB Smart Chain (BSC), OKX Chain, Band Chain, and the now defunct Terra (LUNA).

Verichains made these discoveries while carrying out work last October after the BNB Chain bridge was hacked. Security specialists, who identified the critical IAVL Spoofing Attack via multiple vulnerabilities found in BNB Chain and Tendermint, say it could have resulted in a significant loss of funds.

Although a private disclosure was made to the Tendermint/Cosmos maintainer, and the vulnerabilities duly acknowledged, a patch was not released for the Tendermint Core library as the Cosmos-SDK and IBC had already migrated to ICS-23 from IAVL Merkle proof verification.

However, due to the incredible popularity of Tendermint and the enormous sums of money held in by other projects, we can ascertain that the potential scale of impact should not be taken lightly. For example, in October, the BNB Chain's Cross-Chain Bridge was exploited to illegally issue 2m BNB, worth approximately US$566m, due to a vulnerability in IAVL RangeProof verification of Tendermint.

BNB Chain was also notified by Verichains of these findings in October simultaneously due to an existing working relationship, and the issue was swiftly patched on the same day. No malicious exploitation occurred, and no funds were lost.

Verichains has followed its Responsible Vulnerability Disclosure Policy to now notify the public after the requisite 120 days. Verichains has urged affected Web3 projects, still using Tendermint's IAVL proof verification, to upgrade their security before suffering a catastrophic loss.

Last year, numerous blockchain bridges were breached after hackers identified and exploited weaknesses. If not fixed, the critical nature of the bugs may lead to further hacks and consequent loss of funds, which in some cases could result in millions or even billions of dollars lost.

Security flaws and vulnerabilities identified by the Verichains team during its research and testing are regularly posted on the company's website.

About Verichains

 

 

Contact Details

 

Dan Edelstein

 

 

 

 



Dissemination of a CORPORATE NEWS, transmitted by EQS Group.
The issuer is solely responsible for the content of this announcement.


End of Announcement - EQS News Service

1577967  08-March-2023 

fncls.ssp?fn=show_t_gif&application_id=1577967&application_name=news&site_id=research_pool
EN
08/03/2023

Underlying

300750CONTEMPORARY AMPEREX TECHNOLOGY CO

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on CONTEMPORARY AMPEREX TECHNOLOGY CO

 PRESS RELEASE

EQS-News: vbw Pressemitteilung zum Koalitionsvertrag: Gute Grundlage

Emittent / Herausgeber: ibw – Informationszentrale der Bayerischen Wirtschaft e. V. / Schlagwort(e): Sonstiges/Sonstiges vbw Pressemitteilung zum Koalitionsvertrag: Gute Grundlage 10.04.2025 / 09:30 CET/CEST Für den Inhalt der Mitteilung ist der Emittent / Herausgeber verantwortlich. vbw zum Koalitionsvertrag: Gute Grundlage Brossardt: „Koalitionsvertrag schafft Planungssicherheit und setzt Wachstumsimpulse“  Bertram Brossardt, Hauptgeschäftsführer der vbw – Vereinigung der Bayerischen Wirtschaft e. V.: (München, 09.04.2025). Wir freuen uns, dass jetzt der Weg frei ist f...

 PRESS RELEASE

Aquis Stock Exchange - suspension of trading

Aquis Stock Exchange Aquis Stock Exchange - suspension of trading 10-Apr-2025 / 07:00 GMT/BST The issuer is solely responsible for the content of this announcement. The following securities are suspended from trading on the Aquis Growth Market from 08.00, 10 April 2025, at the request of the company: Richmond Hill Resources Plc Ordinary Shares Symbol: SHNJ ISIN: GB00BNTBWF32 The Regulation Department Aquis Stock Exchange Floor 2, 63 Queen Victoria Street, EC4N 4UA Tel: 0203 597 6361 Email:  Website:  Dissemination of a CORPORATE NEWS, transmitted by EQS Group.The i...

 PRESS RELEASE

EQS-News: CO2Coin one of the most successful crypto investments of the...

Issuer: Clima4Future Ltd. / Key word(s): Cryptocurrency / Blockchain/Market Launch CO2Coin one of the most successful crypto investments of the coming decades. 10.04.2025 / 04:55 CET/CEST The issuer is solely responsible for the content of this announcement.     CO2Coin is going through a phase of phenomenal growth. A year ago the price was just €1, today it is around 270 USDT - an increase in value that illustrates the enormous potential of this unique project. This development reflects the crypto community's growing interest in sustainable investments. Clima4Future Lt...

 PRESS RELEASE

EQS-News: CO2Coin eine der erfolgreichsten Krypto-Investitionen der ko...

Emittent / Herausgeber: Clima4Future Ltd. / Schlagwort(e): Kryptowährung / Blockchain/Markteinführung CO2Coin eine der erfolgreichsten Krypto-Investitionen der kommenden Jahrzehnte. 10.04.2025 / 04:55 CET/CEST Für den Inhalt der Mitteilung ist der Emittent / Herausgeber verantwortlich. Der CO2Coin hat einen beeindruckenden Kursanstieg erlebt. Vor einem Jahr lag der Kurs noch bei 1 €, heute liegt er bei rund 270 USDT - eine Wertsteigerung, die das enorme Potenzial dieses einzigartigen Projekts verdeutlicht. Diese Entwicklung spiegelt das wachsende Interesse der Krypto-Com...

 PRESS RELEASE

EQS-News: Zimbabwe Government Delivers on Commitment: Compensation of ...

EQS-News: Zimbabwe Ministry of Finance, Economic Development and Investment Promotion / Key word(s): Miscellaneous Zimbabwe Government Delivers on Commitment: Compensation of Former Farm Owners under the Global Compensation Deed Commences 09.04.2025 / 20:20 CET/CEST The issuer is solely responsible for the content of this announcement. In line with the GCD agreement, the FFOs receive 1 per cent of their claim in cash, with the balance being paid through US$ denominated Treasury bonds with a 2 per cent coupon and maturities of 2 to 10 years HARARE, Zimbabwe, April 9, 2025...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch