<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
     xmlns:georss="http://www.georss.org/georss"
     xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
     xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[Polygon avoids $850 million in losses and pays out $2 million for disclosing a vulnerability]]></title>
        <atom:link href="https://usagag.com/2021/10/22/polygon-avoids-850-million-in-losses-and-pays-out-2-million-for-disclosing-a-vulnerability/" rel="self" type="application/rss+xml" />
        <link>https://usagag.com/2021/10/22/polygon-avoids-850-million-in-losses-and-pays-out-2-million-for-disclosing-a-vulnerability/</link>
        <lastBuildDate>Fri, 22 Oct 2021 08:58:00 +0000</lastBuildDate>
        <sy:updatePeriod>hourly</sy:updatePeriod>
        <sy:updateFrequency>1</sy:updateFrequency>
        <generator>https://usagag.com</generator>
        <media:content url="/uploads/2021/10/22/polygon-avoids-850-million-in-losses-and-pays-out-2-million-for-disclosing-a-vulnerability.jpg" medium="image">
            <media:title type="html">Polygon avoids $850 million in losses and pays out $2 million for disclosing a vulnerability</media:title>
        </media:content>
        <content:encoded><![CDATA[<p>The Polygon team, on the other hand, was quick to reassure the community that no user funds were lost as a result of the exploit. In fact, Polygon revealed that it has offered a $2 million bounty to Whitehat Gerhard Wagner in exchange for "responsibly disclosing the bug."</p>
<p>Immunefi, a DeFi bug bounty platform, went on to say that it is the highest bug bounty payment ever made in history.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">As promised, we broke another record. <a href="https://twitter.com/g3rh4rdw4gn3r?ref_src=twsrc%5Etfw">@g3rh4rdw4gn3r</a> found a bug in <a href="https://twitter.com/0xPolygon?ref_src=twsrc%5Etfw">@0xPolygon</a>'s plasma bridge that could have resulted in an $850m loss if exploited. <br /><br />The bounty payout is the largest: $2m. <br /><br />Bug fixed. Everyone is safe! <br /><br />A real win for all.<a href="https://t.co/1fqd4ul3uO">https://t.co/1fqd4ul3uO</a></p>
&mdash; Immunefi (@immunefi) <a href="https://twitter.com/immunefi/status/1451172696243511299?ref_src=twsrc%5Etfw">October 21, 2021</a></blockquote>
<p>
<script src="https://platform.twitter.com/widgets.js" async=""></script>
</p>
<p>Wagner, according to Immunefi, reported a bug affecting the Polygon Plasma Bridge earlier this month. According to a report issued by the platform,</p>
<blockquote><strong>&ldquo;The vulnerability allowed an attacker to exit their burn transaction from the bridge multiple times, up to 223 times.&rdquo;</strong></blockquote>
<p>It was essentially a double-spending bug that affected the network's 'Deposit Manager.' We already know that Polygon supports Ethereum blockchain interoperability. The security flaw was discovered in the withdrawal procedure, which verifies transaction burn proof.</p>
<p>After receiving the report from Immunefi, Polygon fixed the breach in about a week. Aside from the bug bounty, Polygon has also paid Immunefi a commission for facilitating the bounty program.</p>
<p><img style="display: block; margin-left: auto; margin-right: auto;"  data-src="/uploads/2021/10/22/AF78C6271863DD17F3D1FAB6FBEF08725737FF5D2E674F7E0FD2E94FEB9BDD27.jpg" width="80%" /></p>
<h3>What might have happened if the bug had not been discovered sooner?</h3>
<p>In the event that the plug was delayed, a large deposit of ETH tokens via the Polygon Bridge could have resubmitted a withdrawal procedure 223 times.</p>
<p>Wagner elaborated,</p>
<blockquote>
<p><strong>&ldquo;A malicious user can leverage the issue to create alternative exits for the same burn transaction and perform double spends on the Polygon network.&rdquo;</strong></p>
</blockquote>
<p>It is worth noting that there is a seven-day waiting period before a user can claim funds back to their Ethereum account. As a result, after the waiting period, a malicious user with a $200,000 initial deposit could end up receiving an additional $44.6 million for the same transaction.</p>
<p>However, there is one point that needs to be clarified. Polygon has two bridges available: the Plasma bridge and the PoS bridge. The bug was only discovered in the previous protocol.</p>
<p>Polygon has recently seen a surge in developer interest. In fact, Alchemy revealed in a recent post that active developers are increasing by more than 60% on average every month.</p>
<figure class="image"><img  data-src="/uploads/2021/10/22/argument-g87ad2592a_1280.png" alt="Additionally, the month-on-month usage has grown by over 145%, as of October." width="770" height="440" />
<figcaption>
<p style="margin: 0px 0px 20px; padding: 0px; border: 0px; font-size: 1.1rem; vertical-align: baseline; color: #000000; font-family: 'PT Serif', sans-serif; line-height: 1.55;">Additionally, the month-on-month usage has grown by over 145%, as of October.</p>

<div id="ambcr-1707068578" class="ambcr-after-content" style="margin: 0px auto; padding: 0px; border: 0px; font-size: 16px; vertical-align: baseline;">

<form id="mc-embedded-subscribe-form" class="validate" style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline;" action="https://ambcrypto.us18.list-manage.com/subscribe/post?u=35eaf2f0f1f82e28b84b25a4e&amp;id=6b74f8871e" method="post" name="mc-embedded-subscribe-form" novalidate="novalidate" target="_blank">

<div class="form_area" style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline; width: 740px; color: #000000; background-color: #ffffff; font-family: 'PT Serif', sans-serif !important;">
<div class="form_inner" style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline; background-color: #ecd9c6;">
<div class="container" style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline;">&nbsp;</div>
</div>
</div>
</form></div>
</figcaption>
</figure>
<script async="" src="https://platform.twitter.com/widgets.js"></script>]]></content:encoded>
                <dc:creator><![CDATA[Elon Mark]]></dc:creator>
            </channel>
</rss><!--Time: 0.022742986679077-->