{"id":343116,"date":"2021-09-23T10:54:47","date_gmt":"2021-09-23T07:54:47","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/sushiswap-denies-reports-of-billion-dollar-bug\/"},"modified":"2021-09-23T10:54:47","modified_gmt":"2021-09-23T07:54:47","slug":"sushiswap-denies-reports-of-billion-dollar-bug","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/sushiswap-denies-reports-of-billion-dollar-bug\/","title":{"rendered":"# SushiSwap denies reports of billion dollar bug"},"content":{"rendered":"<p>&#8220;<strong># SushiSwap denies reports of billion dollar bug <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDkvODFlOTFkZTctYTk4MC00OTRmLWIyYjQtMGQzNjJlZDNmNTA4LmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>The developer behind popular decentralized exchange SushiSwap has rejected a purported vulnerability reported by a white-hat hacker snooping through their smart contracts.<\/p>\n<p>According to <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a> reports, the hacker <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/CryptoWilfred\/status\/1440811435202809861\">claimed<\/a> to have identified a vulnerability that could place more than $1 billion worth of user funds under threats, stating they went public with the information after attempts to reach out to SushiSwap\u2019s developers resulted in inaction.<\/p>\n<p>The hacker claims to have identified a \u201cvulnerability within the emergencyWithdraw function in two of SushiSwap\u2019s contracts, MasterChefV2 and MiniChefV2\u201d \u2014 contracts that govern the exchange\u2019s 2x reward farms and the pools on SushiSwap\u2019s non-Ethereum deployments such as Polygon, Binance Smart Chain and Avalanche.<\/p>\n<p>While the emergencyWithdraw function allows liquidity providers to immediately claim their LP tokens while forfeiting rewards in the event of an emergency, the hacker claims the feature will fail if no rewards are held within the SushiSwap pool \u2014 forcing liquidity providers to wait for the pool to be manually refilled over a roughly 10-hour process before they can withdraw their tokens.<\/p>\n<p>\u201cIt can take <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>roximately 10 hours for all signature holders to consent to refilling the rewards account, and some reward pools are empty multiple times a month,\u201d the hacker claimed, adding:<\/p>\n<blockquote><p>\u201cSushiSwap\u2019s non-Ethereum deployments and 2x rewards (all using the vulnerable MiniChefV2 and MasterChefV2 contracts) hold over $1 billion in total value. This means that this value is essentially untouchable for 10-hours several times a month.\u201d\u00a0<\/p><\/blockquote>\n<p>However, SushiSwap\u2019s pseudonymous developer has taken to Twitter to reject the claims, with the platform&#8217;s &#8220;Shadowy Super Coder Mudit Gupta stressing that the threat described \u201cis not a vulnerability\u201d and that \u201cno funds are at risk.\u201d<\/p>\n<p>Gupta <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1440886435691720709\">clarified<\/a> that \u201canyone\u201d can top up the pool\u2019s rewarder in the event of an emergency, bypassing much of the 10-hour multi-sig process the hacker claimed is needed to replenish the rewards pool. They added:<\/p>\n<blockquote><p>\u201cThe hacker&#8217;s claim that someone can put in a lot of lp to drain the rewarder faster is incorrect. Reward per LP goes down if you add more LP.\u201d<\/p><\/blockquote>\n<p><strong><em>Related: <\/em><\/strong><strong><em>SushiSwap\u2019s token launchpad, MISO, hacked for $3M<\/em><\/strong><\/p>\n<p>The hacker said they had bee instructed to report the vulnerability on bug bounty platform Immunefi \u2014 where SushiSwap is offering to pay rewards of up to $40,000 to users that report risky vulnerabilities in their code \u2014 after they first reached out to the exchange. <\/p>\n<p>They noted that the issue was closed on Immunefi without compensation, with SushiSwap stating they were aware of the matter described.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/sushiswap-denies-reports-of-billion-dollar-bug\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# SushiSwap denies reports of billion dollar bug &#8221; The developer behind popular decentralized exchange SushiSwap has rejected a purported vulnerability reported by a white-hat hacker snooping through their smart contracts. According to media reports, the hacker claimed to have identified a vulnerability that could place more than $1 billion worth of user funds under&#8230;<\/p>\n","protected":false},"author":1,"featured_media":343117,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDkvODFlOTFkZTctYTk4MC00OTRmLWIyYjQtMGQzNjJlZDNmNTA4LmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74860,74868,74882,89215],"class_list":["post-343116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-cryptocurrency-exchange","tag-defi","tag-hacks","tag-sushiswap"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/343116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=343116"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/343116\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/343117"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=343116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=343116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=343116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}