{"id":356620,"date":"2021-10-22T20:16:03","date_gmt":"2021-10-22T17:16:03","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/polygon-pays-2m-bounty-on-bug-which-could-have-compromised-850m-in-user-funds\/"},"modified":"2021-10-22T20:16:03","modified_gmt":"2021-10-22T17:16:03","slug":"polygon-pays-2m-bounty-on-bug-which-could-have-compromised-850m-in-user-funds","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/polygon-pays-2m-bounty-on-bug-which-could-have-compromised-850m-in-user-funds\/","title":{"rendered":"# Polygon pays $2M bounty on bug which could have compromised $850M in user funds"},"content":{"rendered":"<p>&#8220;<strong># Polygon pays $2M bounty on bug which could have compromised $850M in user funds <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTAvY2QwMDA1MjQtMDQ0My00YmI4LThhN2UtOTJmZjZhM2M3YzI2LmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>White hat hacker Gerhard Wagner has earned $2 million after reporting a solution to a potentially costly \u201cdouble-spend\u201d bug on the Polygon network.<\/p>\n<p>In an Oct. 21 blog post from Immunefi, a security service that helps facilitate bug reports in decentralized finance projects, Polygon network\u2019s Plasma Bridge was at <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/medium.com\/immunefi\/polygon-double-spend-bug-fix-postmortem-2m-bounty-5a1db09db7f1\">risk<\/a> of having $850 million removed by a knowledgeable hacker. According to the project, the vulnerability would have allowed attackers to exit their burn transaction from the bridge up to 223 times, quickly turning an amount like $4,500 into $1 million profi. <\/p>\n<p>Immunefi reported the double-spend exploit worked by first depositing Ether (ETH) through the Plasma Bridge and starting the withdrawal process after the transaction was confirmed. A hacker could then wait a week and resubmit the same withdrawals with the exception of &#8220;a modified first byte of the branch mask.&#8221; Provided the hacker was able to begin with $3.8 million, they could have potentially depleted all $850 funds from the bridge\u2019s deposit manager at the time.<\/p>\n<p>Polygon agreed to pay its maximum amount for a bug bounty report \u2014 $2 million \u2014 following Wagner\u2019s initial report on Oct. 5. According to the platform, the bug has already been deployed on the mainnet after testing, Wagner has received the funds, claimed to be \u201cthe highest bounty ever paid out in history,\u201d and no user funds were lost with the exploit.<\/p>\n<p>Wagner <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/gerhard-wagner.medium.com\/double-spending-bug-in-polygons-plasma-bridge-2e0954ccadf1\">speculated<\/a> on his Medium page that the bug might be due to \u201cusing someone else\u2019s code and not having a 100% understanding of what it does.\u201d He added the solution was \u201cnot very elegant\u201d but did fix the double-spend exploit. <\/p>\n<p><strong><em>Related: <\/em><\/strong><strong><em>White hat hacker paid DeFi\u2019s largest reported bounty fee<\/em><\/strong><\/p>\n<p>Before this latest $2 million payout, the largest bounty for a white hat hacker had gone towards programmer Alexander Schlindwein, who in September discovered a vulnerability in Belt Finance\u2019s protocol and was awarded $1.05 million. However, the U.S. Department of State may topple that record if a hacker is able pass on information on terrorist suspects, extremists and state-sponsored hackers \u2014 the government said it would be offering rewards of up to $10 million.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/polygon-pays-2m-bounty-on-bug-which-could-have-compromised-850m-in-user-funds\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Polygon pays $2M bounty on bug which could have compromised $850M in user funds &#8221; White hat hacker Gerhard Wagner has earned $2 million after reporting a solution to a potentially costly \u201cdouble-spend\u201d bug on the Polygon network. In an Oct. 21 blog post from Immunefi, a security service that helps facilitate bug reports&#8230;<\/p>\n","protected":false},"author":1,"featured_media":356621,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTAvY2QwMDA1MjQtMDQ0My00YmI4LThhN2UtOTJmZjZhM2M3YzI2LmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74868,113408,117,73821,70944],"class_list":["post-356620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-defi","tag-polygon","tag-business","tag-developers","tag-hackers"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/356620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=356620"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/356620\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/356621"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=356620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=356620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=356620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}