CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

OpenZeppelin Discovers $15 Billion Rug Pull Vulnerability In Convex Finance

April 5, 2022
in Crypto News
Reading Time: 3 mins read
A A
0
OpenZeppelin Discovers $15 Billion Rug Pull Vulnerability In Convex Finance
0
SHARES
5
VIEWS
ShareShareShareShareShare

RELATED POSTS

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

A routine security audit turned into a potential nightmare for Convex Finance as OpenZeppelin’s security team discovered a vulnerability during a security review of the Convex Finance protocol. 

The bug, if exploited, could have potentially put Convex’s locked value, $15 billion at the time, at risk, giving explorers direct control over it. It is interesting to note that documentation by Convex had stated that such a level of control over its locked value would not have been possible. Since its discovery, the Convex team has been quick to patch the vulnerability. 

Details Of The Bug 

OpenZeppelin shed light on the bug’s discovery and subsequent patching in a blog post. Convex, one of the most prominent DeFi protocols, had a significant bug that put $15 billion of its locked value at risk. The protocol holds a majority of Curve Finance’s CRV tokens. Curve is a leading stablecoin automated market maker that provides around 1/10th of the decentralized economy’s liquidity. 

The bug discovered by OpenZeppelin’s Security Research Team meant that if two or three signers of Convex’s multisig execute a specific series of steps, they gained unrestricted access to Liquidity Provider tokens that have been staked in a target pool configured by the LP token and target gauge. 

Documentation from Convex showed that such a scenario should not be possible, but has since been updated. This made the resolution slightly tricky. However, the vulnerability was patched on 14th December 2021. You can find out more about how the bug could have been exploited here.

Disclosure Complications 

We mentioned that the bug’s disclosure was slightly tricky for OpenZeppelin’s team. Let’s understand why. It becomes slightly complicated if a team finds a protocol vulnerability that can be exploited or patched only by the protocol in question’s developer team. This vulnerability provides an ideal window for how misaligned incentives and imperfect situational knowledge could lead to complications when it comes to disclosures of vulnerabilities. In the case of Curve, the vulnerability could only be exploited by Convex’s anonymous developers. 

OpenZeppelin was confident that the vulnerability on Convex was unintentional, but they could not be certain. Another layer of complication was that even if the Convex team was unaware of the bug, disclosure created an incentive for developers on Convex to act maliciously, with $15 billion up for grabs. While OpenZeppelin was willing to give the benefit of the doubt to Convex developers, the implications were significant if it were proved to be wrong. 

The Way Forward With The Disclosure 

OpenZeppelin’s concerns could be dispelled if Convex revealed the developers’ identities. However, this could lead to security concerns at Convex’s end, with developers losing their anonymity. OpenZeppelin’s team was thus left with three ways forward. 

  • Disclosing the vulnerability details to Convex – This carried some risk as if the vulnerability was intentional, the disclosure would have prompted developers to execute their intended rug pull. 
  • Disclose the vulnerability to the community – While there was some argument in favor of disclosing the vulnerability to the community at large, OpenZeppelin felt this course of action would have been irresponsible. Two possible scenarios could have emerged from this course of action. If the vulnerability were disclosed and was intentional, developers would have executed their rug pull. However, if it were unintentional, it would have caused significant harm to Convex’s reputation. 
  • Obtain assurances that the Convex team would not exploit the vulnerability and then disclose – This was the approach taken by OpenZeppelin, with the team reaching out to bug bounty partner Immunefi for an intermediary between Convex and OpenZeppelin. 

Addition Of Publicly Known Persons To Convex Multisig 

Adding publicly known participants to the Convex multisig was key to reducing risk. OpenZeppelin’s security team and the anonymous developers at Convex agreed that the addition of publicly known parties to the multisig was the best course of action, making a rug pull impossible to execute. After communication between OpenZeppelin and Convex was established, the latter patched the vulnerability. 

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.


Credit: Source link

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Colombian Money Laundering Watchdog Postpones Crypto Transaction Reporting Resolution – Bitcoin News

Next Post

Here’s What’s Ahead for Chainlink, NEAR and Three Other Altcoins, According to Analyst Michaël van de Poppe

Related Posts

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
Crypto News

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026
Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)
Crypto News

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

April 8, 2026
Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link
Crypto News

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

April 8, 2026
Next Post
Here’s What’s Ahead for Chainlink, NEAR and Three Other Altcoins, According to Analyst Michaël van de Poppe

Here’s What’s Ahead for Chainlink, NEAR and Three Other Altcoins, According to Analyst Michaël van de Poppe

Shanghai Includes Metaverse in Electronic Information Development Plan

Zilliqa Becomes First L1 to Launch Metaverse Platform Metapolis

Recommended Stories

Treasury Proposes Stablecoin AML Rules as Bessent Vows to Protect US Financial System – Crypto News Bitcoin News

Treasury Proposes Stablecoin AML Rules as Bessent Vows to Protect US Financial System – Crypto News Bitcoin News

April 8, 2026
Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026
Can US-Iran new peace deal signal keep Bitcoin above $70,000?

Can US-Iran new peace deal signal keep Bitcoin above $70,000?

April 8, 2026

Popular Stories

  • Winklevoss Twins Continue Crypto Donation Spree With Another $1,000,000 in Bitcoin (BTC)

    Trader Says DeFi Altcoin Aave Witnessing Clear Trend Switch, Updates Forecast on Two Low-Cap Coins

    0 shares
    Share 0 Tweet 0
  • Huobi to Discontinue Cloud Wallet Service in May 2023

    0 shares
    Share 0 Tweet 0
  • Bitcoin Rejected at $29K, Arbitrum’s ARB Dumps 20% Daily: Weekend Watch

    0 shares
    Share 0 Tweet 0
  • FTX and Entertainment Giant Dolphin to Launch NFT Marketplace – Bitcoin News

    0 shares
    Share 0 Tweet 0
  • Privacy Is Key for Successful Digital Euro, Data Protection Body Says – Regulation Bitcoin News

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
  • SEC Opens Proceedings on NYSE Proposal to List Grayscale Crypto ETF Options – Regulation Bitcoin News
  • Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.