HomeNewsEthereum Foundation pays $50K bounty after Trust Security finds ERC4337 censoring attack!!

Ethereum Foundation pays $50K bounty after Trust Security finds ERC4337 censoring attack!!

-

The Ethereum Foundation awarded a $50,000 bug bounty on Thursday after researchers at Trust Security disclosed a high-severity flaw in ERC4337, the account-abstraction protocol. The flaw let attackers force certain valid, correctly signed account-abstraction transactions to revert while making the sender pay gas.

The foundation patched the issue and explained the exploit mechanics in its blog post. “This is a censorship and griefing vector, not a fund-theft vector,” the foundation added.

At discovery, usage of the vulnerable transaction type was limited. Still, users sent about 1.7 million vulnerable ERC4337 transactions last week, roughly 9% of all Ethereum transactions, data shows.

Bug bounties remain central to open-source security, and platforms track major payouts. The bug-bounty platform Immunefi has paid over $125 million to security researchers, and Trust Security said it accepted an additional $59,500 from DeFi apps using ERC4337.

Major users of the vulnerable transaction type include Safe and Biconomy, though Trust Security has not specified which apps issued bounties. Developers have implemented a fix requiring certain contract functions to run only from non-account-abstraction wallets, and the foundation urged protocols to upgrade promptly.

LATEST POSTS

SEC Settles With BitTorrent’s Rainberry for $10M, Dismisses Case Against Justin Sun

The U.S. Securities and Exchange Commission has moved to partially resolve its case against entrepreneur Justin Sun and associated entities. Under a proposed judgment, Rainberry...

Institutional Investors Return as Solana Stablecoin Volume Hits $650 Billion

Solana (SOL) shows signs of price stabilization around $90 after recent volatility, supported by renewed institutional interest. Spot ETFs for the asset have recorded significant...

Dubai Regulator Warns KuCoin May Be Operating Without License

Dubai's Virtual Assets Regulatory Authority (VARA) has issued a public warning about the cryptocurrency exchange KuCoin. The regulator states the exchange and related entities may...

Justin Sun settles with SEC for $10M, ending fraud lawsuit

The U.S. Securities and Exchange Commission has settled its fraud and securities lawsuit against cryptocurrency entrepreneur Justin Sun for $10 million. The agency said in...

Most Popular

spot_img