Offchain Labs publicly discloses two serious vulnerabilities in OP Stack fraud proofs

2024-04-26 22:29:52 Views

On April 26, Arbitrum R&D team Offchain Labs announced that it had disclosed two serious security vulnerabilities found on the Optimism testnet to the OP Labs team on March 22. These vulnerabilities exist in the Optimism fraud proof system deployed by OP Labs. Offchain Labs provided the OP Labs team with demonstration exploit code for attack. On March 25, OP Labs confirmed the validity of the two issues, and the two parties coordinated the time of vulnerability disclosure. OP Labs asked Offchain Labs not to publicly disclose these vulnerabilities until they were resolved. Late yesterday (April 25), the Optimism testnet was updated, and today Offchain Labs disclosed these vulnerabilities for the first time. These vulnerabilities allow malicious parties to force the OP Stack fraud proof mechanism to accept fraudulent chain history, or prevent the OP Stack fraud proof mechanism from accepting the correct chain history. These problems stem from defects in the OP fraud proof design in handling timers.

  Disclaimer: Includes third-party opinions. No financial advice. See Risk Warning.
  
Title:Offchain Labs publicly discloses two serious vulnerabilities in OP Stack fraud proofs - Flash
Address:https://www.j56.xyz/flash/6522.html

You may also like

Related Articles