Latest

CertiK found a bug in Sui blockchain

  • Failure found before Sui mainnet launched
  • The company paid $500,000 

Blockchain security company CertiK found a bug in Sui blockchain. The vulnerability that posed a threat was an “endless loop” in the blockchain code, “long before the network was up and running.”. A malicious smart contract could cause this error by making blockchain nodes move in an endless loop, essentially paralyzing the network.

In a statement, CertiK writes:

“An attack called HamsterWheel manipulates all nodes so that they keep running continuously, but do not process new transactions. And traditional attacks simply stop the chains by destroying the nodes. This strategy could paralyze the entire network, rendering it inoperable.”

Sui Foundation said that immediately after discovering the attack vector, they took two key measures that would reduce the potential impact of similar problems in the future. CertiK has confirmed the bug fixes and has promised to publish a full technical report in the future.

Darius Gur, Sui Foundation Head of Communications said:

“Thanks to the bug bounty program, along with robust third party audit programs and thorough internal testing, the first six weeks of Sui mainnet have been very successful from an operational and security perspective.”

.