Vulnerability

46 Articles 0 Followers


Syscoin Hack Ethereum Bridge Bounty - The Cut Off Problem

14 Aug 2019 16 minute read 2 comments art_of_bug

Welcome back. Hacking production chains a.k.a. mainnets is the most fun, but when incentives allow, exploring testnets can be fun too. The following is our first submission to the hack the Syscoin's Ethereum bridge bounty (do follow this link also to...

Emercoin – Bypassing POS Temperature

28 Jul 2019 8 minute read 2 comments art_of_bug

Welcome to the next episode. Last time we discussed Emercoin's 51% attack and the related hardfork. We mentioned that there were more vulnerabilities we have discussed with Emercoin's team. Today we present one of the issues that we reported. It has...

Emercoin Hardfork Mess – Trivial 51% Attack

11 Jul 2019 12 minute read 0 comments art_of_bug

Welcome back. Last time we've talked about Particl. Since then there has been good news coming from Particl. The bugs were fixed and they are allegedly considering creating a proper bug bounty program. And we have published a post about how should a...

Particl – Using Spent Kernel To Split the Network

29 Jun 2019 11 minute read 8 comments art_of_bug

Welcome again. It took us a while to get back. The reasons are both simple and sad – communication with Altcoin vendors is very difficult and slow. Many Altcoins do not have any vulnerability policy in place. You have no idea who to contact and you h...

The big problem of MEGA.NZ and its new solution

31 May 2019 1 minute read 0 comments GranRethory

The big problem of MEGA.NZ and its new solution Today, checking my mega account, in the Security section ---> Session history (https://mega.nz/fm/account/security)I find several open sessions, of which I really do not know all, the problem is that...

Introduction & Neblio – VerifyInputsUnspent Denial of Service

11 May 2019 6 minute read 4 comments art_of_bug

Welcome to our first blog post. We hope you will enjoy our content. Today, we start with a vulnerability in Neblio project. We made several attempts to contact the Neblio team in April, but all our attempts failed. It seemed that they just refused to...