BTC $84,654.09 -1.77%
ETH $2,685.73 -2.37%
BNB $766.91 -1.18%
XRP $1.49 -3.48%
SOL $119.40 -2.15%
TRX $0.3355 +0.28%
DOGE $0.0927 -4.61%
ADA $0.2441 -4.63%
BCH $311.63 -1.12%
LINK $13.97 -3.19%
HYPE $87.84 -2.24%
AAVE $181.30 -0.28%
SUI $1.14 -2.04%
XLM $0.2142 -4.50%
ZEC $1,316.82 -5.11%
AAPL $333.52 +0.69%
AMZN $252.00 +0.82%
GOOGL $343.72 +0.75%
MSFT $517.23 +0.06%
META $728.30 -0.34%
NVDA $234.66 +0.56%
TSLA $370.84 +3.64%
SNDK $1,716.67 -4.56%
INTC $118.17 -3.46%
SPCX $159.13 +6.40%
MU $1,070.14 -3.46%
AMD $632.83 +1.34%
BTC $84,654.09 -1.77%
ETH $2,685.73 -2.37%
BNB $766.91 -1.18%
XRP $1.49 -3.48%
SOL $119.40 -2.15%
TRX $0.3355 +0.28%
DOGE $0.0927 -4.61%
ADA $0.2441 -4.63%
BCH $311.63 -1.12%
LINK $13.97 -3.19%
HYPE $87.84 -2.24%
AAVE $181.30 -0.28%
SUI $1.14 -2.04%
XLM $0.2142 -4.50%
ZEC $1,316.82 -5.11%
AAPL $333.52 +0.69%
AMZN $252.00 +0.82%
GOOGL $343.72 +0.75%
MSFT $517.23 +0.06%
META $728.30 -0.34%
NVDA $234.66 +0.56%
TSLA $370.84 +3.64%
SNDK $1,716.67 -4.56%
INTC $118.17 -3.46%
SPCX $159.13 +6.40%
MU $1,070.14 -3.46%
AMD $632.83 +1.34%

mm

All
Article
Flash

first_img Arbitrum Security Committee urgently suspended the activation of the new contract Stylus and added BoLD protection

On October 2, at 11:30 AM Eastern Time, the Arbitrum Security Committee executed an emergency upgrade on Arbitrum One and Nova, suspending the activation of all new Stylus contracts on both chains, while adding a protective mechanism against BoLD single-step proofs in the dispute system of Arbitrum One. The Arbitrum Foundation stated that this action is part of ongoing proactive security measures aimed at protecting the security and integrity of the network.Stylus allows developers to write smart contracts using languages such as Rust and C++, while maintaining compatibility with the Ethereum Virtual Machine, with its programs compiled into WebAssembly format. This suspension primarily targets manually written WASM programs that do not use the standard Stylus compiler toolchain and have not yet been patched by the current version of ArbOS. The Security Committee increased the gas required for activation to the theoretical maximum by calling ArbOwner.setWasmActivationGas(2^64 - 1), making new activations economically unfeasible. Activated Stylus contracts are unaffected and can continue to execute and renew, and the deployment and execution of Solidity contracts are also unrestricted.The newly added BoLD protection allows anyone to pause the settlement from Arbitrum One to Ethereum when two conflicting and accepted answers appear in the same dispute step, which may delay unconfirmed withdrawals to allow the Security Committee to deploy fixes. Officials pointed out that the currently discovered Stylus-related vulnerabilities mainly affect the activity of the chain, such as denial-of-service attacks, and do not jeopardize user funds.

first_img Core Lightning warns that old version nodes are under attack and urges operators to upgrade immediately

The Core Lightning team, which develops the open-source Bitcoin Lightning Network node software, has issued an urgent alert stating that reports indicate attackers are targeting nodes that have not installed patches, urging operators still running old versions to upgrade immediately. The team stated: "Emergency security update: If you are using version 26.06.7 or earlier, please upgrade to the latest release as soon as possible."Prior to this, Core Lightning began investigating a potential issue that could affect its experimental features and, in turn, impact user funds on September 16, and approximately six days later, version 26.06.8 was released. This update not only fixed several defects but also provided patches for security vulnerabilities reported responsibly by multiple parties, thanking the Bitcoin Red Team and 12 other individuals and organizations in the release notes, while also acknowledging anonymous reporters.According to the changelog, this round of fixes covers a bug that could cause sender nodes to crash, requests that could exhaust REST interface memory, and a vulnerability that could result in user funds facing confiscation losses when closing payment channels. To provide operators with ample upgrade windows and prevent attackers from taking advantage of reverse engineering and exploitation, this version intentionally obscured some testing content. Additionally, in August of this year, the project initiated a collaborative fixing process after reviewing a large number of AI-generated general vulnerability disclosure reports, and two days later released version 26.06.7 to close confirmed vulnerabilities.
app_icon
ChainCatcher Building the Web3 world with innovations.