Leon Spacewalker

5 posts

Leon Spacewalker banner
Leon Spacewalker

Leon Spacewalker

@leonspacewalker

Ex-Blitzballer

Fahrenheit Katılım Aralık 2021
13 Takip Edilen955 Takipçiler
Leon Spacewalker
Leon Spacewalker@leonspacewalker·
@TalBeerySec @0xPolygon Note that this is based on your 3 options, it might be Option 4. So to be fair, it probably has nothing to do with Polygon's decision of upgrading.
English
1
0
2
0
Tal Be'ery
Tal Be'ery@TalBeerySec·
The original white hat that discovered $MATIC vulnerability thinks "option 2" = "Blackhats observed the upgrade, reverse engineered it to deploy an exploit" is the most likely. If it's correct, then @0xPolygon's decision to patch that way was problematic (probleMATIC 😈? )
Leon Spacewalker@leonspacewalker

@TalBeerySec @0xPolygon Option 1: No, I used an automation tool that detects added/changed scopes from Immunefi’s bounties. Option 2: Most likely, as the bug itself is simple enough to be found by anyone who reaches the code first.

English
1
0
1
0
Leon Spacewalker
Leon Spacewalker@leonspacewalker·
@TalBeerySec @0xPolygon Option 3: No, all the communications were done in the Immunefi platform and my PoC was done in the local environment. I’m currently writing a blog to echo more on the Immunefi’s postmortem, mostly will be on the technical stuff tho but probably help shed more light for you
English
1
0
4
0
Tal Be'ery
Tal Be'ery@TalBeerySec·
Option 2: Blackhats observed the upgrade, reverse engineered it to deploy an exploit Option 3: Whitehats discussions, or initial trigger were on a not entirely private channel, thus sparking a race between whitehats and blackhats @0xPolygon can you please shed more light?
English
2
0
1
0
Leon Spacewalker
Leon Spacewalker@leonspacewalker·
@TalBeerySec @0xPolygon Option 1: No, I used an automation tool that detects added/changed scopes from Immunefi’s bounties. Option 2: Most likely, as the bug itself is simple enough to be found by anyone who reaches the code first.
English
0
0
5
0