Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Galaxy Research Drops CLARITY Act Approval Odds From 75% to 60%

June 8, 2026

SIREN crypto soars 44% – But can bulls ignore THESE warning signs?

June 8, 2026

World Cup prediction markets hit $2B before kickoff as Spain and France go head to head

June 8, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Jump Crypto finds double-voting vulnerability in Celer’s SGN
Security and Privacy

Jump Crypto finds double-voting vulnerability in Celer’s SGN

May 26, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Web3 investor and developer Jump Crypto has identified a vulnerability in Celer’s State Guardian Network (SGN) that would allow malicious validators to compromise the network and applications dependent on it, including Celer’s cBridge.

According to Jump Crypto’s postmortem report, validators were allowed to vote more than once on the same update due to a bug in the SGN EndBlocker code. By allowing validators to vote multiple times, malicious actors could multiply their voting power to approve harmful updates. The report explained:

“The [EndBlocker] code is missing a check that prevents a validator from voting on the same update twice. A malicious validator could exploit this by voting multiple times on the same update, effectively multiplying their voting power and potentially tipping the vote in favor of an invalid or malicious update.”

Celer is a Cosmos-based blockchain that supports cross-chain communication. Jump reviewed the script after Celer released parts of the off-chain SGNv2 code on GitHub. The protocol’s team was then privately notified about the vulnerability, which has been fixed without any malicious exploitation.

As the report points out, the vulnerability would give a malicious validator a “wide range of options,” including the ability to spoof arbitrary on-chain events such as bridge transfers, message emissions or staking and delegation on Celer’s main SGN contract.

Screenshot of the postmortem report showing validators’ ability to apply malicious updates on Celer’s network due to the bug. Source: Jump Crypto

However, Celer has defenses to avoid a complete theft of bridge funds. The report highlights three mechanisms: a delay triggered by the bridge contract on transfers over a certain value, a volume-control mechanism limiting the value of tokens that can be extracted within a short period and an emergency halt of contracts that would be triggered once malicious transfers cause an under-collateralization event.

See also  Millions in Cardano (ADA) Will Be Stolen by Artificial Intelligence by This Time Next Year: Charles Hoskinson

Despite the security guardrails, the protocol would not be fully protected. According to Jump’s report, the transaction limits only apply per chain and token, and “due to the large number of supported tokens and chains, it seems realistic that an attacker could exfiltrate tokens with a value of ~$30M before the contracts are halted,” it said.

The amount represents approximately 23% of Celer’s current total value locked of $129.28 million at the time of writing, according to DefiLlama.

“It is important to note that these built-in mechanisms only have the power to protect Celer’s own bridge contracts. dApps built on top of Celer’s inter-chain messaging would be fully exposed to these vulnerabilities by default,” the report continued.

Celer offers a $2 million bug bounty for vulnerabilities in its bridge. However, bounties do not cover off-chain bugs such as the one found in the SGNv2 network.

Jump said it has been in discussion with the protocol about adding the SGNv2 network to its bug bounty program. A potential payout for Jump’s report is under evaluation by Celer’s team.

Magazine: Here’s how Ethereum’s ZK-rollups can become interoperable

Source link

Celers Crypto doublevoting Finds Jump SGN vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

SIREN crypto soars 44% – But can bulls ignore THESE warning signs?

June 8, 2026

Crypto tax proposals weighed ahead of Tuesday House hearing

June 8, 2026

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026

Trump’s family crypto feud spills into customer accounts after wallet freeze

June 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

A Bit of Password Bother

July 17, 2023

Why Did Kraken Just Opt For a License in Netherlands?

February 9, 2024

This Is Why Russia Is Becoming a ‘Crypto Mining Hotspot’

June 24, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Galaxy Research Drops CLARITY Act Approval Odds From 75% to 60%

June 8, 2026

SIREN crypto soars 44% – But can bulls ignore THESE warning signs?

June 8, 2026

World Cup prediction markets hit $2B before kickoff as Spain and France go head to head

June 8, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,325.000.14%
  • ethereumEthereum(ETH)$1,694.230.53%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$605.35-0.05%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • rippleXRP(XRP)$1.181.71%
  • solanaSolana(SOL)$67.030.96%
  • tronTRON(TRX)$0.3270320.22%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.19%
  • HyperliquidHyperliquid(HYPE)$63.156.40%