Follow Us

Multisig Vulnerability in Tron Spotted by 0d Researchers

Share on facebook
Share on twitter
Share on linkedin

Share

Multisig Vulnerability in Tron Spotted by 0d Researchers
Share on facebook
Share on twitter
Share on linkedin

Research by the 0d team at dWallet labs revealed that a critical zero-day vulnerability in the TRON blockchain left multisig accounts open to the risk of theft.

TRON’S Vulnerability 

As the name suggests, multisig accounts are such accounts that must be signed by multiple signatures in order to carry out a transaction. The vulnerability found by the research team was that any signer associated with any multisig account could have easily accessed the funds in that account. 

According to the 0d researchers overseeing TRON’s approach to multisig accounts meant a fault in its verification system for verifying all necessary information. This fault could easily be surpassed by any line of attack and get access to multisig accounts.

One of the team members Omer Sadika stated that the multisig account could’ve been easily accessed by a single signer putting multiple valid signatures for the same message. 

Researchers, however, revealed that the solution to this problem was quite simple. Signatures have to be checked from onwards against the list of addresses as well, not just against the list of signatures.

The research team also revealed that they reported the issue in a program called TRON’s bug bounty program on February 19. The research team further added that after reporting TRON patched the loophole in a few days and they said that most of the TRON validators have been patched. 

In a separate statement made on Twitter by the research team, it stated that no assets were at risk as the problem was fixed. 

What is TRON and How Does it Work? 

TRON is a decentralized platform based on Blockchain and has its own cryptocurrency called Tronix. The platform was built by a non-profit organization known as the Tron Foundation in Singapore in 2017. The platform’s main purpose is to host a digital entertainment system for the cost-effective sharing of digital content.  

Initially limited to Asia, TRON has expanded beyond. As of 2021, it has 50 Million users on its platform.

The company was founded by BitTorrent’s(famous file-sharing platform) CEO  Justin Sun. Justin Sun was born in 1990. Currently, TRON has offices in Singapore and San Francisco. 

The Tron network has been compared to Ethereum a lot of times for its similar use cases, such as building smart contracts, decentralized apps, and tokens.

Leave a Reply

Your email address will not be published. Required fields are marked *

Download our App for getting faster updates at your fingertips.

en_badge_web_generic.b07819ff-300x116-1

We Recommend

Top Rated Cryptocurrency Exchange

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00