{"id":10781,"date":"2021-09-23T12:45:09","date_gmt":"2021-09-23T11:45:09","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=10781"},"modified":"2021-09-23T12:45:17","modified_gmt":"2021-09-23T11:45:17","slug":"sushiswap-refutes-reports-of-a-1-billion-glitch","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/sushiswap-refutes-reports-of-a-1-billion-glitch\/","title":{"rendered":"SushiSwap refutes reports of a $1 billion glitch"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">One of the exchange's developers has dismissed claims made by a self-described white-hat hacker regarding a major security risk to <a href=\"https:\/\/coinscreed.com\/staging\/sushiswap-co-founder-0xmaki-steps-down.html\" data-type=\"post\" data-id=\"10209\">SushiSwap <\/a>liquidity providers.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"933\" height=\"521\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-236.png\" alt=\"SushiSwap refutes reports of a $1 billion glitch\" class=\"wp-image-10788\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-236.png 933w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-236-300x168.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-236-768x429.png 768w\" sizes=\"(max-width: 933px) 100vw, 933px\" \/><\/figure>\n\n\n\n<p>A alleged vulnerability revealed by a white-hat hacker probing through <a href=\"https:\/\/www.google.com\/search?q=SushiSwap+refutes+reports+of+a+%241+billion+glitch&oq=SushiSwap+refutes+reports+of+a+%241+billion+glitch&aqs=chrome..69i57.1125j0j7&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=SushiSwap+refutes+reports+of+a+%241+billion+glitch&oq=SushiSwap+refutes+reports+of+a+%241+billion+glitch&aqs=chrome..69i57.1125j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">SushiSwap's smart contracts<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> has been dismissed by the developer behind the popular decentralized exchange.<\/p>\n\n\n\n<p>According to <a href=\"https:\/\/coinscreed.com\/staging\/crypto-and-defi-cause-disintermediation-in-the-banking-system-occ-head.html\" data-type=\"post\" data-id=\"10051\">media <\/a>reports, the hacker claimed to have discovered a vulnerability that could jeopardize more than $1 billion in user funds, and that they went public with the information after unsuccessful attempts to contact SushiSwap's developers.<\/p>\n\n\n\n<p>The hacker claims to have discovered a &#8220;vulnerability within the emergencyWithdraw function in two of SushiSwap's contracts, MasterChefV2 and MiniChefV2&#8221; \u2014 contracts that govern the exchange's 2x reward farms and pools on non-Ethereum SushiSwap deployments like <a href=\"https:\/\/coinscreed.com\/staging\/polygon-sets-to-scale-eys-blockchain-products.html\" data-type=\"post\" data-id=\"9857\">Polygon<\/a>, <a href=\"https:\/\/coinscreed.com\/staging\/binance-halts-crypto-derivatives-services-in-australia.html\" data-type=\"post\" data-id=\"10420\">Binance <\/a>Smart Chain, and <a href=\"https:\/\/coinscreed.com\/staging\/polychain-and-three-arrows-capital-leads-a-230m-fund-for-avalanche-foundation.html\" data-type=\"post\" data-id=\"10065\">Avalanche<\/a>.<\/p>\n\n\n\n<p>While the emergencyWithdraw function allows liquidity providers to claim their LP tokens immediately while forfeiting rewards in the event of an emergency. <\/p>\n\n\n\n<p>The hacker claims that if no rewards are held within the SushiSwap pool, the feature will fail, forcing liquidity providers to wait for the pool to be manually refilled over a 10-hour process before they can withdraw their tokens.<\/p>\n\n\n\n<p>Gupta&nbsp;clarified&nbsp;that \u201canyone\u201d can top up the pool\u2019s rewarder in the event of an emergency, bypassing much of the 10-hour multi-sig process the hacker claimed is needed to replenish the rewards pool. They added:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cSushiSwap\u2019s non-Ethereum deployments and 2x rewards (all using the vulnerable MiniChefV2 and MasterChefV2 contracts) hold over $1 billion in total value. This means that this value is essentially untouchable for 10-hours several times a month.\u201d&nbsp;<\/p><\/blockquote>\n\n\n\n<p>In response to the assertions, <a href=\"https:\/\/coinscreed.com\/staging\/miso-sushiswaps-token-launchpad-hacked-for-3-million.html\" data-type=\"post\" data-id=\"10117\">SushiSwap's <\/a>pseudonymous creator, &#8220;Shadowy Super Coder Mudit Gupta,&#8221; took to Twitter to clarify that the threat mentioned is &#8220;not a vulnerability&#8221; and that there are &#8220;no funds at risk.&#8221;<\/p>\n\n\n\n<p>Gupta clarified that, in the event of an emergency, &#8220;anyone&#8221; can top up the pool's rewarder, avoiding most of the 10-hour multi-sig process that the hacker claimed was required to replenish the rewards pool. They went on to say:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cThe hacker's claim that someone can put in a lot of lp to drain the rewarder faster is incorrect. Reward per LP goes down if you add more LP.\u201d<\/p><\/blockquote>\n\n\n\n<p>After initially contacting SushiSwap, the hacker claimed that they were instructed to report the vulnerability to bug bounty platform Immunefi \u2014 where SushiSwap is offering rewards of up to $40,000 to users who report potentially dangerous vulnerabilities in their code \u2014 after they first contacted the exchange \u2014 and that they did so.<\/p>\n\n\n\n<p>In their report, they observed that the issue had been resolved on Immunefi without compensation, and <a href=\"https:\/\/coinscreed.com\/staging\/sushiswap-co-founder-0xmaki-steps-down.html\" data-type=\"post\" data-id=\"10209\">SushiSwap <\/a>confirmed that they were aware of the situation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the exchange&#8217;s developers has dismissed claims made by a self-described white-hat hacker regarding a major security risk to SushiSwap liquidity providers. A alleged vulnerability revealed by a white-hat hacker probing through SushiSwap&#8217;s smart contracts has been dismissed by the developer behind the popular decentralized exchange. According to media reports, the hacker claimed to [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":10788,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[2309,853],"class_list":["post-10781","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-avalanche","tag-sushiswap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/09\/image-236.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/10781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=10781"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/10781\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/10788"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=10781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=10781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=10781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}