{"id":35589,"date":"2022-09-08T16:51:15","date_gmt":"2022-09-08T20:51:15","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=35589"},"modified":"2024-04-10T23:17:06","modified_gmt":"2024-04-11T03:17:06","slug":"peter-szilagyi-ethereums-lead-developer-salvaged-avalanches-24b-ecosystem","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/peter-szilagyi-ethereums-lead-developer-salvaged-avalanches-24b-ecosystem\/","title":{"rendered":"P\u00e9ter Szil\u00e1gyi Ethereum&#8217;s lead developer salvaged Avalanche&#8217;s $24B ecosystem"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\" id=\"h-peter-szilagyi-discovered-a-flaw-in-avalanche-s-peerlist-package-on-march-29-2022\">P\u00e9ter Szil\u00e1gyi discovered a flaw in Avalanche's PeerList package on March 29, 2022<\/h3>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/img.currency.com\/imgs\/articles\/834xx\/shutterstock_1947690298.jpg\" alt=\"Avalanche\" \/><figcaption>Peter Szilagyi Ethereum's lead developer salvaged Avalanche's $24B ecosystem<\/figcaption><\/figure>\n\n\n\n<p>P\u00e9ter Szil\u00e1gyi, an <a href=\"https:\/\/coinscreed.com\/staging\/ethereum-merge-final-countdown-has-officially-started.html\">Ethereum <\/a>developer, has published a vulnerability report explaining how a fault he discovered in Avalanche would have brought down the entire network.<\/p>\n\n\n\n<p>P\u00e9ter Szil\u00e1gyi discovered a vulnerability in Avalanche's PeerList package on March 29, 2022, which a bad actor might have easily exploited. The Avalanche developer team swiftly patched the issue once he contacted them.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Publishing my <a href=\"https:\/\/twitter.com\/hashtag\/Avalanche?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#Avalanche<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> vulnerability report from 29th March, 2022 that could have been used to take the entire network down at no cost.<br><br>The issue was fixed way back, and with the latest Avalanche hard fork, all nodes run the patched software.<br><br>Njoy \ud83d\ude42<a href=\"https:\/\/t.co\/nokedKF7IZ\" target=\"_blank\">https:\/\/t.co\/nokedKF7IZ<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; P\u00e9ter Szil\u00e1gyi (@peter_szilagyi) <a href=\"https:\/\/twitter.com\/peter_szilagyi\/status\/1567835617932808193?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 8, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">PeerList's flaw<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/coinmarketcap.com\/currencies\/avalanche\/\" target=\"_blank\" rel=\"noopener\">Avalanche <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>network interacts using a PeerList package that can only be transmitted by validating nodes. <\/p>\n\n\n\n<p>explained that an attacker may exploit the vulnerability by staking the 2,000 AVAX tokens required to be a validator node and sending a malicious PeerList package to network nodes.<\/p>\n\n\n\n<p>Szil\u00e1gyi clarified;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><strong>Since all nodes in the network connect to all validators, it\u2019s pretty much an insta-death for the entire network.<\/strong><\/p><\/blockquote>\n\n\n\n<p>He also added;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><strong>The price is of course 2000AVAX, but I kind of find that acceptable since a nice short would net a sweet profit and the network would rebound anyway after a few hours so no long term value lost in the malicious validator.<\/strong><\/p><\/blockquote>\n\n\n\n<p>As of March 2022, it was estimated that the market capitalization of the Avalanche network exceeded $24 billion. <\/p>\n\n\n\n<p>If the vulnerability had been exploited by an adversary, the ecosystem would have collapsed catastrophically.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Avalanche's Bug War<\/h3>\n\n\n\n<p>During the February 2021 introduction of the DeFi protocol Pangolin on Avalanche, the network encountered a &#8220;cross-chain finality&#8221; flaw that pushed it into &#8220;self-healing mode.&#8221;<\/p>\n\n\n\n<p>Some validators on Avalanche accepted invalid mint transactions as a result of a high network load. As a result, the network was forced to suspend all transactions for hours. <\/p>\n\n\n\n<p>The developers applied a quick fix and processed all pending transactions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>P\u00e9ter Szil\u00e1gyi discovered a flaw in Avalanche&#8217;s PeerList package on March 29, 2022 P\u00e9ter Szil\u00e1gyi, an Ethereum developer, has published a vulnerability report explaining how a fault he discovered in Avalanche would have brought down the entire network. P\u00e9ter Szil\u00e1gyi discovered a vulnerability in Avalanche&#8217;s PeerList package on March 29, 2022, which a bad actor [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[132],"class_list":["post-35589","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/35589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=35589"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/35589\/revisions"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=35589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=35589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=35589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}