BlockSec: Taiko is suspected to have lost over $1.7 million due to GitHub's SGX proof key being attacked

source··13:59 编辑

Comparing news, according to BlockSec monitoring, the Taiko network was attacked and lost more than $1.7 million. Preliminary investigations suggest that the likely root cause is the Raiko SGX enclave signature key revealed on GitHub. Raiko is Taiko's multi-prover stack for Taiko and the Ethereum block, so the exposed Raiko SGX enclave key could directly affect Taiko's on-chain proof verification path.

Since enclave signing keys are publicly accessible, the SGX attestor trust model may have been broken. The exposed keys could allow attackers to register SGX instances controlled by the attackers. Once registered, these instances can sign the public certification input accepted by the Taiko Proof Validator, thereby allowing fraudulent status/signal proofs to pass. The attackers then use a fake source signal to register the fake bridge message as RETRIABLE and then call retryMessage to cause ERC20Vault to release the canonical L1 assets.

Original Link
#链上动态
说明: All Bitpush articles reflect the author's views only and do not constitute investment advice.

Related

Loading...