Analysis of the Ronin Bridge Vulnerability: Weight Anomaly Leads to Unnecessary Multi-Signature Withdrawals
Publication Time:2024-08-06 19:41:07
According to a report by Golden Finance, SlowMist disclosed the details of the attack on Ronin Bridge. The core issue lies in the accidental setting of the system's weight parameter to an abnormal value, leading to a serious vulnerability. Typically, any withdrawal of funds requires validation through a multi-signature process to ensure transaction security and prevent unauthorized access. However, in this incident, due to the setting of an unreasonable value for the weight, funds could bypass this crucial security check mechanism and be withdrawn directly, without the consent of multiple signatures. Prior to this, Ronin Bridge was targeted in an attack with a total fund amount of $9.33 million. Following the discovery of this vulnerability, Ronin Bridge immediately took emergency measures, paused its service, and initiated an investigation into potential miner extraction fee (MEV) vulnerabilities.
security vulnerability
Ronin Bridge
Weight Anomaly
Multi-Signature