Ethereum L2 scaling project Optimism fixes bug that left it open to unlimited ETH token creation in its accounts; $2M+ bounty given to Jay Freeman of Cydia fame
Ethereum scaling startup Optimism disclosed a “critical bug” fix in the project's Geth fork that would have allowed malicious hackers to create infinite ETH Source: saurik.com .
Optimism has removed a path for an attacker to create unlimited ETH in affected accounts and paid Jay Freeman more than $2M for surfacing it.
The disclosure puts immediate scrutiny on Optimism’s Geth fork, while Geth’s dominant validator share makes client-code security a wider Ethereum concern.
Second-order effects
Jay Freeman’s payout raises the practical benchmark for finding severe flaws in Ethereum scaling infrastructure, giving security researchers a clear incentive to examine forks as well as base clients.
Optimism’s users and counterparties have a concrete reason to demand stronger review of changes inherited from Geth, rather than treating Layer 2 code as isolated from Ethereum client risk.
Third-order effects
If major Layer 2 systems continue to rely on modified core clients, security assurance becomes a shared infrastructure bottleneck: a fault in a common code lineage can threaten multiple layers of the ecosystem.
The episode adds to the crypto legitimacy challenge by making large, public bug bounties and transparent remediation part of how protocol operators establish trust.
The trend: Ethereum scaling is expanding through Layer 2 systems, but their security posture remains tightly coupled to the reliability and review of underlying client software.
Last week, I discovered (and reported) a critical bug (which has been fully patched) in @optimismPBC (a “layer 2 scaling solution” for Ethereum) that would have allowed an attacker to print arbitrary quantity of tokens, for which I won a $2,000,042 bounty. https://www.saurik.com/…
We're incredibly thankful to saurik for spending so much time analyzing our protocol over the year—enough to find such an important fix! We highly recommend you check out his in-depth breakdown. We'll award the full $2,000,042 promised in our bug bounty. https://saurik.com/... ht…
Just another totally forgettable, unimportant, tiny inflation bug on Ethereum that allowed this attacker “ACCESS TO INFINITE CAPITAL.” For 40 days undetected, his “unbounded supply of IOUs” allowed him to “PRINT AN ARBITRARY QUANTITY OF ANY ERC-20 TOKEN.” https://www.saurik.com/.…
All is well. Developers from the Ethereum Layer 2 scaling project Optimism announced that a “critical bug” had been identified and subsequently patched earlier this month. https://cointelegraph.com/...
snippet from @saurik's https://www.saurik.com/... (the whole article is a great read, kudos to how everyone involved handled this) lasting value can only be created “at pace” - neither too slow, nor too fast. design and time your feedback loops properly to effect real impact http…
If you hate all the people who steal in crypto you should love all the people that fix bugs like this. The open financial system allows people to fix or fork it. https://twitter.com/...
“if we do not believe that destruction is ethical, and we are going to assign such strong moral judgement to people who destroy rather than build, how can we avoid falling into the trap of building systems that only work due to trust?” https://www.saurik.com/...
@OrchidProtocol @saurik $oxt Amazing to read, even though i don't understand most of it.. We (Orchid followers) are so lucky to have Saurik and the the rest of team at the helm.. https://www.saurik.com/...
Reading the detailed write up it's clear how this was not a stroke of luck but actually a deep thinking job lasting over 1 year. Congrats @saurik https://twitter.com/...
A very interesting article about the technical backgrounds of recent blockchain hacks. Quite nice to read about geniuses like geohot, saurik and the inventor of bash 😮 https://www.saurik.com/...