Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Hacken boosts Binance proof of reserves security

Altszn.com by Altszn.com
February 18, 2023
in Blockchain
0
Hacken boosts Binance proof of reserves security
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



On Feb 14, 2023, Hacken researchers ran tests and identified a bug in the Binance zkSNARK-based Proof of Reserves system.

Hacken published a complete report on the assessment, announced it on their Twitter, and immediately apprized the Binance team to resolve the issue.

Binance proof of reserves verification upgrade

Binance announced an upgrade on its proof-of-reserves verification to include zk-SNARKs. The upgrade was expected to boost the verification system’s transparency and security on Feb 10, 2023. 

The zkSNARK-based Proof of Reserves system upgrade also included the addition of zero-knowledge proof protocols to Binance’s existing Merkle tree cryptography. The new features addressed the possibility of fake accounts and negative balances and preserved user safety and privacy during transactions. 

Previously, Binance relied on plain Merkle tree cryptography for system safety and transparency.

Various blockchains adopted the Merkle-tree-based proof-of-reserves system to increase industry transparency after the fall of FTX. Binance also made the project open source to benefit the whole crypto industry and assure users feel SAFU.

Bug identification

The Hacken team went through all the 1157 dependencies on the project and found 42 vulnerabilities, with 16 exposed to public exploitation. 20 dependencies had a severe vulnerability, while 20 had medium severity.

Of the severe vulnerabilities, the team identified two significant shortcomings on the Merkle sum tree; negative balance and privacy.

The Binance developers immediately responded to the observation by generating zk-SNARK proofs. The proofs contained batches of 864 users, and each interlinked through a Poseidon hash.

The Hacken researchers also discovered that Binance’s Proof of Reserves had loopholes that could allow the generation of fake user debt undetectable by a third party and the possibility of creating fake debt.

The team of three security researchers and blockchain developers led by Luciano Ciattaglia checked the source code and discovered a bug in the system that allowed it to bypass totalUserDebt, totalUserEquity (api.AssertIsLessOrEqual) assertion. 

The team created a counterfeit-proof by setting BasePrice at a very high value because the parameter was missing a CheckValueInRange validation, i.e., hackers can create fake proof without system detection. Contrariwise, the BasePrice is a public entity, and it’s easy to detect when it is compromised.

The BasePrice overflow bug means one could change the BasePrice without detection, which could lower exchange-proved liabilities. 

Binance response

Hackens contacted Binance after discovering the bugs adhering to their dedication to ensuring transparency in exchanges. Binance developers responded immediately by fixing the bugs and announce on their official Twitter handle. 

Hacken’s developers suggested that Binance add CheckValueInRange for BasePrice to prevent the overflow, which the Binance team reviewed and merged Hacken’s commit into Binance’s main branch. Binance fixed all the identified critical and medium severity loopholes.

However, Binance cannot verify any proof generated before the tests as valid, as the critical bugs allowed tampering with the total debt amount. Users cannot confirm that any proof before the test is not compromised due to the vulnerability.

The blockchain also acknowledged Hacken’s work as an outstanding example of community feedback power. Binance also provides a platform where users can report or give feedback on any of Binance’s products. 


Follow Us on Google News





Read More: crypto.news

Tags: BinanceBlockchainboostsHackenProofReservesSecurity
ADVERTISEMENT

Recent

Cointelegraph Bitcoin & Ethereum Blockchain News

Cointelegraph Bitcoin & Ethereum Blockchain News

May 19, 2025
Bitcoin impulse move toward new highs sets a fire under HYPE, ETH, XMR and AAVE

Bitcoin impulse move toward new highs sets a fire under HYPE, ETH, XMR and AAVE

May 18, 2025
There can never be too many L2s

There can never be too many L2s

May 18, 2025

Categories

  • Bitcoin (4,767)
  • Blockchain (11,255)
  • Crypto (9,192)
  • Dark Web (529)
  • DeFi (8,317)
  • Ethereum (4,821)
  • Metaverse (7,367)
  • Monero (283)
  • NFT (1,393)
  • Solana (5,009)
  • Web3 (20,497)
  • Zcash (494)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Cointelegraph Bitcoin & Ethereum Blockchain News

    Cointelegraph Bitcoin & Ethereum Blockchain News

    May 19, 2025
    Bitcoin impulse move toward new highs sets a fire under HYPE, ETH, XMR and AAVE

    Bitcoin impulse move toward new highs sets a fire under HYPE, ETH, XMR and AAVE

    May 18, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 103,012.00
    • ethereumEthereum (ETH) $ 2,415.81
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.32
    • bnbBNB (BNB) $ 640.27
    • solanaSolana (SOL) $ 162.09
    • usd-coinUSDC (USDC) $ 0.999870
    • dogecoinDogecoin (DOGE) $ 0.217239
    • cardanoCardano (ADA) $ 0.727600
    • tronTRON (TRX) $ 0.263737
    • staked-etherLido Staked Ether (STETH) $ 2,412.23
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,828.00
    • suiSui (SUI) $ 3.67
    • wrapped-stethWrapped stETH (WSTETH) $ 2,889.86
    • chainlinkChainlink (LINK) $ 15.21
    • avalanche-2Avalanche (AVAX) $ 21.69
    • stellarStellar (XLM) $ 0.281265
    • hyperliquidHyperliquid (HYPE) $ 25.45
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.64
    • hedera-hashgraphHedera (HBAR) $ 0.187475
    • bitcoin-cashBitcoin Cash (BCH) $ 384.05
    • the-open-networkToncoin (TON) $ 2.99
    • litecoinLitecoin (LTC) $ 95.79
    • usdsUSDS (USDS) $ 0.999868
    • polkadotPolkadot (DOT) $ 4.52
    • wethWETH (WETH) $ 2,414.83
    • moneroMonero (XMR) $ 345.26
    • bitget-tokenBitget Token (BGB) $ 5.15
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998893
    • wrapped-eethWrapped eETH (WEETH) $ 2,576.08
    • pepePepe (PEPE) $ 0.000013
    • pi-networkPi Network (PI) $ 0.715428
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,959.00
    • whitebitWhiteBIT Coin (WBT) $ 30.15
    • daiDai (DAI) $ 0.999503
    • uniswapUniswap (UNI) $ 5.75
    • bittensorBittensor (TAO) $ 391.51
    • aaveAave (AAVE) $ 220.07
    • nearNEAR Protocol (NEAR) $ 2.69
    • aptosAptos (APT) $ 4.99
    • okbOKB (OKB) $ 51.89
    • jito-staked-solJito Staked SOL (JITOSOL) $ 195.63
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • ondo-financeOndo (ONDO) $ 0.897187
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.17
    • crypto-com-chainCronos (CRO) $ 0.094211
    • kaspaKaspa (KAS) $ 0.104767
    • ethereum-classicEthereum Classic (ETC) $ 17.78
    • bitcoinBitcoin (BTC) $ 103,012.00
    • ethereumEthereum (ETH) $ 2,415.81
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.32
    • bnbBNB (BNB) $ 640.27
    • solanaSolana (SOL) $ 162.09
    • usd-coinUSDC (USDC) $ 0.999870
    • dogecoinDogecoin (DOGE) $ 0.217239
    • cardanoCardano (ADA) $ 0.727600
    • tronTRON (TRX) $ 0.263737
    • staked-etherLido Staked Ether (STETH) $ 2,412.23
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,828.00
    • suiSui (SUI) $ 3.67
    • wrapped-stethWrapped stETH (WSTETH) $ 2,889.86
    • chainlinkChainlink (LINK) $ 15.21
    • avalanche-2Avalanche (AVAX) $ 21.69
    • stellarStellar (XLM) $ 0.281265
    • hyperliquidHyperliquid (HYPE) $ 25.45
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.64
    • hedera-hashgraphHedera (HBAR) $ 0.187475
    • bitcoin-cashBitcoin Cash (BCH) $ 384.05
    • the-open-networkToncoin (TON) $ 2.99
    • litecoinLitecoin (LTC) $ 95.79
    • usdsUSDS (USDS) $ 0.999868
    • polkadotPolkadot (DOT) $ 4.52
    • wethWETH (WETH) $ 2,414.83
    • moneroMonero (XMR) $ 345.26
    • bitget-tokenBitget Token (BGB) $ 5.15
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998893
    • wrapped-eethWrapped eETH (WEETH) $ 2,576.08
    • pepePepe (PEPE) $ 0.000013
    • pi-networkPi Network (PI) $ 0.715428
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,959.00
    • whitebitWhiteBIT Coin (WBT) $ 30.15
    • daiDai (DAI) $ 0.999503
    • uniswapUniswap (UNI) $ 5.75
    • bittensorBittensor (TAO) $ 391.51
    • aaveAave (AAVE) $ 220.07
    • nearNEAR Protocol (NEAR) $ 2.69
    • aptosAptos (APT) $ 4.99
    • okbOKB (OKB) $ 51.89
    • jito-staked-solJito Staked SOL (JITOSOL) $ 195.63
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • ondo-financeOndo (ONDO) $ 0.897187
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.17
    • crypto-com-chainCronos (CRO) $ 0.094211
    • kaspaKaspa (KAS) $ 0.104767
    • ethereum-classicEthereum Classic (ETC) $ 17.78