Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
LayerZero CEO responds to vulnerability rumors: Inference is baseless, protocol is secure

LayerZero CEO responds to vulnerability rumors: Inference is baseless, protocol is secure

Bitget2024/07/01 03:37

BlockBeats news, on July 1st, Bryan Pellegrino, co-founder and CEO of LayerZero Labs, responded to the rumors about "serious vulnerabilities in LayerZero" on social media. He stated that "this is completely unfounded. First of all, all the code you mentioned was pushed out in 2022. Secondly, these are application configurations rather than protocol configurations.

The payload size limit is part of the security configuration for applications and it sets up DVNs. Even in the latest version, an application can override this limit. In other words, if an application cannot override this setting then LayerZero could block message delivery by setting 'payload limit' to zero which would violate the entire design principle of the protocol.

As initially responded to your query: just fork and test it as I'm sure you've already confirmed at that time - it's not executable; if it were executable then that would be because a particular app chose to set it like so - similar to how some apps choose incorrect contract settings on Ethereum.

This isn't a vulnerability but part of protocol design instead. Any messaging protocols now engraving such configuration into their protocols can review any applications – they're inseparable from each other. We believe in censorship-resistant technology tracks."

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!