[ad_1]
Darius Baruo
Mar 24, 2025 09:28
Conflux (CFX) Network has completed a significant security upgrade to address a vulnerability in its EVM, enhancing the safety of user assets and reinforcing ecosystem security.
The Conflux (CFX) Network has successfully executed a critical security upgrade, version 2.5, on March 17, 2025, following the discovery of a vulnerability in its Ethereum Virtual Machine (EVM). This vulnerability was initially identified by the GraFun team, according to Conflux Forum.
The vulnerability, reported on February 13, 2025, involved the CREATE2 opcode, which permitted the redeployment of contracts at existing addresses, potentially resetting their state. This flaw deviated from the standard Ethereum EVM behavior, where such redeployment is prohibited.
A comprehensive security impact assessment revealed that most factory contracts, like Swappi factories, were unaffected due to additional address conflict checks. However, Gnosis Safe contracts lacked these checks, posing a risk of state reset and enabling replay attacks on previously signed transactions.
The security assessment involved examining approximately 30 Gnosis Safe contracts, revealing that while most funds were secure, a minority might be at risk.
Conflux acted swiftly to mitigate the threat by notifying ecosystem partners and facilitating the transfer of at-risk assets. The security upgrade process involved several phases:
The vulnerability stemmed from the Conflux EVM’s original code ported from OpenEthereum, which contained misleading comments and lacked clear error definitions. These factors led to a misunderstanding of Ethereum’s CREATE2 behavior, resulting in the omission of critical checks in Conflux’s implementation.
Recognizing the severity of the vulnerability, Conflux awarded the GraFun team a total bounty of 60,000 CFX, acknowledging their timely report and the prevention of potential losses.
Looking ahead, Conflux plans to synchronize with Ethereum EVM features and integrate official test cases to prevent similar vulnerabilities. This move aims to enhance Conflux’s security and compatibility with Ethereum’s ecosystem.
The Conflux team remains dedicated to transparency and rapid response, ensuring the security of its ecosystem and the protection of user interests.
Image source: Shutterstock
[ad_2]
Source link
[ad_1] भारतीय शेयर बाजारों में शुक्रवार (11 अप्रैल) को जबरदस्त तेजी देखने को मिली। सेंसेक्स…
[ad_1] Joerg Hiller Dec 13, 2025 13:56 BTC price prediction suggests…
[ad_1] Mutual Fund March 2025 Data: शेयर बाजार में जारी उतार-चढ़ाव और ट्रंप टैरिफ (Trump…
[ad_1] Lawrence Jengar Dec 10, 2025 12:37 Glassnode releases The Bitcoin…
[ad_1] जेफरीज के अनुसार 2026 में देखने योग्य शीर्ष उपभोक्ता वित्त स्टॉक्स [ad_2] Source link
[ad_1] Felix Pinkston Dec 10, 2025 12:39 ARB price prediction shows…
This website uses cookies.