Skip to main content

Sayfer Identifies New Frontrunning Vulnerability in the Connext Bridge

By: Get News

Israeli cybersecurity firm Sayfer has identified a new vulnerability in the Connext bridge that exposes relayer remuneration funds to frontrunning. It is believed that more than $70,000 worth of fees have been frontrunned to date.

The connext bridge requires a class of actors called ‘relayers’. Relayers are responsible for submitting users’ transactions on the receiving chain without requiring the user to spend gas out of their own pocket. For their work, relayers are allocated a certain fee. Sayfer has discovered that because the fee is sent to the msg.sender (i.e. the account or contract that sent the transaction), without authenticating the identity of the relayer, this fee can be snatched by frontrunners.

Frontrunning is performed by bots (also known as MEV bots) that scour Ethereum’s mempool for vulnerable impending transactions. They then copy the transaction, and place an identical order but with higher gas fees. That way, the copied transaction is executed before the original, and the bot pockets the profit. The proliferation of MEV bots is considered a major threat to the integrity and reliability of the Ethereum blockchain.

Sayfer has reported their research to Connext, but they claim that this is not a vulnerability, and refuse to correct it.

https://twitter.com/SayferSecurity/status/1572843128406646785

Media Contact
Company Name: Sayfer
Contact Person: Media Relations
Email: Send Email
Country: Israel
Website: https://sayfer.io/blog/connexts-bridge-possible-hack-more-than-70k-frontrunned/

Recent Quotes

View More
Symbol Price Change (%)
AMZN  198.79
-0.81 (-0.41%)
AAPL  255.78
-5.95 (-2.27%)
AMD  207.32
+1.38 (0.67%)
BAC  52.55
+0.03 (0.06%)
GOOG  306.02
-3.35 (-1.08%)
META  639.77
-10.04 (-1.55%)
MSFT  401.32
-0.52 (-0.13%)
NVDA  182.81
-4.13 (-2.21%)
ORCL  160.14
+3.66 (2.34%)
TSLA  417.44
+0.37 (0.09%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.