Jump Crypto finds double-voting vulnerability in Celer’s SGN
The bug would have allowed malicious validators to compromise the network and applications that rely on it, including Celer’s cBridge. Web3 investor and developer Jump Crypto has identified a vulner ability in Celer’s State Guardian Network (SGN) that would allow malicious validators to compromise the network and applications dependent on it, including Celer’s cBridge. According to Jump Crypto’s postmortem report, validators were allowed to vote more than once on the same update due to a bug in the SGN EndBlocker code. By allowing validators to vote multiple times, malicious actors could multiply their voting power to approve harmful updates. The report explained: “The [EndBlocker] code is missing a check that prevents a validator from voting on the same update twice. A malicious validator could exploit this by voting multiple times on the same update, effectively multiplying their voting power and potentially tipping the vote in favor of an invalid or malicious update." Celer...