Earn up to 12% APY on Bitcoin, Ethereum, USD, EUR, GBP, Stablecoins & more.

Start Earning Interest
Your gateway to Bitcoin and beyond

Bug on TRON could have allowed a single computer to crash the network

Bug on TRON could have allowed a single computer to crash the network

A high severity bug on the TRON network could have allowed an attacker with a single computer to crash the network, as first reported by TNW. The fault stems from a vulnerability related to spamming smart contracts.

On Jan. 13th, software engineer Danish Shrestha reported a bug to TRON that would have allowed an attacker to conduct a distributed-denial-of-service attack on the TRON blockchain.

โ€œUsing a single machine an attacker could send DDOS attack to all or 51% of the SR [super representative] nodes and render Tron network unusable or make it unavailable.โ€

The bug stems from one type of computationally intensive operation, which takes 2-3 minutes for a modern MacBook Pro to process. A particular type of smart contract deployment on TRONโ€™s wallet required six of these operations. In combination, these deployments had the potential to bog down the TRON blockchain.

By spamming these smart contract deployments it was possible to overwhelm the TRON network, clogging up available CPU and memoryโ€”rendering the blockchain unusable.

The exploit is similar to other types of denial-of-service (DoS) attacks. Simple attacks like spamming transactions or smart contract requests make it possible to overwhelm the resources of a network and make it inaccessible.

Justin Sun reveals launch date for second-layer scaling, โ€œ100X scalabilityโ€ for TRON
Related:ย Justin Sun reveals launch date for second-layer scaling, โ€œ100X scalabilityโ€ for TRON

Networks like Bitcoin and Ethereum add a cost to transactions to prevent this simple kind of attack (although there are many other types), while XRP Ledger has a cost attached to creating new addresses for similar reasons. Networks are vulnerable if resources are too cheap or free.

Something to keep in mind is that these kind of bugs are not uncommon, especially for a system as complex as a blockchain protocol.

EOS is known for giving out large bug bounties to incentivize ethical hacking. Since blockchain protocols are oftentimes open-source, companies like TRON can leverage the community to discover vulnerabilities as people probe the code.

The TRON Foundation awarded Shrestha $1,500 for finding the bug and marked the issue resolved on Jan. 31st.

Get an edge on the cryptoasset market

Access more crypto insights and context in every article as a paid member of CryptoSlate Edge.

On-chain analysis
Price snapshots
More context
Join now for $19/month Explore all benefits
Posted In: , Hacks, Price Watch

Like what you see? Subscribe for updates.