BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
FOLLOW
BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
BlockNews

Crypto Wallet, ZenGo, Announces Its Discovery Of Security Vulnerabilities In Popular DApps

by BlockNews Team
March 23, 2023
in Business, Crypto, Media, Technology
A A
Crypto Wallet, ZenGo, Announces Its Discovery Of Security Vulnerabilities In Popular DApps
1
SHARES
Share on TwitterShare on Reddit
  • ZenGo reveals security risks in many Web3 vendors.
  • The crypto wallet is awarded bug bounties and grants.
  • Called a “red pill attack,” it can steal user assets.

ZenGo crypto wallet developers have discovered security vulnerabilities in DApps (Decentralised Applications) around the Web3 space.

On March 20, ZenGo, a crypto wallet, published a blog post explaining how it came across security risks in transaction simulation solutions used by most DApps. It is named “Red Pill Attack” from the red pill in the famous movie franchise Matrix.’

The malicious intent of these security vulnerabilities is to steal user assets through preliminary transaction approvals offered and authorized by users. ZenGo stated that it could only come across these vulnerabilities due to its research on blockchain security.

According to the blog post, multiple vendors offering transaction simulation solutions were found to have been victims of these security attacks. They had since rectified them when it was brought to their notice by ZenGo. Some of these vendors did not let ZenGo’s good deed go unrewarded, as the crypto wallet received multiple bug bounties and an Ethereum Foundation $50,000 grant.

Additionally, ZenGo mentioned that if malware can detect being executed in a simulated environment or within the Matrix, it can act benignly and deceive the anti-malware solution. Still, it can only reveal its initial intent when executed in a natural environment.

How Does This Work?

ZenGo stated that these security vulnerabilities lie in smart contracts, and by using an example, the developers explained how they are operated. This error can be blamed on programming oversight in “special variables” among smart contracts collecting information on the blockchain functionality or data on the user-controlled parameters of the transaction.

“Since these variables can take a range of values, they have no accurate value. Hence, it was tempting for simulation creators to take a shortcut and set them to a constant value.”

Using “COINBASE” as an example to bolster the explanation, ZenGo said that the “COINBASE” instructions could include the address of the present block miner. Since there is no fundamental block during simulation, there is also no miner, allowing some simulation implementations to set it to a null address (zeros address).

“If COINBASE is zero, the contract will return some coins, making the transaction profitable for the user as its wallet simulated it. However, when the user moves the transaction on-chain, COINBASE is filled with the non-zero address of the existing miner, and the malicious contract steals the transferred coins,” the developers explained.

After demonstrating how the red pill attack is executed on a YouTube video, ZenGo suggested a solution to rectify it. Rather than populating these vulnerable variables with unsteady values, the simulation should populate them with significant values.

Conclusion

Decentralized Applications (DApps) are the foundation of user interaction in the Web3 universe. Hence, blockchain security is highly recommended. ZenGo’s discovery has alerted Web3 vendors about a programming oversight that could prove harmful.

Tags: BusinesscryptoCrypto WalletdAppsZenGo
TweetShareShare

DON'T MISS THESE! HOT OFF THE PRESS

$TAO Is Back With a Vengeance: Bittensor is About to Explode and Here is Why
Crypto

$TAO Is Back With a Vengeance: Bittensor is About to Explode and Here is Why

May 9, 2025
Crypto

Everything You Need to Know About $DOOD: A New Era for Doodles and Its Ecosystem

May 9, 2025
Ethereum ETH Hits Biggest Single Day Gain Since May 2024: Here is Why $3K is Next
Crypto

Ethereum ETH Hits Biggest Single Day Gain Since May 2024: Here is Why $3K is Next

May 8, 2025
Analysts Predict MOG Coin Could 4x as mog/acc Trend Gains Momentum With Elon Musk Endorsement
Crypto

Analysts Predict MOG Coin Could 4x as mog/acc Trend Gains Momentum With Elon Musk Endorsement

May 8, 2025
Stellar XLM Technical Indicators Suggest Imminent Breakout: Here is What You Need to Do
Crypto

Stellar XLM Technical Indicators Suggest Imminent Breakout: Here is What You Need to Do

May 8, 2025
$LTC in a Limbo: Is Litecoin Quietly Gearing Up for a Breakout?
Crypto

$LTC in a Limbo: Is Litecoin Quietly Gearing Up for a Breakout?

May 8, 2025
Load More

Related News

Hedera on the Move: Why Analysts Are Eyeing a Major $HBAR Comeback?

Hedera on the Move: Why Analysts Are Eyeing a Major $HBAR Comeback?

May 9, 2025
$TAO Is Back With a Vengeance: Bittensor is About to Explode and Here is Why

$TAO Is Back With a Vengeance: Bittensor is About to Explode and Here is Why

May 9, 2025

Everything You Need to Know About $DOOD: A New Era for Doodles and Its Ecosystem

May 9, 2025
Ethereum ETH Hits Biggest Single Day Gain Since May 2024: Here is Why $3K is Next

Ethereum ETH Hits Biggest Single Day Gain Since May 2024: Here is Why $3K is Next

May 8, 2025
Analysts Predict MOG Coin Could 4x as mog/acc Trend Gains Momentum With Elon Musk Endorsement

Analysts Predict MOG Coin Could 4x as mog/acc Trend Gains Momentum With Elon Musk Endorsement

May 8, 2025
Discord Twitter Youtube TikTok Instagram

BLOCKNEWS.COM

BlockNews

BlockNews.com is your premier source for real-time cryptocurrency, blockchain, and financial market news.

Our mission is to deliver accurate, timely, and insightful information to help both seasoned investors and newcomers navigate the evolving digital economy.

With in-depth analysis, exclusive insights, and up-to-date news, BlockNews.com keeps you informed on the latest trends in crypto, DeFi, NFTs, tech, and beyond.

Stay ahead of the herd with BlockNews.com

RESOURCES

  • About
  • Newsletter
  • Advertise
  • Terms and Conditions
  • Privacy Policy

POPULAR TOPICS

$ADA $XRP AI Avalanche Binance Bitcoin Bitcoin ETF blackrock Blockchain BTC Business Cardano China Coinbase crypto cryptocurrency Crypto Exchange Crypto Regulation DeFi Dogecoin Donald Trump Elon Musk ETF eth ethereum Federal Reserve FTX Gary Gensler grayscale Memecoin metaverse Microstrategy NFT NFTs PEPE ripple sec Shiba Inu Solana Stablecoin Technology twitter US Web3 xrp

GET QUICKER UPDATES ON X

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.

No Result
View All Result
  • Home
  • Crypto
  • Memecoins
  • Technology
  • Politics
  • Finance
  • NFT
  • DeFi
  • Opinion

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.