{"id":28319,"date":"2020-09-07T18:24:44","date_gmt":"2020-09-07T15:24:44","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=28319"},"modified":"2025-08-27T11:04:10","modified_gmt":"2025-08-27T08:04:10","slug":"developer-finds-another-vulnerability-in-sushiswap-protocol","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/developer-finds-another-vulnerability-in-sushiswap-protocol\/","title":{"rendered":"Developer finds another vulnerability in SushiSwap protocol"},"content":{"rendered":"<p>A vulnerability in the governance of the DeFi platform SushiSwap has been discovered that preserves the voting right for token holders even after transfer. Developer Chong Sok Park <a href=\"https:\/\/medium.com\/bulldax-finance\/sushiswap-delegation-double-spending-bug-5adcc7b3830f\" target=\"_blank\" rel=\"noopener noreferrer\">wrote<\/a> about the double-spending bug in his blog.<!--more--><\/p>\n<p>The governance mechanism of SushiSwap allows token holders to transfer voting power. Transferring assets from a wallet should reset the delegation parameters, but due to the bug the user retains the governance power.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-109469 aligncenter\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image2-179.png\" alt=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0430\u0448\u0435\u043b \u0435\u0449\u0435 \u043e\u0434\u043d\u0443 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 SushiSwap\" width=\"669\" height=\"570\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/image2-179.png 669w, https:\/\/u1f987.com\/wp-content\/uploads\/image2-179-300x256.png 300w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/p>\n<p>As explained by Park, the double-spending bug allows a user to extend voting power through delegation transactions. The developer sees a fix in adding the code &#8220;moveDelegates&#8221; to the SushiSwap smart contract when transferring tokens.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-109468 aligncenter\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image1-284.png\" alt=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u043d\u0430\u0448\u0435\u043b \u0435\u0449\u0435 \u043e\u0434\u043d\u0443 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 SushiSwap\" width=\"682\" height=\"384\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/image1-284.png 682w, https:\/\/u1f987.com\/wp-content\/uploads\/image1-284-300x169.png 300w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><\/p>\n<p>In a comment to Cointelegraph, the CEO of FTX, Sam Bankman-Fried <a href=\"https:\/\/cointelegraph.com\/news\/dev-finds-major-governance-bug-in-sushiswap-but-no-threat-to-the-project-yet\" target=\"_blank\" rel=\"noopener noreferrer\">confirmed<\/a> the existence of the vulnerability. According to him, it does not pose a real threat to SushiSwap \u2014 the governance mechanism has not yet been activated.<\/p>\n<p>Earlier, experts <a href=\"https:\/\/u1f987.com\/en\/news\/experts-identify-ten-vulnerabilities-in-sushiswap-protocol\">found<\/a> ten vulnerabilities in SushiSwap. One of them allows re-adding a liquidity provider token, while another could lead to transferring funds to any address.<\/p>\n<p>Earlier, the anonymous creator of SushiSwap &#8220;Chef Nomi&#8221; <a href=\"https:\/\/u1f987.com\/en\/news\/sushiswap-administrator-triggers-50-drop-in-token-price\">sold<\/a> half of the funds from the platform\u2019s development fund. This spurred the SUSHI price from $11 to $2.35.<\/p>\n<p>As of writing, the asset <a href=\"https:\/\/www.coingecko.com\/en\/coins\/sushi\/usd#panel\" target=\"_blank\" rel=\"noopener noreferrer\">is trading<\/a> at around $2.70.<\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\"https:\/\/t.me\/forkloglive\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog FEED<\/a> \u2014 the full feed of news, <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog<\/a> \u2014 the most important news and polls.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability in the governance of the DeFi platform SushiSwap has been discovered that preserves voting power for token holders even after transfer. Developer Chong Sok Park wrote about the double-spending bug in his blog.<\/p>\n","protected":false},"author":1,"featured_media":28320,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1301,1093,1379],"class_list":["post-28319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-blockchain-vulnerabilities","tag-defi","tag-sushiswap"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=28319"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28319\/revisions"}],"predecessor-version":[{"id":28321,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28319\/revisions\/28321"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/28320"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=28319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=28319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=28319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}