{"id":61884,"date":"2022-05-23T16:44:01","date_gmt":"2022-05-23T13:44:01","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=61884"},"modified":"2025-09-05T14:47:57","modified_gmt":"2025-09-05T11:47:57","slug":"wormhole-team-pays-white-hat-hacker-10-million-for-discovered-vulnerability","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/wormhole-team-pays-white-hat-hacker-10-million-for-discovered-vulnerability\/","title":{"rendered":"Wormhole Team Pays White-Hat Hacker $10 Million for Discovered Vulnerability"},"content":{"rendered":"<p>The Wormhole project team paid $10 million to a white-hat hacker who identified a critical vulnerability in the cross-chain protocol. Immunefi, the platform hosting the corresponding bug bounty program, said so.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Whitehat satya0x reported a critical vulnerability in <a href=\"https:\/\/twitter.com\/wormholecrypto?ref_src=twsrc%5Etfw\">@wormholecrypto<\/a> on Feb 24 via Immunefi. <\/p>\n<p>The bug was quickly patched, no user funds were affected, and satya0x received a $10 million payout from Wormhole, the largest bounty payout on record. <a href=\"https:\/\/t.co\/xKDGxfFLjA\">https:\/\/t.co\/xKDGxfFLjA<\/a><\/p>\n<p>\u2014 Immunefi (@immunefi) <a href=\"https:\/\/twitter.com\/immunefi\/status\/1527693383581552641?ref_src=twsrc%5Etfw\">May 20, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>According to Immunefi&#8217;s press release, on February 24, 2022, a researcher going by the handle satya0x discovered a vulnerability in Wormhole&#8217;s core bridge smart contract on the Ethereum side of the blockchain. The exploit could potentially have led to user funds being frozen.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;The Wormhole team reacted incredibly quickly to the bug report, verifying and fixing the issue on the same day it was reported. User funds were not lost,&#8221; according to Immunefi&#8217;s statement.<\/p>\n<\/blockquote>\n<p>For the discovered bug, satya0x received the maximum bounty allowed under Wormhole&#8217;s bug bounty program \u2014 $10 million. In addition to the cross-chain protocol, such a reward <a href=\"https:\/\/u1f987.com\/en\/news\/makerdao-launches-bug-bounty-program-with-rewards-of-up-to-10-million\">is offered<\/a> only by the MakerDAO platform.\u00a0<\/p>\n<p>In February 2022, hackers <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-drain-more-than-319-million-from-wormhole-cross-chain-bridge-pool\">withdrew from the Wormhole pool more than $319 million<\/a> in digital assets.<\/p>\n<p>Read ForkLog&#8217;s Bitcoin news in our <a href=\"\/\/telegram.me\/forklog\" target=\"\u201c_blank\u201d\" rel=\"\u201cnofollow\u201d noopener\">Telegram<\/a> \u2014 cryptocurrency news, prices and analytics.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Wormhole project team paid $10 million to a white-hat hacker who discovered a critical vulnerability in the cross-chain protocol. Immunefi, the platform hosting the corresponding bug bounty program, said so.<\/p>\n","protected":false},"author":1,"featured_media":61885,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1301,1210,1195],"class_list":["post-61884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-blockchain-vulnerabilities","tag-cross-chain-protocols","tag-white-hat-hackers"],"aioseo_notices":[],"amp_enabled":true,"views":"73","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/61884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=61884"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/61884\/revisions"}],"predecessor-version":[{"id":61886,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/61884\/revisions\/61886"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/61885"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=61884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=61884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=61884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}