Analysts warn that the Blast contract is controlled by anonymous addresses. Users have invested over $300 million in the project
Polygon Labs and SlowMist experts claim that Blast is not a layer 2 network
24.11.2023 - 13:08
265
2 min
0
What’s new? Experts from blockchain developer Polygon and audit firm SlowMist have reported a vulnerability in the Blast project, which was launched by the Blur NFT marketplace team on November 21. According to the analysts, the project is based on a multi-signature contract with instant update capability that requires 3 out of 5 signatures to make changes. In turn, all five signature addresses are anonymous and recently created.
What else is known? In the event of an exploit or bad faith by the owners of the signature-enabled addresses, the Blast contract can instantly inject malicious code updates to steal funds.
The experts added that Blast, unlike other projects with similar features such as Arbitrum, is not a layer 2 (L2) network and is simply a smart contract that accepts deposits and invests them in revenue-generating protocols such as Lido, liquid ETH staking protocol.
Jarrod Watts of Polygon Labs emphasized that Blast has no testnet, bridges, or rollups, and does not even send transaction data to Ethereum.
“By sending money to the Blast contract, you’re basically trusting 3-5 strangers to stake your funds for you. You won’t be able to withdraw that money at any point in time unless those 3-5 people decide to do the right thing in the future,” the developer explained.
Notably, Blast currently lacks a withdrawal feature. According to the roadmap, it will be activated only on February 24 next year. At the same time, users have already blocked over $303 million in the project’s contract.
In turn, SlowMist founder Yu Xiang said that Blast is a centralized Web 2.0 project, which has received support from financial institutions. Thus, one of the investors of the project is the venture capital firm Paradigm, which previously supported the Blur marketplace.
Xiang expressed indignation that users do not study the technical features of the project, judging its reliability only by the presence of institutional partners.
Useful material?
Market
The company’s unrealized profits from investing in its first cryptocurrency approached $14 billion
Nov 19, 2024
Incidents
The search, the reason for which was not announced, took place a week after the election, the results of which Polymarket users predicted quite accurately
Nov 14, 2024
Market
Analysts point to the growing popularity of the first cryptocurrency as a safe haven asset
Nov 13, 2024
Market
The product will begin trading on the Swiss Exchange on November 19
Nov 12, 2024
Market
The company’s unrealized profits from investing in the first cryptocurrency approached $13 billion
Nov 12, 2024
Market
The company predicts that the rate of the first cryptocurrency will grow to $200 000 by the end of next year
Nov 11, 2024