Analysts warn that the Blast contract is controlled by anonymous addresses. Users have invested over $300 million in the project
Polygon Labs and SlowMist experts claim that Blast is not a layer 2 network
24.11.2023 - 13:08
260
2 min
0
What’s new? Experts from blockchain developer Polygon and audit firm SlowMist have reported a vulnerability in the Blast project, which was launched by the Blur NFT marketplace team on November 21. According to the analysts, the project is based on a multi-signature contract with instant update capability that requires 3 out of 5 signatures to make changes. In turn, all five signature addresses are anonymous and recently created.
What else is known? In the event of an exploit or bad faith by the owners of the signature-enabled addresses, the Blast contract can instantly inject malicious code updates to steal funds.
The experts added that Blast, unlike other projects with similar features such as Arbitrum, is not a layer 2 (L2) network and is simply a smart contract that accepts deposits and invests them in revenue-generating protocols such as Lido, liquid ETH staking protocol.
Jarrod Watts of Polygon Labs emphasized that Blast has no testnet, bridges, or rollups, and does not even send transaction data to Ethereum.
“By sending money to the Blast contract, you’re basically trusting 3-5 strangers to stake your funds for you. You won’t be able to withdraw that money at any point in time unless those 3-5 people decide to do the right thing in the future,” the developer explained.
Notably, Blast currently lacks a withdrawal feature. According to the roadmap, it will be activated only on February 24 next year. At the same time, users have already blocked over $303 million in the project’s contract.
In turn, SlowMist founder Yu Xiang said that Blast is a centralized Web 2.0 project, which has received support from financial institutions. Thus, one of the investors of the project is the venture capital firm Paradigm, which previously supported the Blur marketplace.
Xiang expressed indignation that users do not study the technical features of the project, judging its reliability only by the presence of institutional partners.
Useful material?
Market
According to the founder of TRON, the leading US crypto exchange asked for several hundred million dollars for the listing of TRX
Nov 4, 2024
Incidents
The company conducted fictitious trading for six years to inflate the trading volume of tokens of several companies, receiving payment for these services
Nov 1, 2024
Market
1,5 million addresses have already left applications
Oct 31, 2024
Business
The company began investing in bitcoin in 2020, and since then, the value of its securities has risen by 1700%
Oct 30, 2024
Mining
The Deputy Energy Minister explained that in deficit regions, it is impossible to allocate large capacities for industry enterprises until 2030
Oct 30, 2024
Market
Customers will also be able to withdraw funds to bank accounts using cards
Oct 30, 2024