|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Cryptocurrency News Articles
Asymmetric Research Helps Circle Identify and Fix a Bug that Could Have Led to Massive Losses
Aug 29, 2024 at 08:00 pm
Asymmetric Research, a blockchain cybersecurity firm, helped Circle identify a bug that could have led to massive losses if not addressed.

Blockchain cybersecurity firm Asymmetric Research has helped Circle identify a critical vulnerability that could've led to massive losses if not addressed. The vulnerability resided in Circle's Cross-Chain Transfer Protocol (CCTP) deployed on the Cosmos network, enabling the bridging of the firm's USDC stablecoin.
Asymmetric discovered the vulnerability in the noble-cctp module of the CCTP, which is used for cross-chain USDC transfers on the Cosmos-based Noble chain. The vulnerability allowed anyone to send a message to the CCTP, instructing it to burn (destroy) a specific amount of USDC tokens on the Cosmos Hub.
However, due to a faulty verification process, the CCTP would instead mint (create) the specified amount of USDC tokens on the Noble chain. This vulnerability could've been exploited to mint an "infinite" amount of USDC tokens on the Noble chain, as observed by Asymmetric.
“We privately disclosed a vulnerability to Circle via their bug bounty program,” the security firm noted in its report. “Notably, no malicious exploitation took place, and no user funds were lost. Circle promptly took action, once notified, to fix the bug.”
The vulnerability could've enabled malicious actors to exploit the message sender verification process of the Noble Bridge, which is designed to ensure that only authorized parties (such as the TokenMessenger) can trigger USDC burns on the Cosmos Hub.
This verification process is crucial to prevent unauthorized mints of USDC on the Noble chain. However, the verification was not being performed correctly, allowing anyone to send a message to the CCTP, instructing it to burn USDC on the Cosmos Hub.
As a result, an attacker could've exploited this vulnerability and triggered malicious USDC mints by sending a fake BurnMessage directly through a CCTP MessageTransmitter contract, using the noble-cctp module address and noble's chainid as the CCTP destination.
“However, we did not identify any evidence of exploitation,” Asymmetric stated in its findings, adding that the vulnerability was patched quickly by Circle.
Infinite Money Glitch at First Assumption
Asymmetric initially observed that attackers could've exploited this vulnerability to mint as many USDC tokens as they wanted, which seemed like an "infinite money glitch" at first glance.
However, upon further investigation, they discovered that Noble enforced a mint limit of around 35 million USDC, preventing attackers from minting an unlimited amount of tokens. While this mint limit significantly reduced the potential impact of the vulnerability, it remained a critical issue that needed to be addressed promptly.
Fortunately, thanks to Asymmetric's discovery and Circle's swift response, the vulnerability was patched before any malicious exploitation occurred. Additionally, no tokens were minted out of thin air, and no Noble Bridge users lost their funds.
This incident highlights the importance of regular security audits and vulnerability scanning to identify and address potential risks in blockchain protocols and applications, especially those handling large volumes of user funds.
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.
-
-
- Consensus 2026 Miami: Web3, Blockchain, Cryptocurrency, NFTs, Metaverse, Conference, May 5th — Where Wall Street Meets the Digital Frontier
- May 01, 2026 at 11:27 pm
- Miami buzzes as Consensus 2026 approaches on May 5th, highlighting Web3, blockchain, crypto, NFTs, and the metaverse's shift from hype to institutional and sustainable reality.
-
-
- Bitcoin Miners Electrify the Grid: Ohio Gas Plant Acquisition Powers Up a New Era for Digital Gold
- Apr 30, 2026 at 10:38 pm
- The Bitcoin mining industry is undergoing a significant transformation, with major players aggressively expanding operations and strategically acquiring energy assets like Ohio gas plants to solidify their future in the digital economy.
-
-
- Solana's Slippery Slope: Price Prediction Points to Resistance Loss and Potential Further Drops
- Apr 30, 2026 at 09:08 pm
- Solana is struggling to break key resistance, signaling potential downside. Repeated rejections at $86-$88, coupled with a broken short-term pattern, point to targets as low as $67, or even $40, as sellers maintain control. Investors should watch critical support levels closely.
-
-
- NYC's New Beat: Staking Systems, USD1, and Governance Drive Crypto's Next Wave
- Apr 30, 2026 at 03:02 pm
- From lucrative USD1 earning events to robust governance models, the crypto sphere is buzzing with innovations reshaping how we engage with digital assets, focusing on long-term commitment and stablecoin utility.
-
- OKX Unveils Agent Payments Protocol: Ushering in a New Era of AI Transactions
- Apr 30, 2026 at 02:53 pm
- OKX launches its Agent Payments Protocol (APP), an open standard for AI-driven commerce, enabling agents to manage full business cycles. Explore the implications for AI transactions and agentic payments.

































