Blockchain

Virtuals Protocol Fixes Bug, Pledges Bounty For Researcher’s Discovery

An unexpected bug found in an audited smart contract led Virtuals Protocol, a blockchain firm focused on artificial intelligence agents, to issue a timely fix and relaunch its bug bounty program. On Dec. 3, 2024, pseudonymous security researcher Jinu contacted Virtuals Protocol after discovering a bug in one of its audited contracts. Still, upon reporting the issue, Jinu learned that the company did not have an active bug bounty program, meaning the discovery did not qualify for a reward.

According to Jinu, the Virtuals Protocol team also closed the Discord group created solely to report the vulnerability. In an X thread, Jinu said: “The vulnerability is simple and can impact the virtuals ecosystem (but virtuals probably doesn’t care about security”. Jinu explained to Cointelegraph that the vulnerability was related to a lack of validation when creating AgentTokens based on the internal bond threshold. “If exploited, this vulnerability would have prevented AgentTokens from being generated until the contract was fixed,” Jinu said.
After the information was made public on X, Virtuals Protocol contacted Jinu and issued an immediate fix. Despite the timely fix, Virtuals Protocol is yet to announce a bug bounty reward for Jinu. In a message to the researcher, the company thanked Jinu for reporting the issue and apologized for earlier miscommunication.
“Hey jinu we have verified the vulnerability and applied a patch below. Thank you for bringing this up to us and we apologise for the miscommunication between support and yourself. Let us internally review the severity of the issue and we will issue you a bug bounty shortly,” the company representatives told the security researcher.
When asked about the bounty expectations, Jinu said they are unaware of the general rewards for bug discoveries. Jinu told Cointelegraph that they got interested in Virtuals Protocols after a friend invested in a token created on Virtuals. “I spent about 30 minutes looking at the code to see if it was well done,” Jinu said before they came across the bug.
Terron Gold

Recent Posts

Senator Murphy Alleges White House Insiders Profited From Iran Strike Bets, Pushes to Ban Prediction Markets on Government Actions

U.S. Senator Chris Murphy (D-Conn.) is calling for legislation to ban prediction markets that allow traders to bet…

2 days ago

IRS Proposes Electronic-Only Delivery For Crypto Tax Forms Under New Reporting Rules

The U.S. Internal Revenue Service (IRS) has proposed a new rule that would allow cryptocy brokers to deliver…

2 days ago

Crypto-Friendly Fintech Revolut Files For U.S. Banking License to Expand Crypto and Payments Services

Global fintech powerhouse Revolut has filed an application for a U.S. banking license, a move that would allow…

2 days ago

Suspect Arrested on Caribbean Island of Saint Martin in $46M Seized Crypto Theft Case

A man accused of stealing tens of millions of dollars in cryptocy from U.S. government…

2 days ago

NYSE Parent ICE Invests in Crypto Exchange OKX at $25B Valuation Amid Tokenized Stocks Push

Intercontinental Exchange (ICE) — the parent company of the New York Stock Exchange — has taken a strategic…

2 days ago

AI Models Favor Bitcoin as a Store of Value, Stablecoins for Payments, BPI Study Finds

A new study from the Bitcoin Policy Institute (BPI) found that leading artificial intelligence models overwhelmingly favor Bitcoin…

2 days ago