Stablecoins
Identified Bug in Circle's Noble-CCTP on Cosmos Network
Wednesday. August 28 at 6:00 PM
1 min. readAsymmetric Research recently disclosed a critical bug in Circle's Noble-CCTP, a key component of the USDC Cross-Chain Transfer Protocol on the Cosmos network. The bug allowed a potential exploit where a malicious actor could bypass the protocol's verification process and create counterfeit USDC tokens on the Noble bridge. Specifically, the vulnerability was found in the 'ReceiveMessage' handler, which accepted 'BurnMessages' from any sender without verifying the source. Fortunately, no funds were lost, and Circle promptly addressed the issue. This incident echoes a similar vulnerability in the Wormhole bridge on the Aptos network in May 2024, which could have led to a $5 million exploit if left unaddressed. Asymmetric Research's discovery highlights the importance of proactive security measures in safeguarding against potential threats in the cryptocurrency space.