Blockchain Gaming
Risk of Exploits in Upgradeable Smart Contracts
Friday. August 16 at 11:30 PM
1 min. readThe $10 million Ronin bridge exploit on Aug. 6 was caused by a faulty upgrade deployment script, as reported by Verichains. The upgrade lowered the voting threshold for validators to zero, allowing any user to withdraw from the bridge without a signature. Verichains highlighted the risks of interacting with upgradeable smart contracts. The attacker could have taken the full amount if they paid more in gas to avoid being front-run. Ronin, known for hosting Axie Infinity, uses the bridge for fund transfers. The exploit occurred due to an error in initializing a variable during an upgrade. The attacker exploited the system by providing a signature from an unauthorized address. The MEV bot, Frontrunner Yoink, successfully drained over $10 million but returned most funds. This incident underscores the dangers of upgradeable cross-chain bridges and the need for more secure deployment practices.