搜索
文章
快讯
2025-02-17 05:30:29
Planet Lunch News
<p>1. Pension funds or treasuries of 12 U.S. states hold a total of $330 million worth of Strategy shares;<br/> 2. Bloomberg: Argentine President Milley, who is deeply involved in the LIBRA scandal, may avoid paying a heavy political price due to his performance;<br/> 3. Argentine development team LambdaClass: considering whether to file a lawsuit. The LIBRA incident destroyed the Argentine encryption market;<br/> 4. The Broccoli holding &quot;No. 1 address&quot; transferred 40.75 million Broccoli to Gate.io 10 minutes ago. If sold, it will lose 30%;<br/> 5. Metaplanet, a Japanese listed company, increased its holdings by 269.43 BTC;<br/> 6. The founder of Bartool Sports may have lost $5.34 million due to buying LIBRA too late, but was compensated with 5 million USDC;<br/> 7. Billionaire Paul Tudor Jones&#39; investment firm holds $426.9 million in BlackRock IBIT;<br/> 8. Lawyer confirms that the United States has dropped all charges against former BTC-e operator Alexander Vinnik;<br/> 9. Meteora Co-founder: recommended Kelsier to the team behind MELANIA, but never purchased, received or managed MELANIA, LIBRA and other tokens;<br/> 10. Coffeezilla: The LIBRA team admitted in an interview that they had attacked the token;<br/> 11. Analysis: The average transaction cost difference between Ethereum L1 and Solana hit a new low last weekend;<br/> 12. Viewpoint: The Meme coin cycle may become active again as the macro-economy improves, and the market has entered the late stage.<br/></p>
2025-01-29 06:29:28
Succinct releases fix after revealing potential SP1 vulnerability, critics say communication process lacks transparency
<p>Odaily News LambdaClass has come under scrutiny after it recently disclosed a serious security vulnerability in the proof generation process of Succinct SP1 ZKVM, a zero-knowledge proof infrastructure company. The vulnerability in SP1 version 3 was discovered in collaboration with 3Mi Labs and Aligned, and stems from the interaction of two independent security vulnerabilities.<br/> Succinct previously disclosed this potential vulnerability to its users via Github and Telegram. Although the vulnerability was quickly resolved before disclosure, the process raised concerns about the transparency of the security practices of the Zero-Knowledge Virtual Machine (ZKVM). SP1&#39;s technology is currently supporting upgrades to the rollup infrastructure under development:<br/> -Mantle Network has integrated SP1 to transition to ZK validity rollup, aiming to shorten transaction completion time and support institutional-grade asset settlement;<br/> -AggLayer uses SP1 to generate pessimistic proofs to ensure the security of its cross-chain interoperability solution;<br/> -Taiko has adopted SP1 as a ZK prover to protect its L2 execution using a multi-prover system;<br/> -Soon is a relatively new project that is building an SVM rollup framework that uses ZK fault proofs powered by SP1 to settle to Ethereum, similar to Eclipse, which uses RISC Zero.<br/> LambdaClass warns that the full impact of the vulnerability requires further assessment. It is worth noting that the exploitation of the vulnerability depends on the interaction between the two issues, which means that fixing one issue may not be enough to prevent exploitation.<br/> LambdaClass developer Fede stressed on social media that his team felt compelled to disclose the issue publicly after sensing a lack of urgency on the issue from Succinct.<br/> According to Avail&#39;s Anurag Arjun, Succinct leadership acted responsibly in fixing the issue, but he agrees that better public disclosure practices are needed. Arjun confirmed that his team was privately informed of the issue before the vulnerability was publicly disclosed. Avail&#39;s deployments were not at risk because they rely on Succinct&#39;s proprietary attestor, which remains under license. Avail&#39;s rollup clients have not yet started using their SP1-driven bridge contract, so there is no practical impact.<br/> At the same time, Succinct’s supporters point out that responsible disclosure often involves private reporting before public announcements to avoid unnecessary panic and potential exploitation.<br/> Additionally, Succinct&#39;s SP1 update version 4 (called Turbo) addresses the discovered vulnerabilities, and downstream projects have begun integrating these fixes. (Blockworks)<br/></p>
查看更多