BlockSec: Taiko suspected of being attacked due to GitHub leak of SGX attestation key, resulting in losses exceeding $1.7 million

robot
Abstract generation in progress

BlockBeats News, June 22 — According to BlockSec monitoring, the Taiko network was attacked, resulting in losses of over $1.7 million. Preliminary investigations suggest that the possible root cause is the exposure of the Raiko SGX enclave signing key on GitHub. Raiko is Taiko’s multi-prover stack used for Taiko and Ethereum blocks, so the exposed Raiko SGX enclave key could directly impact Taiko’s on-chain proof verification process.

Because the enclave signing key is publicly accessible, the trust model of SGX provers may have been compromised. The exposed key could allow attackers to register SGX instances controlled by them. Once registered, these instances can sign proof inputs accepted by Taiko’s proof verifiers, enabling fraudulent state/signaling proofs to pass. The attacker can then use forged source signals to register fake bridge messages as RETRIABLE, and subsequently call retryMessage to cause the ERC20Vault to release the standard L1 assets.

TAIKO-13.38%
ETH1.05%
L1-13.95%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned