Ethereum Scaling Solution Aurora Pays $2 Million Bug Bounty to Hackers

Ethereum
Author
Author
Ruholamin HaqshanasVerified
Part of the Team Since
Oct 2021
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated: 
Image credit: Aurora.com

Aurora, an Ethereum Virtual Machine (EVM) compatible scaling and bridge solution built on top of the NEAR Protocol blockchain network, has completed the payment of a $2 million bug bounty to a pair of whitehat hackers that reported vulnerabilities on the platform back in June. 

According to a blog post written by ImmuneFi, a leading web 3 bug bounty platform that facilitated the transaction, the whitehat hackers will each receive $1 million worth of the platform’s eponymously named native token streamed linearly over one year. 

The vulnerabilities the hackers discovered related to Aurora’s permissionless bridging functionality between NEAR Protocol and Ethereum. The first vulnerability was that the platform had a different ERC-20 (fungible token standard) called NEP-141. This would potentially allow an attacker to create worthless NEAR tokens, bridge them to Aurora, and then use them to withdraw ETH from the addresses of Aurora users. 

The second bug had to do with the burn function of the bridge. It would have allowed an attacker to create a “fake burn event” on Aurora which could then be used to withdraw ETH from the protocol’s reserve. 

Both vulnerabilities have been fixed without any loss of funds to users, the blog post noted. The first report on the vulnerabilities was written by DeFi security firm Halborn. 

“We would like to thank the anonymous whitehat for doing an amazing job and responsibly disclosing such an important bug. Big props also to the Aurora team who responded quickly to the report and patched it,” ImmuneFi said in the post. 

Hacks still a major problem among blockchain platforms

Not all cross-bridge blockchain platforms have been as lucky as Aurora in handling major vulnerabilities without loss of funds. According to a CNBC report in August, bridge protocols have lost over $1.4 billion to hackers so far in 2022. 

The report notes that the endemic attacks on bridges can be traced in part to sloppy engineering. This was the case in the hacks of Axie Infinity’s Ronin Network, and also Harmony Horizon, Wormhole, and Nomad. 

Meanwhile, they are not the only sector of the crypto market under attack by cybercriminals. The New York Times estimates that over $2 billion in total have been stolen from the crypto industry this year by hackers. The trend points to the need for greater scrutiny and regulation of the space the report noted. 

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$2,714,199,547,593
-12.84%
Trending Crypto

More Articles

Bitcoin News
Bitcoin Hashrate Falls 12% After US Winter Storms Hit Miners
Amin Ayan
Amin Ayan
2026-02-01 10:30:00
Blockchain News
Ripple Co-Founder Leads $40M Push to Counter California Wealth Tax
Anas Hassan
Anas Hassan
2026-02-01 10:00:14
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors