<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Moonbeam_Network_DelegateCall_Vulnerability_Pwning.eth</id>
	<title>Moonbeam Network DelegateCall Vulnerability Pwning.eth - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Moonbeam_Network_DelegateCall_Vulnerability_Pwning.eth"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonbeam_Network_DelegateCall_Vulnerability_Pwning.eth&amp;action=history"/>
	<updated>2026-06-01T20:18:44Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonbeam_Network_DelegateCall_Vulnerability_Pwning.eth&amp;diff=5194&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/moonbeamnetworkdelegatecallvulnerabilitypwningeth.php}} {{Unattributed Sources}}  Moonbeam NetworkThe Moonbeam network is a cross-chain smart contract platform that integrates functionality from various blockchains, including Ethereum, Cosmos, and Polkadot. It enables developers to create multi-chain instances of their applications with compatibility and cross-cha...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Moonbeam_Network_DelegateCall_Vulnerability_Pwning.eth&amp;diff=5194&amp;oldid=prev"/>
		<updated>2023-11-16T21:39:08Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/moonbeamnetworkdelegatecallvulnerabilitypwningeth.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Moonbeamnetwork.jpg&quot; title=&quot;File:Moonbeamnetwork.jpg&quot;&gt;thumb|Moonbeam Network&lt;/a&gt;The Moonbeam network is a cross-chain smart contract platform that integrates functionality from various blockchains, including Ethereum, Cosmos, and Polkadot. It enables developers to create multi-chain instances of their applications with compatibility and cross-cha...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study|source=https://www.quadrigainitiative.com/casestudy/moonbeamnetworkdelegatecallvulnerabilitypwningeth.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Moonbeamnetwork.jpg|thumb|Moonbeam Network]]The Moonbeam network is a cross-chain smart contract platform that integrates functionality from various blockchains, including Ethereum, Cosmos, and Polkadot. It enables developers to create multi-chain instances of their applications with compatibility and cross-chain interoperability. A whitehat named pwning.eth discovered and reported a critical vulnerability in Moonbeam via Immunefi, demonstrating the potential for direct theft of native assets. The vulnerability, found within the Frontier Substrate pallet, could have impacted up to $100 million in funds. Moonbeam swiftly addressed the issue, preventing any user funds from being lost, and awarded pwning.eth a $1 million bounty for responsibly disclosing the bug, along with a $50,000 bonus from Moonwell.&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&amp;lt;ref name=&amp;quot;immunefi-12214&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;opensea-12215&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;immunefimedium-12216&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;moonbeamnetwork-12217&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;moonbeamnetwork-12218&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-12219&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Moonbeam Network ==&lt;br /&gt;
&amp;quot;The Moonbeam network is a smart contract platform for cross-chain connected applications that unites functionality from many blockchains including Ethereum, Cosmos, Polkadot, and more. It makes it possible for developers with Solidity or Vyper-based smart contracts to create multi-chain instances of their application that are able to communicate with each other. Moonbeam is able to unify access to users, assets, and data through: compatibility and cross-chain interoperability with many blockchains, an excellent development environment with unmatched tool support, and a modern proof-of-stake architecture built on Substrate.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Moonbeam simplifies the developer experience by combining full Ethereum compatibility with the power of Polkadot, including scalability, cross-chain integrations, and on-chain governance.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Moonbeam delivers complete Ethereum compatibility within a Polkadot parachain environment, so developers can continue to use the programming languages and tools they’ve grown used to — but within a fast-growing and scalable Layer 1 chain.&lt;br /&gt;
&lt;br /&gt;
It is also compatible with the Substrate and Polkadot ecosystem, including block explorers, wallets, parachains, and more, allowing users the flexibility to choose the right tools and services for the job.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Write your smart contracts in anything that compiles to Solidity bytecode, without needing to rewrite or reconfigure.&amp;quot; &amp;quot;Leverage Ethereum’s broad development ecosystem by using the tools you love, like MetaMask, Hardhat, Waffle, Remix, and Truffle, in addition to Substrate-based APIs.&amp;quot; &amp;quot;Built-in integrations for assets like DOT and ERC-20s and infrastructure services like Chainlink and TheGraph. Continual efforts to integrate with other Polkadot-native assets.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On May 27th, whitehat pwning.eth submitted a missing call check critical vulnerability to the Moonbeam network via Immunefi, demonstrating the possibility of a direct theft of the native assets, such as Moonriver (MOVR) and Moonbeam (GLMR), which were deployed using pre-compiled contracts. The Moonbeam team estimated that the vulnerability could have impacted up to $100m in funds, which was prevented due to the whitehat’s swift disclosure.&lt;br /&gt;
&lt;br /&gt;
The security vulnerability was found within Frontier — the Substrate pallet that provides core Ethereum compatibility features within the Polkadot ecosystem, which Moonbeam helped create.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;In Ethereum, there are three major types of contract calls: regular CALL, STATICCALL, and DELEGATECALL.&lt;br /&gt;
&lt;br /&gt;
When contract A makes a CALL to contract B by calling foo(), the function execution relies on contract B’s storage, and the msg.sender is set to contract A.&lt;br /&gt;
&lt;br /&gt;
This is because contract A called the function foo(), so that the msg.sender would be contract A’s address and msg.value would be the ETH sent along with that function call. Changes made to state during that function call can only affect contract B.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;However, when the same call is made using DELEGATECALL, the function foo() would be called on contract B but in the context of contract A. This means that the logic of contract B would be used, but any state changes made by the function foo() would affect the storage of contract A. msg.sender would point to the EOA who made the call in the first place. And what is important in the case of the Moonbeam bug, msg.value would point to the first call context, not the second. In other words, Ether is not sent along delegatecall. (See example 2).&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;[T]here was no logic present under the Moonbeam pre-compiled contract to determine if the incoming call is DELEGATECALL or a static CALL in EVM.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;[T]hanks to the whitehat’s work, no user funds were lost, and Moonbeam quickly released an upgrade that patched the vulnerability.&lt;br /&gt;
&lt;br /&gt;
The whitehat was awarded $1 million for his find, the max critical bounty from Moonbeam’s bug bounty program on Immunefi. Moonwell added a $50k bonus as well, making pwning.eth’s total winnings $1,050,000.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The third custom-designed whitehat card was minted to whitehat pwning.eth on September 19, 2022, to recogize his critical bug find in Moonbeam, for which he received a $1 million payment and an additional contribution of $50,000 from Moonwell. You can read more details about how he responsibly disclosed that bug here.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The whitehat card legend for the pwning.eth Moonbeam card, left to right:&lt;br /&gt;
&lt;br /&gt;
Bow: Well-written PoC&lt;br /&gt;
Lightning: Rare/complex type of exploit&lt;br /&gt;
Impact of Attack: 7&lt;br /&gt;
Ease of Defense: 5&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&lt;br /&gt;
&lt;br /&gt;
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.&lt;br /&gt;
&lt;br /&gt;
Include:&lt;br /&gt;
&lt;br /&gt;
* Known history of when and how the service was started.&lt;br /&gt;
* What problems does the company or service claim to solve?&lt;br /&gt;
* What marketing materials were used by the firm or business?&lt;br /&gt;
* Audits performed, and excerpts that may have been included.&lt;br /&gt;
* Business registration documents shown (fake or legitimate).&lt;br /&gt;
* How were people recruited to participate?&lt;br /&gt;
* Public warnings and announcements prior to the event.&lt;br /&gt;
&lt;br /&gt;
Don't Include:&lt;br /&gt;
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.&lt;br /&gt;
* Anything that wasn't reasonably knowable at the time of the event.&lt;br /&gt;
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Moonbeam Network DelegateCall Vulnerability Pwning.eth&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|May 27th, 2022&lt;br /&gt;
|Vulnerability Report&lt;br /&gt;
|The vulnerability was reported to the Immunify Bug Bounty program.&lt;br /&gt;
|-&lt;br /&gt;
|July 28th, 2022 5:23:34 AM MDT&lt;br /&gt;
|Bugfix Review Published&lt;br /&gt;
|Imumify first publishes a bugfix review for the vulnerability.&lt;br /&gt;
|-&lt;br /&gt;
|September 19th, 2022 3:35:23 AM MDT&lt;br /&gt;
|Pwning.eth Trading Card NFT&lt;br /&gt;
|Pwning.eth is issued a trading card NFT as recognition for his contribution by Immunefy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount at risk has been estimated at $100,000,000 USD. No funds were lost.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
A bounty of $10,050,000 USD was paid for the discovery.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;immunefi-12214&amp;quot;&amp;gt;[https://immunefi.com/hall-of-fame/ Immunefi - Whitehat Hall of Fame] (Jan 10, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;opensea-12215&amp;quot;&amp;gt;[https://opensea.io/assets/ethereum/0xdbe4e52b12790670f9f9152d775bab806a08795d/3 https://opensea.io/assets/ethereum/0xdbe4e52b12790670f9f9152d775bab806a08795d/3] (Nov 15, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;immunefimedium-12216&amp;quot;&amp;gt;[https://medium.com/immunefi/moonbeam-missing-call-check-bugfix-review-6279d609bdc5 Moonbeam Missing Call Check Bugfix Review] (Nov 16, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;moonbeamnetwork-12217&amp;quot;&amp;gt;[https://moonbeam.network/ Moonbeam | Cross-Chain Connected Smart Contract Platform] (Nov 16, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;moonbeamnetwork-12218&amp;quot;&amp;gt;[https://moonbeam.network/networks/moonbeam/ Moonbeam Network - Solidity Smart Contracts on Polkadot] (Nov 16, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-12219&amp;quot;&amp;gt;[https://etherscan.io/tx/0x5bd9dce0e8cd4a2967689492c2fa9b2dec39a831591c4c2bc2c7455fa5d667e9 Ethereum Transaction Hash (Txhash) Details | Etherscan] (Nov 16, 2023)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>