The beacon chain is the backbone of the Ethereum's evolution towards a proof-of-stake-based scalable network. Beacon clients are the applications implementing the services required to operate the beacon chain, namely validators, beacon nodes, and slashers. Security defects in beacon clients could lead to loss of funds, consensus rules violation, network congestion, and other inconveniences. We reported more than 35 issues to the beacon client developers, including various security improvements, specification inconsistencies, missing security checks, exposure to known vulnerabilities. None of our findings appears to be high-severity. We covered the four main beacon clients, namely Lighthouse (Rust), Nimbus (Nim), Prysm (Go), and Teku (Java). We looked for bugs in the logic and implementation of the new security-critical components (BLS signatures, slashing, networking protocols, and API) over a 3-month project that followed a preliminary analysis of BLS signatures code. We focused on Lighthouse and Prysm, the most popular clients, and thus the highest-value targets. Furthermore, we identify protocol-level issues, including replay attacks and incomplete forward secrecy. In addition, we reviewed the network fingerprints of beacon clients, discussing the information obtainable from passive and active searches, and we analyzed the supply chain risk related to third-party dependencies, providing indicators and recommendations to reduce the risk of backdoors and unpatchable vulnerabilities. Our results suggest that despite intense scrutiny by security auditors and independent researchers, the complexity and constant evolution of a platform like Ethereum requires regular expert review and thorough SSDLC practices.
翻译:信标链是Eceenum系统演变成以验收为根据的可扩展网络的基石。信标客户是执行信标链运作所需服务的应用程序,即验证器、信标节点和鞭笞器。信标客户的安全缺陷可能导致资金损失、违反共识规则、网络拥堵和其他不便。我们向信标客户开发者报告了超过35个问题,包括各种安全改进、规格不一致、安全检查缺失、暴露于已知弱点。我们发现的情况似乎都不是高度的。我们覆盖了四个主要信标客户,即灯塔(鲁斯特)、尼姆斯(尼姆)、普里斯姆(戈)和特库(贾瓦)。我们寻找了在新安全关键组成部分(BLS签名、斜线、联网协议和API)的逻辑和实施中的错误。我们向信标开发者报告了35个以上的问题,包括各种安全改进、规格、最受欢迎的客户和最高价值目标。此外,我们从定期的服务器服务器上,我们从S-liver上,我们从S-list的服务器上,从S-listal Serview Streal vical views reviews reviews reviewst views reviewst views views view views view views views views views viol viol viol viol viol views viol viol viol viol viol viol vi vi vi viol viol viol vi vi vi vi vi vical vi vi vi vi vi vical views views vi vical vi vi vi vi vi vi vi vi vi vi vi vi vi vical vical vical vical vi vi vical vical vical vical vi vi vi vi vi vi vi vi vi vi vi vi vi vical vi vi vi vi vical vi vi vi vi