harmony-one / harmony

The core protocol of harmony
https://harmony.one
GNU Lesser General Public License v3.0
1.47k stars 289 forks source link

[~2,000 USD] DDOS a validator node to prevent it to propose/sign blocks (BINGO) #2712

Closed gizemcakil closed 4 years ago

gizemcakil commented 4 years ago

image

About The Bounty

Please carefully review the competition terms and submission process before starting. https://github.com/harmony-one/harmony-open/blob/master/README.md

Description

This is an open ended bounty to identify exploitation areas, specifically related to preventing a validator node from proposing and/or signing blocks by DDOS like attacks. OOM, MiTM and eclipse attacks will be considered under this bounty.

Useful readings:

Prizes

There are two tiers of prizes for this bounty. The prize tier for each submission will be evaluated and decided by the Harmony engineering team. The judging criteria for tiers are:

image

IMPORTANT NOTE: The prizes will be paid in native ONE tokens, the fiat value of prizes will change with token prices.

Explore All Bounties

https://gitcoin.co/profile/harmony-one

sophoah commented 4 years ago

IP addresses of external validators are not exposed, so the main challenge here would be figure out the IP, or expand the attack to the entire shard/network as a whole

gitcoinbot commented 4 years ago

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


This issue now has a funding of 0.001 ETH (0.17 USD @ $170.32/ETH) attached to it as part of the harmony-one fund.

daniyal-24 commented 4 years ago

john