Learn

Get to know Acurast. Explore our story, dive into the technical documentation, and see who we’re partnered up with in the ecosystem.

Acurast Security Protocol Upgrades

 

 

Dear Community,

The threat landscape has changed

 

Since the public release of AI models like Claude Mythos/Fable, AI-assisted security breaches have surged across the crypto space. Driven by high financial incentives, open-source codebases, and professionalized state-sponsored hacker groups (such as those detailed in the FBI/CISA Joint Cybersecurity Advisory AA22-108A), Web3 is and will remain a prime target.

 

What happened

Although the Acurast network was not breached by external attackers, a critical bug within our components did lead to more rewards being paid out to some unknowing users. The good news is that the larger users benefiting from this bug agreed to burn the surplus tokens they received. Thanks to their cooperation, the remaining impact was limited to approximately 71,000 ACU in excess rewards, ACU is the Acurast network token, worth around $5,500 at the time. The Acurast Association will cover this amount from its operational funds. We must always stay vigilant.

 

Thank you to our disclosing researcher

On that note, we want to give a massive thank you to community member “only01essential”, who responsibly disclosed three major security issues to us.

 

Why we shipped the fixes before the source code

Fixing these vulnerabilities required an unusual approach for protocol upgrades 26.3, 26.4, and 26.5. Normally, we publish the source code before a governance vote — the on-chain process by which token holders approve a change to the protocol. In this case, publishing the changes before the fixes were live would have exposed the vulnerabilities and potentially allowed others to exploit them.

 

For this reason, we deployed the fixes first and published the source code afterwards.

 

This is not intended to become the norm. Now that all reported issues have been fixed, we are returning to our standard process of publishing the source code before future governance votes.

The updated source code and changelog are available on the Acurast Substrate releases page on GitHub.

 

The post-mortems

We are also publishing detailed post-mortems — write-ups of exactly what went wrong, when it was introduced, and how it was fixed — for the discovered issues:

 

Acurast Compute — Double claiming of staking rewards

Acurast Token Conversion — replay of conversion messages

 

Security remains a top priority at Acurast and if you are a bounty hunter we welcome your reports.

 

The upside

There is also something positive to take away from this.

The bugs being found today were already there. The difference is that more people now have the tools to find them.

AI is making security research easier and more accessible, not just for attackers, but also for developers and security researchers.

This will translate to having soon a safer crypto space in general and also give a huge security edge to open source projects.

 

Thank you to everyone who helped us identify, fix, and contain these issues. Every vulnerability we find and fix makes Acurast stronger.