Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cross-Chain Bridge Risk Assessment: Deribit

Cross-Chain Bridge Risk Assessment: Deribit Target Protocol : Deribit (TVL: $3898.1M) Cross‑Chain Bridge Risk Assessment – Deribit TVL: ≈ $3.9 B (Ethereum + L2) Date: 9 Oct 2026 Prepared by: Senior DeFi Security Researcher – [Your Name] 1. Executive Summary Deribit, a leading crypto‑derivatives exchange, has recently launched a cross‑chain bridge that enables users to transfer collateral,…

The report outlines the risk assessment of Deribit's cross-chain bridge, a critical component supporting the $3.9 billion TVL of the platform. The assessment identified several high-severity issues, with a total risk score of 7 out of 10, indicating a high-medium risk level.

The smart contract layer of the bridge contained three high-severity vulnerabilities. These included a re-entrancy issue in the L2-to-L1 withdrawal handler, an unchecked external call in the fee-distribution module, and an integer overflow in the capacity accounting mechanism. These vulnerabilities could lead to significant token theft, economic denial-of-service, and unlimited capacity over-commitment, respectively.

Cross-chain message verification also presented two high-severity weaknesses. The first was a weak Merkle-proof verification for Optimism roll-up messages, which could allow malicious relayers to submit fabricated proofs. The second issue was reliance on a single "Message-Relayer" oracle that could be censored or compromised, potentially allowing an attacker to censor withdrawals or inject false messages.

Governance and upgradeability presented two medium-severity weaknesses. The bridge used a single-owner ProxyAdmin with no timelock, and critical parameters like fee rates and capacity caps were not protected with a multi-sig. This setup could allow a compromised owner to pause the bridge at will, leading to operational disruption and potential ransom-like extortion.

Operational and infrastructure concerns ranked as low severity. The most significant issue was inadequate monitoring of the "Deribit Chain" validator set, which could expose the system to a potential 51% attack on the side-chain.

Overall, while the bridge functions adequately and has passed internal QA, the identified high-severity vulnerabilities and governance weaknesses pose a realistic pathway for a financially significant exploit.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Why Your Static Site’s lastmod Is a Lie (And How CI/CD Shallow Clones Secretly Hurt Your SEO)

If you build static websites, documentation hubs, or content platforms using Next.js, Astro, or 11ty, there is a very high probability that your sitemap.xml is quietly lying to Googlebot every single…

  • CI/CD shallow clones timestamp all files with current time, inflating last modified dates.
  • Search engines penalize sites with false timestamps, wasting crawl budget and slowing indexing.

Detection content as code: reviewing a change the way you review software

Detection content as code: reviewing a change the way you review software The problem with editing rules in a console Detection rules written directly in a security platform have no review, no…

  • Detection rules should be treated as code with review, version control, and testing.
  • Store rules in plain text format within a repository for portability.

Day 16: Learning JavaScript DOM Manipulation — Create, Change & Delete Elements

My webdevelopment learning journey continues Today I learned about JavaScript DOM manipulation and how to create, modify, and delete HTML elements dynamically using JavaScript. 1.

  • document.getElementById() selects HTML elements by unique ID
  • document.createElement() creates new HTML elements dynamically
  • remove() method deletes elements from the webpage

More from Friday 9 October →