Urgent.News

What's breaking now, across thousands of outlets.

Tech

Smart Contract Vulnerability Surface Analysis: Binance CEX

Smart Contract Vulnerability Surface Analysis: Binance CEX Target Protocol : Binance CEX (TVL: $172851.1M) Smart Contract Vulnerability Surface Analysis Binance CEX (Centralized Exchange) – Ethereum & L2 Ecosystem TVL (Ethereum/L2): ≈ $172,851.1 M Prepared for: Binance CEX Security & Engineering Teams Prepared by: Senior DeFi Security Researcher – Smart‑Contract Audit Date: 2026‑10‑11 1.…

The Binance Centralized Exchange (CEX) employs a hybrid architecture, combining off-chain order matching and custody with on-chain smart contracts. These contracts handle deposit/withdrawal operations, bridge transfers, staking/earn products, governance proxies, and API-driven instant swap modules. The primary goal is to protect user assets during critical transactions while maintaining high throughput and low-latency interaction with the centralized order book.

Our analysis targeted the smart contract attack surface within Binance CEX, focusing on potential vulnerabilities that could lead to stolen or locked user funds, disrupted market operations, or compromised off-chain accounting (double-spending and replay attacks). The risk posture of the current contract suite is assessed as high (Risk Score = 8/10), primarily due to upgradeability, access-control centralisation, bridge and cross-chain modules, and insufficient isolation between hot and cold wallet contracts.

The analysis covered five main contract groups: core vault contracts (DepositVault, WithdrawalVault, ColdStorageProxy, and HotWalletProxy), bridge and L2 integration (BinanceBridgeV2, L2Adapter, and CrossChainRouter), earn/staking products (BinanceEarnV1 and AutoCompoundProxy), governance and upgradeability (ProxyAdmin, TimelockController, and UpgradeBeacon), and API-driven instant swap (InstantSwapRouter and FlashLoanProvider).

External dependencies include OpenZeppelin libraries, Chainlink price feeds, and third-party L2 rollup contracts.

Potential attack vectors identified include upgradeability abuse, re-entrancy in the withdrawal vault, bridge message replay, oracle manipulation, flash loan exploitation, and insufficient access control on emergency pause functions. Each of these vectors poses varying levels of risk, with upgradeability abuse, re-entrancy, and bridge message replay being the most significant threats.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

How to Avoid YouTube Ads Using MikroTik and a VPN

I do not watch YouTube that often, but the ads get on my nerves whenever I do. For a while, I paid for Turkish YouTube Premium through my Apple account.

  • Set up VPN connection on MikroTik router using IKEv2/IPsec protocol
  • Configure MikroTik router with VPN provider's certificate and IPsec settings
  • Route YouTube traffic through VPN by importing IP ranges and setting firewall rule

OpenNVR 0.1.6 Is Out: Search Your Camera Footage in Plain English

What if you could search hours of CCTV footage by simply describing what you're looking for? Instead of manually scrubbing through recordings, imagine searching for "red truck at the dock yesterday"…

  • OpenNVR 0.1.6 released with AI-powered video surveillance enhancements
  • Natural language search for CCTV footage using keywords, colors, vehicle types
  • Integration with Home Assistant via MQTT discovery and enhanced security

Binary, Octal, Decimal, and Hexadecimal Explained (With Conversion Methods)

We write numbers in base 10 because we have ten fingers. Computers work in base 2, and programmers often use base 8 and base 16 as compact ways to write binary.

  • Decimal system based on ten fingers, computers use base 2
  • Binary digits (0,1) represent hardware storage, octal (0-7) in Unix permissions
  • Hexadecimal blends digits 0-9 and letters A-F, compact binary representation

A College Told Flock to Remove Its Cameras. The Company Refused.

The Chicago Sun-Times reports: When Elgin Community College hired Flock Safety to install six surveillance cameras in April 2025, President Peggy Heinrich thought they would "enhance the safety and…

  • Elgin Community College installed surveillance cameras in April 2025.
  • Flock refused to remove cameras despite college's request.
  • College covered cameras with black trash bags and zip ties.

AI Made Code Cheaper. It Didn’t Make Software Ownership Free.

When a widely used open-source library changes its licensing or introduces a commercial model, one reaction appears almost immediately: “We can build this ourselves.” And now, with AI-assisted coding…

  • AI-assisted coding makes software cheaper to implement.
  • Ownership and maintenance of AI-generated code remain unclear.
  • Concerns about security, compatibility, and support persist.

More from Sunday 11 October →