TON blockchain narrowly avoids crash: Is the TVM vulnerable?

robot
Abstract generation in progress

TON blockchain security firm TonBit announced that it averted a major vulnerability on the TON Virtual Machine.

TON blockchain (TON) averted a total crash after discovering a major bug. On Monday, July 21, TonBit announced that it identified a critical vulnerability in the TON Virtual Machine. According to TonBit, the bug could have led to denial-of-service attacks across the network, bringing its infrastructure down.

The bug in the INMSGPARAM instruction for the TVM included a null-pointer dereference that could have been used to inject false message parameters. Attackers could exploit this behavior to crash the virtual machine at runtime.

In the case of such an exploit, the network would halt its execution of smart contracts and disrupt dApps operating on TON. This would significantly affect the large miniapp ecosystem on Telegram, many of which rely on TON for their infrastructure.

TonBit discovered the vulnerability ahead of the rollout of Global Version 11. This enabled maintainers to quietly integrate the fix before the mainnet deployment of the update.

TonBit fixes third critical bug on blockchain

For its efforts, TonBit earned a bug bounty from the TON Core development team. This was the third time that the security firm obtained a similar reward, with formal recognition from the TON team. In both cases, the team delivered patches before bad actors were aware of the vulnerabilities.

“Ensuring the security and robustness of the TON ecosystem remains our highest priority,” said Paul Li, Co-founder of TonBit. “By continuously probing the deepest layers of TVM and working hand‑in‑hand with the TON Core team, we not only protect users today but also build the foundation of trust necessary for tomorrow’s decentralized applications.”

Owned by BitsLab, TonBit is a security firm focusing on the TON ecosystem. The firm is a primary security assurance provider for the network, and specializes in comprehensive audits for TON-based projects.

TON6.22%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)