Skip to content
← Back to newsVirtuals Protocol Addresses Critical Vulnerability and Launches Bug Bounty Program
Security

Virtuals Protocol Addresses Critical Vulnerability and Launches Bug Bounty Program

By ToTo BugelmanNewcomer0 rep· 1/3/2025

Virtuals Protocol, a blockchain firm specializing in artificial intelligence agents, recently addressed a critical vulnerability discovered in its audited smart contract. The issue was identified by a pseudonymous security researcher, prompting the company to implement an urgent fix and relaunch its bug bounty program to reward future discoveries.

 

Key Takeaways

  • A critical vulnerability was found in Virtuals Protocol’s audited contract.

  • The bug was reported by a pseudonymous researcher named Jinu.

  • Virtuals Protocol has issued a fix and plans to reward the researcher with a bounty.

 

Discovery of the Vulnerability

On December 3, 2024, Jinu, the security researcher, reached out to Virtuals Protocol after identifying a significant bug in one of its smart contracts. Upon reporting the issue, Jinu discovered that the company did not have an active bug bounty program at the time, which meant that the discovery would not qualify for a reward.

Jinu expressed concerns about the vulnerability, stating that it could have serious implications for the Virtuals ecosystem. The researcher noted that the vulnerability stemmed from a lack of validation when creating AgentTokens based on the internal bond threshold. If exploited, this flaw could have halted the generation of AgentTokens until a fix was implemented.

 

Immediate Response and Fix

Following the public disclosure of the vulnerability on social media, Virtuals Protocol promptly contacted Jinu to confirm the issue and implement a fix. The company acknowledged the oversight and expressed gratitude for the researcher’s diligence in reporting the problem.

In a message to Jinu, Virtuals Protocol stated, "We have verified the vulnerability and applied a patch. Thank you for bringing this to our attention, and we apologize for the earlier miscommunication. We will review the severity of the issue and issue you a bug bounty shortly."

 

Bug Bounty Program Relaunch

In light of this incident, Virtuals Protocol has decided to relaunch its bug bounty program. This initiative aims to encourage security researchers to identify and report vulnerabilities in their systems, thereby enhancing the overall security of the platform.

While the specifics of the bounty reward for Jinu have yet to be determined, the company has committed to recognizing the researcher’s contribution. Jinu, who became interested in Virtuals Protocol after a friend invested in a token created on the platform, spent approximately 30 minutes reviewing the code before discovering the bug.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Virtuals Protocol Addresses Critical Vulnerability and Launches Bug Bounty Program | BlockzHub