BlockSec releases preliminary analysis of Taiko attack: suspected exposure of Raiko SGX signature key on GitHub
Foresight News reported that BlockSec Phalcon has released a preliminary analysis of the Taiko security incident. The root cause may be that the SGX enclave signing key for Taiko's multi-prover component Raiko was exposed on GitHub. Attackers leveraged the exposed key to register maliciously controlled SGX instances, bypassed the proof verification mechanism, and forged state/signal proofs. Subsequently, they used the forged source signal to mark fake cross-chain messages as RETRIABLE and called retryMessage to extract canonical L1 assets from ERC20Vault.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Apollo Silver Reaffirms Support For Ejido Benito Juarez's Water Resources in Mexico
Dow Jones 1:30 PM Averages
Sector Update: Energy
