EILMELDUNGEN LIVE
🔧 ProgrammierungSoftware-defined Storage für Kubernetes(27.08.2026 um 13:25 Uhr)
🔧 ProgrammierungSoftware-defined Networking in Kubernetes-Infrastrukturen(27.08.2026 um 13:49 Uhr)
🔧 AI Nachrichten Debian is Voting on Whether to Allow AI-Assisted Contributions(23.08.2026 um 09:34 Uhr)
🕵️ SicherheitslückenEight stable kernels with fix for a single vulnerability(28.08.2026 um 15:42 Uhr)
🔧 Programmierung[$] The "rnull" Rust block driver(28.08.2026 um 20:26 Uhr)
🔧 AI Nachrichten Wie KI den Flughafen verändert(26.08.2026 um 10:00 Uhr)
🔧 AI Nachrichten KI Made in Germany: Vision AI für die Industrie | INSIDE AI #39(27.08.2026 um 10:00 Uhr)
🔧 AI Nachrichten I built an app to get my boss to listen to me(27.08.2026 um 16:41 Uhr)
🔧 ProgrammierungSoftware-defined Storage für Kubernetes(27.08.2026 um 13:25 Uhr)
🔧 ProgrammierungSoftware-defined Networking in Kubernetes-Infrastrukturen(27.08.2026 um 13:49 Uhr)
🔧 AI Nachrichten Debian is Voting on Whether to Allow AI-Assisted Contributions(23.08.2026 um 09:34 Uhr)
🕵️ SicherheitslückenEight stable kernels with fix for a single vulnerability(28.08.2026 um 15:42 Uhr)
🔧 Programmierung[$] The "rnull" Rust block driver(28.08.2026 um 20:26 Uhr)
🔧 AI Nachrichten Wie KI den Flughafen verändert(26.08.2026 um 10:00 Uhr)
🔧 AI Nachrichten KI Made in Germany: Vision AI für die Industrie | INSIDE AI #39(27.08.2026 um 10:00 Uhr)
🔧 AI Nachrichten I built an app to get my boss to listen to me(27.08.2026 um 16:41 Uhr)

10 🕛 kürzlich 2 Min Lesezeit 14 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 23.6%
CVE-2020-26241
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
1.1k YouTube-Aufrufe
Securing over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a single memory corruption bug in the dominant Geth client, triggered an unintended Ethereum mainnet chain fork, causing a catastrophic 7-hour outage for major infrastructures like Infura and MetaMask. While the community now champions "client diversity" to mitigate such single points of failure, this heterogeneity introduces a new, insidious threat: subtle implementation inconsistencies across different languages and architectures that traditional testing methods fail to detect.

To fortify this multi-billion dollar foundation, we propose a novel, specification-driven differential testing framework that synergizes classical software engineering with modern AI. Unlike traditional fuzzers, our approach leverages Large Language Models (LLMs) to bridge the gap between abstract specifications and complex reality. We utilize LLMs not only to generate diverse, semantically valid test inputs (covering both EVM opcodes and Client APIs) but also to act as intelligent filters that distinguish genuine bugs from harmless semantic variations. This "dual-engine" approach allows us to identify deep logic flaws with high precision while minimizing false positives.

Our comprehensive evaluation across 11 distinct clients uncovered 98 previously unknown bugs, even including critical errors within the official Ethereum specifications themselves. The impact of our work is immediate and far-reaching: developers confirmed our findings with a greater than 90% acceptance rate, 4 vulnerabilities were assigned CNVD IDs, and our methodology has received official endorsement from the Ethereum Foundation, with specific findings escalated to core protocol management meetings. We provide not just a bug-finding approach, but a crucial safeguard for the stability of the decentralized economy.

Jie Ma | Eng.D Candidate, Beihang University; Zhongguancun Laboratory
Ningyu He | Research Assistant Professor, The Hong Kong Polytechnic University; Amber Group
Chiachih Wu | Partner & Head of Web3 Security, Amber Group
Haoyu Wang | Professor, Huazhong University of Science and Technology
Ying Gao | Associate Professor, Beihang University; Zhongguancun Laboratory
Yinliang Yue | Professor, Zhongguancun Laboratory

https://blackhat.com/asia-26/briefings/schedule/?#fortifying-the-foundation-llm-empowered-differential-testing-for-the-ethereum-infrastructure-50238
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
120 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 48%
🟡 In Evaluierung 21%
🟢 Keine Auswirkung 18%
Spannende Innovation 13%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
Distribution Release: Vanilla OS 3
1 Quelle
New Linux “Steal Governor” Targets CPU Contention in Overcommitted Virtual Machines
1 Quelle
Codex CLI: Use OpenAI’s AI Coding Agent in the Linux Terminal