EILMELDUNGEN LIVE
🔧 AI Nachrichten Use Your Computer and Browser(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Talk to ChatGPT Work(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Create Slides, Docs, and Templates(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Use ChatGPT Work on Your Phone(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Tennis (:30)(29.08.2026 um 07:22 Uhr)
🔧 AI Nachrichten Magic Manga Girl (:30)(29.08.2026 um 07:22 Uhr)
🔧 ProgrammierungGetting started with JAX on NVIDIA GPUs(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungScale JAX models to multi-GPU systems(26.08.2026 um 21:03 Uhr)
🔧 AI Nachrichten Soccer(27.08.2026 um 17:43 Uhr)
🔧 ProgrammierungHow to build and scale multi-agent AI systems on GKE(27.08.2026 um 00:42 Uhr)
🔧 AI Nachrichten Use Your Computer and Browser(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Talk to ChatGPT Work(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Create Slides, Docs, and Templates(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Use ChatGPT Work on Your Phone(28.08.2026 um 22:51 Uhr)
🔧 AI Nachrichten Tennis (:30)(29.08.2026 um 07:22 Uhr)
🔧 AI Nachrichten Magic Manga Girl (:30)(29.08.2026 um 07:22 Uhr)
🔧 ProgrammierungGetting started with JAX on NVIDIA GPUs(26.08.2026 um 21:03 Uhr)
🔧 ProgrammierungScale JAX models to multi-GPU systems(26.08.2026 um 21:03 Uhr)
🔧 AI Nachrichten Soccer(27.08.2026 um 17:43 Uhr)
🔧 ProgrammierungHow to build and scale multi-agent AI systems on GKE(27.08.2026 um 00:42 Uhr)

10 🕛 kürzlich 2 Min Lesezeit 17 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 23.6%
CVE-2020-26241
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
1.2k YouTube-Aufrufe
Securing over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a single memory corruption bug in the dominant Geth client, triggered an unintended Ethereum mainnet chain fork, causing a catastrophic 7-hour outage for major infrastructures like Infura and MetaMask. While the community now champions "client diversity" to mitigate such single points of failure, this heterogeneity introduces a new, insidious threat: subtle implementation inconsistencies across different languages and architectures that traditional testing methods fail to detect.

To fortify this multi-billion dollar foundation, we propose a novel, specification-driven differential testing framework that synergizes classical software engineering with modern AI. Unlike traditional fuzzers, our approach leverages Large Language Models (LLMs) to bridge the gap between abstract specifications and complex reality. We utilize LLMs not only to generate diverse, semantically valid test inputs (covering both EVM opcodes and Client APIs) but also to act as intelligent filters that distinguish genuine bugs from harmless semantic variations. This "dual-engine" approach allows us to identify deep logic flaws with high precision while minimizing false positives.

Our comprehensive evaluation across 11 distinct clients uncovered 98 previously unknown bugs, even including critical errors within the official Ethereum specifications themselves. The impact of our work is immediate and far-reaching: developers confirmed our findings with a greater than 90% acceptance rate, 4 vulnerabilities were assigned CNVD IDs, and our methodology has received official endorsement from the Ethereum Foundation, with specific findings escalated to core protocol management meetings. We provide not just a bug-finding approach, but a crucial safeguard for the stability of the decentralized economy.

Jie Ma | Eng.D Candidate, Beihang University; Zhongguancun Laboratory
Ningyu He | Research Assistant Professor, The Hong Kong Polytechnic University; Amber Group
Chiachih Wu | Partner & Head of Web3 Security, Amber Group
Haoyu Wang | Professor, Huazhong University of Science and Technology
Ying Gao | Associate Professor, Beihang University; Zhongguancun Laboratory
Yinliang Yue | Professor, Zhongguancun Laboratory

https://blackhat.com/asia-26/briefings/schedule/?#fortifying-the-foundation-llm-empowered-differential-testing-for-the-ethereum-infrastructure-50238
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
44 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 49%
🟡 In Evaluierung 29%
🟢 Keine Auswirkung 15%
Spannende Innovation 7%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
The Sideload 042: A Genderless Pixel Experience with Damien Wilde
1 Quelle
Even China’s done with Windows
1 Quelle
That’s It?