EILMELDUNGEN LIVE
🔧 AI Nachrichten Wie 1200 Agents HuggingFace hacken(28.08.2026 um 15:57 Uhr)
🔧 AI Nachrichten Wie 1200 Agents HuggingFace hacken(28.08.2026 um 15:57 Uhr)
🔧 AI Nachrichten Claude Code + Codex = AI GOD MODE! (Open source + Free)(23.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Cheapest Way to Run Every Open Weight AI Coding Model!(25.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Gemini Notebook 2.0 Just Got a MASSIVE Upgrade! Full Guide!(26.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten I Gave Claude Code Control...(28.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Claude Code 2.0 MASSIVE Upgrade! (NEW UPDATE)(29.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Generate playable HTML5 games with Mistral Medium and GLM(28.08.2026 um 16:00 Uhr)
🔧 AI Nachrichten Wie 1200 Agents HuggingFace hacken(28.08.2026 um 15:57 Uhr)
🔧 AI Nachrichten Wie 1200 Agents HuggingFace hacken(28.08.2026 um 15:57 Uhr)
🔧 AI Nachrichten Claude Code + Codex = AI GOD MODE! (Open source + Free)(23.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Cheapest Way to Run Every Open Weight AI Coding Model!(25.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Gemini Notebook 2.0 Just Got a MASSIVE Upgrade! Full Guide!(26.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten I Gave Claude Code Control...(28.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Claude Code 2.0 MASSIVE Upgrade! (NEW UPDATE)(29.08.2026 um 08:15 Uhr)
🔧 AI Nachrichten Generate playable HTML5 games with Mistral Medium and GLM(28.08.2026 um 16:00 Uhr)

10 🕛 kürzlich 2 Min Lesezeit 12 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 23.6%
CVE-2020-26241
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
1.3k YouTube-Aufrufe
Securing over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a single memory corruption bug in the dominant Geth client, triggered an unintended Ethereum mainnet chain fork, causing a catastrophic 7-hour outage for major infrastructures like Infura and MetaMask. While the community now champions "client diversity" to mitigate such single points of failure, this heterogeneity introduces a new, insidious threat: subtle implementation inconsistencies across different languages and architectures that traditional testing methods fail to detect.

To fortify this multi-billion dollar foundation, we propose a novel, specification-driven differential testing framework that synergizes classical software engineering with modern AI. Unlike traditional fuzzers, our approach leverages Large Language Models (LLMs) to bridge the gap between abstract specifications and complex reality. We utilize LLMs not only to generate diverse, semantically valid test inputs (covering both EVM opcodes and Client APIs) but also to act as intelligent filters that distinguish genuine bugs from harmless semantic variations. This "dual-engine" approach allows us to identify deep logic flaws with high precision while minimizing false positives.

Our comprehensive evaluation across 11 distinct clients uncovered 98 previously unknown bugs, even including critical errors within the official Ethereum specifications themselves. The impact of our work is immediate and far-reaching: developers confirmed our findings with a greater than 90% acceptance rate, 4 vulnerabilities were assigned CNVD IDs, and our methodology has received official endorsement from the Ethereum Foundation, with specific findings escalated to core protocol management meetings. We provide not just a bug-finding approach, but a crucial safeguard for the stability of the decentralized economy.

Jie Ma | Eng.D Candidate, Beihang University; Zhongguancun Laboratory
Ningyu He | Research Assistant Professor, The Hong Kong Polytechnic University; Amber Group
Chiachih Wu | Partner & Head of Web3 Security, Amber Group
Haoyu Wang | Professor, Huazhong University of Science and Technology
Ying Gao | Associate Professor, Beihang University; Zhongguancun Laboratory
Yinliang Yue | Professor, Zhongguancun Laboratory

https://blackhat.com/asia-26/briefings/schedule/?#fortifying-the-foundation-llm-empowered-differential-testing-for-the-ethereum-infrastructure-50238
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
156 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 38%
🟡 In Evaluierung 28%
🟢 Keine Auswirkung 10%
Spannende Innovation 24%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
#121 Warum NIS 2 die Produktion verändert
1 Quelle
„Wenn du Hersteller bist, veröffentliche deine SBOM und mach sie für deine Kunden nutzbar.“ #podcast
1 Quelle
„Guckt euch an, was ihr da überhaupt laufen habt. Holt euch eine SBOM – ihr braucht ein Inventar.“