EILMELDUNGEN LIVE
📰 IT Security NachrichtenWith the Snip of a Gene, Scientists Hope To Erase High Cholesterol For Life(29.08.2026 um 23:00 Uhr)
📰 IT Security NachrichtenWhat's 88-year-old Ridley Scott Doing Now?(30.08.2026 um 00:00 Uhr)
📰 IT Security NachrichtenWhat's 88-year-old Ridley Scott Doing Now?(30.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / VirenWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning(24.08.2026 um 19:41 Uhr)
⚠️ Malware / Trojaner / VirenWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning(24.08.2026 um 19:41 Uhr)
🕵️ SicherheitslückenAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access(25.08.2026 um 10:34 Uhr)
🕵️ SicherheitslückenAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access(25.08.2026 um 10:34 Uhr)
🕵️ SicherheitslückenFrontier AI: Vulnerability Management's Systemic Revolution(25.08.2026 um 13:14 Uhr)
📰 IT Security NachrichtenWith the Snip of a Gene, Scientists Hope To Erase High Cholesterol For Life(29.08.2026 um 23:00 Uhr)
📰 IT Security NachrichtenWhat's 88-year-old Ridley Scott Doing Now?(30.08.2026 um 00:00 Uhr)
📰 IT Security NachrichtenWhat's 88-year-old Ridley Scott Doing Now?(30.08.2026 um 00:00 Uhr)
⚠️ Malware / Trojaner / VirenWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning(24.08.2026 um 19:41 Uhr)
⚠️ Malware / Trojaner / VirenWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning(24.08.2026 um 19:41 Uhr)
🕵️ SicherheitslückenAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access(25.08.2026 um 10:34 Uhr)
🕵️ SicherheitslückenAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access(25.08.2026 um 10:34 Uhr)
🕵️ SicherheitslückenFrontier AI: Vulnerability Management's Systemic Revolution(25.08.2026 um 13:14 Uhr)

10 🕛 kürzlich 2 Min Lesezeit 31 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH EPSS 23.6%
CVE-2020-26241
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
️ Im CVE-Radar öffnen
↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
1.8k YouTube-Aufrufe
Securing over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a single memory corruption bug in the dominant Geth client, triggered an unintended Ethereum mainnet chain fork, causing a catastrophic 7-hour outage for major infrastructures like Infura and MetaMask. While the community now champions "client diversity" to mitigate such single points of failure, this heterogeneity introduces a new, insidious threat: subtle implementation inconsistencies across different languages and architectures that traditional testing methods fail to detect.

To fortify this multi-billion dollar foundation, we propose a novel, specification-driven differential testing framework that synergizes classical software engineering with modern AI. Unlike traditional fuzzers, our approach leverages Large Language Models (LLMs) to bridge the gap between abstract specifications and complex reality. We utilize LLMs not only to generate diverse, semantically valid test inputs (covering both EVM opcodes and Client APIs) but also to act as intelligent filters that distinguish genuine bugs from harmless semantic variations. This "dual-engine" approach allows us to identify deep logic flaws with high precision while minimizing false positives.

Our comprehensive evaluation across 11 distinct clients uncovered 98 previously unknown bugs, even including critical errors within the official Ethereum specifications themselves. The impact of our work is immediate and far-reaching: developers confirmed our findings with a greater than 90% acceptance rate, 4 vulnerabilities were assigned CNVD IDs, and our methodology has received official endorsement from the Ethereum Foundation, with specific findings escalated to core protocol management meetings. We provide not just a bug-finding approach, but a crucial safeguard for the stability of the decentralized economy.

Jie Ma | Eng.D Candidate, Beihang University; Zhongguancun Laboratory
Ningyu He | Research Assistant Professor, The Hong Kong Polytechnic University; Amber Group
Chiachih Wu | Partner & Head of Web3 Security, Amber Group
Haoyu Wang | Professor, Huazhong University of Science and Technology
Ying Gao | Associate Professor, Beihang University; Zhongguancun Laboratory
Yinliang Yue | Professor, Zhongguancun Laboratory

https://blackhat.com/asia-26/briefings/schedule/?#fortifying-the-foundation-llm-empowered-differential-testing-for-the-ethereum-infrastructure-50238
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
144 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 52%
🟡 In Evaluierung 29%
🟢 Keine Auswirkung 14%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
The World's Busiest Spaceport Is About To Get a Lot Quieter, At Least For Now
2 Quellen
Xylitol Linked To Strokes and Heart Attacks, Study Finds
2 Quellen
As Backlash Grows, More Americans Now Oppose Automated Police License Plate Readers Than Support