Security Scanner Found 2022 Wormhole $325M Bug, Missed Cashio $52M Flaw in Replay Test
A security team ran their static analysis scanner against the pre-hack source code of two Solana protocols — Wormhole and Cashio — without prior knowledge of the vulnerabilities, publishing both results including the failure. For Wormhole's February 2022 breach, the scanner correctly identified within seven minutes the unverified instructions sysvar account that allowed attackers to forge guardian signatures and mint $325M in wrapped ETH from nothing. On the Cashio protocol, exploited for $52M in March 2022, the tool flagged a related symptom but missed the actual root cause. The team stressed these were 2026 re-runs on long-patched, publicly known code and made no claim the tool would have prevented either real-world incident. Of five total Wormhole findings, only two were rated genuinely valid after manual verification, highlighting that raw scanner output requires careful human review to separate real risks from false positives.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in