logo
  • menu
  • Markets
  • ETFs
  • Live
  • Spot
  • Futures
  • Learn
  • Sign In
  • Sign Up
  • Downloads
  • English
  • |
  • USD
  • |
Sign Up
Crypto PricesLearnLatest NewsDownloadsMarketsSpotAnnouncements
Home/
Latest News/
Industry

ZenGo Discovers 'Red Pill Attack' Vulnerability in Popular Web3 Apps

By James Dean
Mar 27, 2023
3.9 
★
★
★
★
★
★
★
★
★
★
 357 User Rating
Share

According to a blog post published by the developer of crypto wallet ZenGo, the company said it discovered a security flaw in a transaction simulation solution used by popular decentralized applications, or dApps. Dubbed a "red pill attack," the vulnerability allows malicious dApps to steal user assets based on opaque transaction approvals that are presented to and approved by users. The bug gets its name from the iconic "red pill" scene in the Matrix movie series.

"If malware can detect that it's actually executing in a simulated environment or living in the Matrix, it can behave in a benign way that tricks anti-malware solutions, only revealing it when actually executing in a real environment. A truly hostile environment."

ZenGo claims its research shows that many leading providers, including Coinbase Wallet, were at one time vulnerable to such attacks. "All vendors were very receptive to our reports," ZenGo said, "and most of them fixed their buggy implementations very quickly."

The vulnerability may be due to a programming oversight in a "special variable" in the smart contract that stores general information about blockchain functionality, such as the timestamp of the current block. However, during the simulation, ZenGo stated that the special variables did not have the correct values, and claimed that the developers "cut corners" and set them to arbitrary values.

"For example, the "COINBASE" instruction contains the address of the miner for the current block. Since there is no real block during the simulation, and thus no miner, some simulation implementations just set it to an empty address (address of all zeros)."

In a video, ZenGo developers demonstrate how a smart contract simulation on Polygon (MATIC) requiring users to send their native token in exchange for another token could be compromised by this method: "When a user actually sends a transaction on-chain, the COINBASE [Wallet] is actually filled with the non-zero address of the current miner, and the contract only receives the coins sent."

ZenGo said the bug's fix was straightforward: "Simulation needs to populate these vulnerable variables with meaningful values, rather than filling them with arbitrary values." The company showed edited screenshots of the bug bounty, apparently by Granted by Coinbase to address this issue. The Ethereum Foundation also awarded ZenGo a $50,000 grant for its research in transaction simulation.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of BitKan. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. BitKan shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. Products mentioned in this article may not be available in your region.

Related News

  • SBI’s $289M Bitbank Deal Signals Japan Crypto Consolidation

    SBI’s $289M Bitbank Deal Signals Japan Crypto Consolidation

    SBI Holdings has solidified its domestic dominance by agreeing to acquire all shares of Bitbank in a transaction valued at ¥46.7 billion ($289 million), according to the company’s official disclosure.
    Cornell Rachel
    Jun 29, 2026
  • Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco has officially filed with the U.S. Securities and Exchange Commission (SEC) to launch the Invesco Stablecoin Reserves Onchain Fund, a new vehicle designed to offer stablecoin issuers a compliant way to manage their collateral.
    Martha Grizzard
    Jun 26, 2026
  • Spark and Uniswap Target $4T Market with New FX Infrastructure

    Spark and Uniswap Target $4T Market with New FX Infrastructure

    Uniswap and the decentralized finance protocol Spark have launched a shared liquidity infrastructure designed to function as a foreign-exchange network for the growing number of stablecoin issuers.
    Wayne Ingram
    Jun 26, 2026

Latest News

Industry

Cryptocurrency

Airdrop

Markets

  • SBI’s $289M Bitbank Deal Signals Japan Crypto Consolidation

    SBI’s $289M Bitbank Deal Signals Japan Crypto Consolidation

    SBI Holdings has solidified its domestic dominance by agreeing to acquire all shares of Bitbank in a transaction valued at ¥46.7 billion ($289 million), according to the company’s official disclosure.
    Cornell Rachel
    Jun 29, 2026
  • Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco has officially filed with the U.S. Securities and Exchange Commission (SEC) to launch the Invesco Stablecoin Reserves Onchain Fund, a new vehicle designed to offer stablecoin issuers a compliant way to manage their collateral.
    Martha Grizzard
    Jun 26, 2026
  • Spark and Uniswap Target $4T Market with New FX Infrastructure

    Spark and Uniswap Target $4T Market with New FX Infrastructure

    Uniswap and the decentralized finance protocol Spark have launched a shared liquidity infrastructure designed to function as a foreign-exchange network for the growing number of stablecoin issuers.
    Wayne Ingram
    Jun 26, 2026
  • Ethereum Foundation to Cut Budget by 40% in Major Restructuring

    Ethereum Foundation to Cut Budget by 40% in Major Restructuring

    The Ethereum Foundation (EF) has announced a comprehensive reorganization that includes a 40% reduction in its 2026 budget and a 20% cut to its workforce, signaling a shift toward a leaner, endowment-style operational model for the blockchain ecosystem.
    Wayne Ingram
    Jun 25, 2026
  • Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    The Japan Financial Services Agency (JFSA) approved RLUSD under the Payment Services Act.
    Wayne Ingram
    Jun 25, 2026
View more data 
BTCBTC(BTC)
$0
--(Last 24h)
SpotFutures

Top

View more
  1. 1S&P 500 Reclaims 200-Day Moving Average, Bitcoin Gains
  2. 2Trump Softens His Stance on Reciprocal Tariffs, US Stocks and Crypto Markets Rise
  3. 3Vitalik Buterin : The current price of ETH has not been affected by the merger event
  4. 4Vibhu Norby : Solana Spaces store to bring 100K people to Solana per month
  5. 5CZ: compared with the record high nine months ago, the current situation of the industry is much better

Top Gainers

View more
Checkmate
CheckmateCHECK

$0.0382

+50.16%
RSK Infrastructure Framework
RSK Infrastructure FrameworkRIF

$0.0885

+23.09%
MemeCore
MemeCoreM

$0.7169

+22.53%
Gensyn
GensynAIGENSYN

$0.0345

+21.12%
Sleepless AI
Sleepless AIAI

$0.0242

+18.63%

Top Trending

View more
Stellar
StellarXLM

$0.1842

+4.30%
INFINIT
INFINITIN

$0.0697

-43.78%
Dogecoin
DogecoinDOGE

$0.0719

-2.69%
Filecoin
FilecoinFIL

$0.7150

-2.99%
Synapse
SynapseSYN

$0.5679

+5.07%

Recently added

View more
Cap
CapCAP

$0.0279

+2.61%
The Black Bull
The Black BullANSEM

$0.1369

+11.01%
Nesa
NesaNES

$0.1707

-8.96%
Arcium
ArciumARX

$0.2488

-10.12%
Ambire AdEx
Ambire AdExADX

$0.0508

-8.63%

Learn

View more
  1. 1Crypto Trading Bots: What Are They and How Do They Work?
  2. 2What Are Appchains? How Do Application-Specific Blockchains Work?
  3. 3What Is Chain Abstraction? What Are the Advantages and Challenges?
  4. 4What Are Intent-Based Transactions? How Do They Work?
  5. 5What Are Modular Blockchains? How Do They Scale Networks?
About Us
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
English
About Us
+
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
+
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
+
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
+
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
+
  • Twitter
  • Facebook
  • Telegram
  • YouTube
  • Instagram
  • Medium
  • Linkedin
@2012-2026 BITKAN.com