During the past week, HC1 members discovered and investigated a critical vulnerability in the go-zenon software.
A future post will detail the exact nature of the issue, but what we can say right now is that to our knowledge it has not been exploited.
HC1 then directly contacted several bridge operators to shut down their orchestrators, without disclosing the existence of a vulnerability. This is the reason the bridge has been down.
The currently liquidity for ZNN on CEXs is under 1 USDT, so we will consider it irrelevant.
Based on our understanding, the issue can be fixed through a soft fork.
HC1 will provide instructions in an upcoming post.
We strongly urge all pillars, orchestrators, and node operators to backup their go-zenon nodes at this time.
This will help prevent your node from needing to resync from scratch if it ends up on the old chain.
For a worst case scenario, HC1 snapshotted the chain at height 10102550 on Tuesday.
Until the chain is stabilized and most pillars are patched, all transactions after 10102550 should be considered invalid and at risk of rollback.
As an immediate next step, HC1 will begin rolling out patched nodes and HC1 members will privately patch their pillars to start the soft fork.
This soft fork will function the exact same as the old chain, until someone exploits the vulnerability.
Unfortunately, once we publish the patch, we have to assume that someone will reverse engineer how to exploit the old chain.
At that point, the chain will split into two.
If you patch your node, it’s possible that your nodes will eventually join the right chain, but it’s also possible that you will need to resync.
So please take a backup asap and not when your node is already on the wrong chain.
Understandably this news is terrible to hear.
While we hope to mitigate this issue as smoothly as possible, many might question if there are any other issues that will require the same kind of response.
This is something that HC1 has considered. In an upcoming post, we will describe the long term steps that HC1 will be taking.