At Metallicus, we take immense pride in our engineering and the resilience of our infrastructure. A security researcher recently disclosed a severe vulnerability that allowed a malformed C-Chain API request to kill the MetalGo process.
After verifying the issue, we confirmed that Metal Blockchain was affected and swiftly implemented a fix. Within 24 hours, we rolled out a hotfix release to both the Tahoe testnet and mainnet core nodes, ensuring our network remains stable and secure.
Notably, this vulnerability also affects Avalanche, as we were able to reproduce the issue on their end. As of now, they have not yet patched it.
We appreciate the responsible disclosure from the researcher and remain committed to maintaining the highest standards of security as we continue building the future of blockchain banking.
More details can be found here: https://gist.github.com/tamjid0x01/9235294546954c8c4bd6bd43a541d8ee
Thank you,
— The Metallicus Engineering Team