4/17 (四) 10:10 - 10:40

Pwning Blockchain for Fun and Profit: Exploiting an RCE Vulnerability in the Solana validator

Premiere: 4/17 10:10 - 10:40 

Replays: 4/17 16:10 - 16:40, 4/17 22:10 - 22:40


While extensive research has been conducted on all kinds of smart contracts, analysis of the underlying

infrastructure powering blockchains remains relatively rare, despite its far greater impact. This talk

explores a RCE vulnerability in Solana's validator, discovered during its transition to a new runtime

optimization in version 1.16. We will delve into Solana’s architecture, its runtime VM, and the evolution of

its data storage model that led to this flaw. The bug enables attackers to compromise the blockchain

entirely, allowing actions like minting tokens, exfiltrating validator keys, and ultimately achieving RCE.

Attendees will gain technical insights into the vulnerability and its exploitation process, offering insights

and guidance for future researchers.

Ginoah
講者
Anatomist Security
Co-Founder

TOPIC / TRACK
CYBERSEC GLOBAL 2025: United as One

LEVEL
進階 進階議程為對資安主題的深入探討,包含資安架構與工具、最佳實作經驗分享,以及資安策略比較,內容常有程式碼、通訊協定分析、逆向解析、實機示範等解說,適合具備經驗的資安與資訊人員。

SESSION TYPE
Live Stream Session

LANGUAGE
英文

SUBTOPIC
Blockchain
Exploit of Vulnerability
Open Source Security