Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Security concerns found in Ethereum L2 solution Blast: Resonance Security

Security concerns found in Ethereum L2 solution Blast: Resonance Security

Cryptopolitan2024/06/27 14:55
By:By Jai Hamid

Share link:In this post: Resonance Security reports security concerns in Ethereum L2 solution, Blast. Blast’s reliance on Lido and MakerDAO opens it up to the possibility of security breaches. Resonance advises projects to vet third-party providers or develop in-house solutions for better security control.Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent

Blast, the new Ethereum Layer 2 solution, has some security concerns, according to a research report by cybersecurity company Resonance Security . Blast has quickly gained traction in the crypto industry. It promises points, airdrops, jackpots, native staking yields, and gas revenue sharing. But Resonance says Blast should improve its security measures.

From its announcement to its launch, Blast accepted ETH deposits through a one-way bridge. This allowed users to accumulate native yield and Blast Points, promising early adopters entry into a future airdrop. 

Security concerns found in Ethereum L2 solution Blast: Resonance Security image 0 Source: L2Beat

Despite criticism from major financial backers like Paradigm, this strategy boosted Blast’s popularity. It attracted $600 million in its first week, reaching over $1 billion by January 2024. As of now, Blast’s total value locked (TVL) stands at $3.16 billion, making it the fourth-largest EVM L2.

Users can deposit ETH onto Blast in exchange for liquid L2 tokens. The deposited ETH is staked in Lido staking pools via Blast smart contracts, earning a 4% interest rate. 

For stablecoins, users bridge them to Blast for USDB, Blast’s official stablecoin, which generates yield through MakerDAO’s T-bill protocol with a 5% interest rate. USDB can be redeemed for DAI when bridged back to Ethereum.

Blast Gold is awarded to dApps built on the chain, rewarding them for using Blast-native features, and is distributed manually every 2-3 weeks or during jackpot events.

Blast inherits security concerns

According to Resonance, Blast’s reliance on third-party DeFi protocols like Lido and MakerDAO introduces potential risks. If any yield-generating pools or protocols on these platforms are compromised, the associated tokens of Blast users will also be affected. This dependence on Lido and MakerDAO’s security to protect users’ funds could lead to financial issues for Blast users.

Security concerns found in Ethereum L2 solution Blast: Resonance Security image 1 How Blast’s smart contract works. Source: L2Beat

Previously, HTX Square pointed out that Blast’s LaunchBridge contract (0x5f…a47d) is not a rollup bridge but a “custodial contract protected by a 3/5 multisig address.” Jarrod Watts of Polygon Labs also raised concerns about these multisig addresses, saying that they are newly created and their owners are unknown. 

Security concerns found in Ethereum L2 solution Blast: Resonance Security image 2 Source: Jarrod Watts

CryptoHopper questioned Blast’s claim of being an L2, stating, “Blast lacks the necessary validity proofs for an L2 state root and does not have an anti-fraud mechanism in place.” Resonance thinks Blast’s Risk Summary further corroborate these concerns.

Security concerns found in Ethereum L2 solution Blast: Resonance Security image 3 Source: L2Beat

Resonance also looked into Lido and MakerDAO’s security protocols. MakerDAO has not published a security audit of their smart contracts in three years, with some audits dating back five years. 

This is concerning because smart contracts can be susceptible to newly discovered vulnerabilities and should be audited periodically. Resonance states that a quick query for smart contract CVEs in the NIST National Vulnerability Database returned 584 records published between 2018 and 2024. While specific contracts may not be susceptible to all these CVEs, they are likely susceptible to some.

Maintaining smart contract security requires a multi-faceted approach, including pre-deployment and periodic security audits and bug bounty programs.

“Regular communication and joint security testing can also help validate these standards and improve upon them over time.”

Resonance Security

Smaller projects need to be meticulous when choosing their third-party providers. Proactively vetting third-party options for strict security standards can save projects many headaches in the long run. If third-party options do not meet a project’s required standards, developing in-house solutions might be a safer alternative. As long as the project has the resources to do so. 

This allows for complete control over the security. Forming partnerships or alliances with other projects can help collectively advocate for better security practices with larger third-party providers. A united front will have more influence than individual efforts, said Resonance.

Jai Hamid

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

The article analyzes the TGE performance of multiple blockchain projects, evaluating project performance using three dimensions: current price versus all-time high, time span, and liquidity-to-market cap ratio. Projects are then categorized into five grades: S, A, B, C, and D. Summary generated by Mars AI This summary was generated by the Mars AI model, and the accuracy and completeness of its content are still being iteratively updated.

MarsBit2025/11/28 16:26
2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

Russian households have invested 3.7 billion rubles in cryptocurrency derivatives, mainly dominated by a few large players. INTERPOL has listed cryptocurrency fraud as a global threat. Malicious Chrome extensions are stealing Solana funds. The UK has proposed new tax regulations for DeFi. Bitcoin surpasses $91,000. Summary generated by Mars AI. The accuracy and completeness of this summary are still being iteratively updated by the Mars AI model.

MarsBit2025/11/28 16:26
Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

How much is ETH really worth? Hashed provides 10 different valuation methods in one go

After taking a weighted average, the fair price of ETH exceeds $4,700.

ForesightNews 速递2025/11/28 15:05
How much is ETH really worth? Hashed provides 10 different valuation methods in one go

Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost

People tend to overestimate what can happen in two years, but underestimate what can happen in ten years.

深潮2025/11/28 14:53
Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost