bugs – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 22 Jul 2025 01:14:54 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 bugs – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Over $3.4 billion in Ethereum lost forever due to user mistakes and contract bugs https://earlybirdsinvest.com/over-3-4-billion-in-ethereum-lost-forever-due-to-user-mistakes-and-contract-bugs/ https://earlybirdsinvest.com/over-3-4-billion-in-ethereum-lost-forever-due-to-user-mistakes-and-contract-bugs/#respond Tue, 22 Jul 2025 01:14:54 +0000 https://earlybirdsinvest.com/over-3-4-billion-in-ethereum-lost-forever-due-to-user-mistakes-and-contract-bugs/

More than 913,111 ETH has been permanently lost due to user and contract-related errors, according to Conor Grogan, a director at Coinbase.

At current prices, that amounts to approximately $3.43 billion in inaccessible assets, which represent over 0.76% of Ethereum’s total circulating supply.

Grogan highlighted several major incidents that have contributed to this significant number of irreversible ETH losses.

Lost Ethereum
Lost Ethereum (Source: X/ Grogan)

Topping the list is the Web3 Foundation, which lost 306,000 ETH due to a vulnerability in the Parity multisig wallet. The defunct Canadian crypto exchange QuadrigaCX lost 60,000 ETH through a faulty smart contract. NFT project Akutars mistakenly burned 11,500 ETH during a botched minting process.

Additionally, users have inexplicably sent over 25,000 ETH directly to burn addresses, permanently removing them from circulation.

Losses could be higher

Meanwhile, Grogan emphasized that the $3.4 billion figure is a conservative estimate.

According to him, the figure only accounts for provably inaccessible ETH, such as coins trapped in flawed contracts or burn addresses. It does not include ETH tied to lost private keys or dormant wallets from Ethereum’s early days, like Genesis wallets that haven’t moved funds in years.

He also pointed out that the figure is significantly higher when factoring in Ethereum’s destruction via the EIP-1559 burn mechanism, with more than 5.3 million ETH permanently removed from circulation. This total exceeds 5% of all ETH ever minted and represents over $23.4 billion in value.

]]>
https://earlybirdsinvest.com/over-3-4-billion-in-ethereum-lost-forever-due-to-user-mistakes-and-contract-bugs/feed/ 0 48950
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/ https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/#respond Thu, 17 Jul 2025 22:14:42 +0000 https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/

VMware

VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.

These flaws are described in the security advisory as:

  • CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
  • CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. This flaw was used by Corentin BAYET of REverse Tactics at Pwn2Own.
  • CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. Thomas Bouzerar and Etienne Helluy-Lafont of Synacktiv at Pwn2Own used this flaw.

The fourth flaw, tracked as CVE-2025-41239, received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin BAYET of REverse Tactics, who chained with CVE-2025-41237 during the hacking contest.

VMware has not provided any workarounds, and the only way to fix these vulnerabilities is to install the new versions of the software.

It should be noted that CVE-2025-41239 impacts VMware Tools for Windows, which requires a different upgrade process.

These vulnerabilities were demonstrated as zero-days during the Pwn2Own Berlin 2025 hacking contest, where security researchers collected $1,078,750 after exploiting 29 zero-day vulnerabilities.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/feed/ 0 48217