TGViewer
TON Status TON Status @tonstatus · 157K subscribers
Post #80 35.8K
Critical bug detected and fixed thanks to bug bounty

It was found that no special check against "all bytes same" public keys in OpenSSL crypto.

Thus, due to the recent zeroing of the configuration key, a vulnerability has opened up.

Just now we have used this issue to yet another time update config contract storage - bytes of public key are replaced with
82b17caadb303d53c3286c06a6e1affc517d1bc1d3ef2e4489d18b873f5d7cd1 -
sha256 hash of Not a valid curve point phrase. This means that the
vulnerability is closed and no one can use the configuration key.

We thank everyone who participated in the TON bug bounty! This is an example of a bug that gets a top reward.
More from @tonstatus
  1. Aug 27, 2026Attention Mainnet validators Please vote on the network configuration adjustment. Config 3…
  2. Aug 26, 2026Mainnet Validators Please schedule time tomorrow, August 27, at 15:00 UTC to participate i…
  3. Aug 24, 2026Attention Mainnet validators Please prepare for an increased network load and ensure that…
  4. Aug 20, 2026Attention Mainnet validators This update is mandatory for validators; full node owners do…
  5. Aug 18, 2026Attention Mainnet validators Please make sure that you have updated your machines to [2026…
  6. Aug 17, 2026Mainnet Validator Software Update [v2026.08] This update is mandatory for validators; full…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →