frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Sui fobbed off my disclosure that nearly 40% of their validators are exposed

2•simonmorley•3h ago
I built a tool called PGDN.ai that analyses DeFi/L1 networks for misconfigurations, CVEs, exposed services, etc. I started with Sui because I had a contact there. I didn’t expect much from one of the largest chains. What I found was wild.

- Nearly 40% of validators are running with serious misconfigurations: open SSH, CVEs, default services, no firewalls. - The majority expose the exact Ubuntu version. They didn’t give a sausage. - I flagged multiple validators with default Apache landing pages on 80, all with a CVE. They said, "that’s by design!" - They cannot tell the difference between RPC & HTTP. - Port 2375 (usually Docker) was open - they actually just denied this.

For context: I was CTO of a crypto exchange for 4 years, and have spent 20 years in security. It's not my first rodeo as they say.

When I disclosed responsibly, their response was bizarre:

'A CVE is only exploitable if you know how to exploit it.'

They brushed it off as a "bug bounty". I was not looking for a quick buck, I was looking to help them.

After I spoke to a journalist, their comms team even told my contact not to discuss it further.

I eventually wrote up a simulated attack doc:

Full report (technical): https://github.com/pgdn-network/sui-network-report-250819 Blog (overview): https://paragraph.com/@pgdn/40percent-of-sui-validators-exposed

To me, this shows a systemic lack of security hygiene in a network securing billions of $$$. Given the right tools, an organised group could easily take Sui offline. (I am personally selling all my Sui because of this.)

So my question: is this lack of secops understanding, lack of genuine concern, or something else? I have really struggled to get this out there with my limited public "followers". Would appreciate any input!

Comments

mouse_•2h ago
51% them and send everyone's coin to burn address
simonmorley•2h ago
Quite... Also, simpler than that, don’t even need 51%! At ~33% you hit the Byzantine limit and consensus dies. And I doubt anyone running one of these validators knows what a backup is.
Fade_Dance•1h ago
>is this lack of secops understanding, lack of genuine concern, or something else?

Even if they were to path the provided list, it sounds like the problem runs deeper. In that case there's not much you can do unless you're at a higher up position within the actual org.

There's probably nothing you can realistically do (except spread the word, of course). Most pen testing just isn't that sexy. The likely result that will draw in public interest is that eventually they will have a major public security issue. It's that simple, and sometimes it's just a matter of time.

There is a chance that the biggest problems are localized at the interface between the company and public, and in that case getting the higher ups to be aware of the severity of the deficiency (both culturally and technically) could change things, but it's likely you're going to find the same thing when you climb the ladder...

simonmorley•33m ago
Yeah, exactly. It isn't. At one point, someone in their team sent me a internal DDOS audit for the sui application. And basically said "no problems". Erm.

What’s ironic is that Aptos (their supposed arch nemesis) came back clean as a whistle on our first pass. Yet it’s Sui always "out there winning" because of their massive marketing spend.

That said, I started publishing the node scores to the blockchain and someone did ask me if they should move their staked funds from one that was sub-standard.... Yes, you should.

How to Find Early Adopters

1•firstusers•26s ago•0 comments

Braess' Paradox

https://en.wikipedia.org/wiki/Braess%27_paradox
1•Jimmc414•1m ago•0 comments

Refined GitHub, a browser extension that simplifies GitHub and adds features

https://github.com/refined-github/refined-github
1•rutierut•1m ago•0 comments

Oracle 2026 Q1 Results

https://investor.oracle.com/investor-news/news-details/2025/Oracle-Announces-Fiscal-Year-2026-Fir...
1•dzonga•3m ago•1 comments

Simple Licensing: Content licensing standard for the AI-first Internet

https://rslstandard.org/
1•kkliau•3m ago•0 comments

ICE awards Clearview AI $9.2M facial recognition contract

https://www.biometricupdate.com/202509/ice-awards-clearview-ai-9-2m-facial-recognition-contract
2•Improvement•4m ago•0 comments

Aulico – Wrapping LLMs around crypto and stock markets

https://www.aulico.com
1•local_phi•5m ago•0 comments

Can filtering seawater provide for a thirsty world?

https://www.washingtonpost.com/climate-solutions/2025/09/07/desalinization-water-crisis-agricultu...
1•paulpauper•6m ago•0 comments

Show HN: Stb_JSON header only JSON parser for C/C++

1•Forgret•6m ago•0 comments

Not smarter, just better

https://film42.substack.com/p/not-smarter-just-better
1•film42•6m ago•0 comments

Twilight of the Econs?

https://www.global-developments.org/p/twilight-of-the-econs
1•paulpauper•6m ago•0 comments

'Make Me Commissioner' Review: Is Baseball Broken?

https://www.wsj.com/sports/baseball/make-me-commissioner-review-is-baseball-broken-d6988ede
1•paulpauper•7m ago•0 comments

AZ inmate filed fake documents for years, then used them to get out of prison

https://www.kjzz.org/politics/2025-09-09/az-inmate-filed-fake-documents-for-years-before-official...
2•ljosa•7m ago•0 comments

Public Schools: Make Them Private – Milton Friedman [pdf]

https://www.cato.org/sites/cato.org/files/pubs/pdf/bp023.pdf
1•mhb•8m ago•0 comments

The Memory Paradox: Why Our Brains Need Knowledge in an Age of AI

https://arxiv.org/abs/2506.11015
1•speckx•8m ago•0 comments

Bending Spoons to Buy Vimeo in $1.38B All-Cash Deal

https://www.bloomberg.com/news/articles/2025-09-10/bending-spoons-to-buy-vimeo-in-1-38-billion-al...
1•thm•9m ago•0 comments

Evolution of Human-Accelerated Neuron Type May Underly High Autism Prevalence

https://academic.oup.com/mbe/article/42/9/msaf189/8245036
1•bookofjoe•10m ago•0 comments

Performance Improvements in .NET 10

https://devblogs.microsoft.com/dotnet/performance-improvements-in-net-10/
3•benaadams•10m ago•0 comments

Leaked Ice document shows worker detained in Hyundai raid had valid visa

https://www.theguardian.com/us-news/2025/sep/10/hyundai-factory-ice-raid-legal-visa
3•garrettdreyfus•10m ago•0 comments

Lens Blur Fields. A fingerprint in every photo

https://blur-fields.github.io/
2•thinkingemote•11m ago•0 comments

The web has a new system for making AI companies pay up

https://www.theverge.com/news/775072/rsl-standard-licensing-ai-publishing-reddit-yahoo-medium
1•thm•12m ago•0 comments

Nvidia's context-optimized Rubin CPX GPUs were inevitable

https://www.theregister.com/2025/09/10/nvidia_rubin_cpx/
1•nabla9•13m ago•0 comments

JWST could expose alien biosignatures on hazy exoplanets

https://bigthink.com/starts-with-a-bang/jwst-alien-biosignatures-hazy-exoplanets/
1•elashri•13m ago•0 comments

Lofi Girl Became a Chill Beats Empire

https://www.404media.co/how-lofi-girl-became-a-chill-beats-empire/
1•beardyw•14m ago•0 comments

Test your ping worldwide from the browser

https://www.meter.net/tools/world-ping-test/
1•amazonhut•15m ago•0 comments

China stages first 'Robot Olympics' to showcase its tech ambition

https://english.elpais.com/technology/2025-08-21/china-stages-first-robot-olympics-to-showcase-it...
2•PaulHoule•15m ago•0 comments

Using technology skills for positive change

https://werd.io/using-technology-skills-for-positive-change/
1•benwerd•15m ago•0 comments

Firefox ext turns YouTube homepage into just text links

https://github.com/andrewarrow/civilian
1•fcpguru•15m ago•0 comments

AI will never be a shortcut to wisdom

https://bigthink.com/business/ai-will-never-be-a-shortcut-to-wisdom/
1•elashri•15m ago•0 comments

Why do ChatGPT and Claude's web UIs slow to a crawl during long conversations?

1•hauxir•16m ago•0 comments