[MR94 & MB146] Authorize Upgrade to RT4102 on Moonriver & Moonbeam via Whitelist

Abstract - This proposal is to authorize the upgrade to runtime 4102 on both Moonriver and Moonbeam using the whitelist track.

Details - A critical vulnerability has been found in the Moonriver and Moonbeam runtimes. The OpenGov Technical Committee has voted in favor of whitelisting the authorization for the upgrade in order to get it deployed to both networks quickly.

More details surrounding the vulnerability will be shared once the fix is applied.

2 Likes

The vulnerability that was patched in this hotfix involves the ability to mint native tokens into Treasury through certain XCM transactions thereby incorrectly increasing inflation.

The vulnerability existed for many years. It was only reported recently by a white through the Moonbeam Foundation’s Immunefi Bug Bounty program.