Skip to content

erification Request: Reported Vulnerability Disclosure (March 2026) #2471

Description

@jamesdula82

Hello
I'm reaching out to verify a security claim that's been shared with me directly, and I want to be straightforward about the full context so you have what you need to check your records.

I've been in direct communication with Arturo Cantera, founder of Prime Numbers Labs (a staking platform built on XDC — primestaking.xyz), regarding an unrelated withdrawal delay issue. During that conversation, he shared the following claims with me, which I'm now trying to independently verify:

On-chain messages he pointed me to (via XDCScan IDM):

March 22, 2026, 11:17:43 AM UTC — a transaction message reading: "XDC Security Audit — Responsible Disclosure | Prime Numbers Labs | 60 findings reported to XDC Team | Report SHA256: [60 findings reported to XDC Team | Report SHA256: f42d6f461e7bfdbfd005d26a349ed3f4a891c3fbfd13e46ba2a25ddfb75c4f78]

March 25, 2026, 09:18:52 AM UTC — a follow-up message reading: "XDC Security Audit Follow-Up | Prime Numbers Labs still has access | Vulnerability remains unpatched after responsible disclosure on 2026-03-22"

Verbal claims made directly to me in conversation, escalating over the course of the discussion:

  1. That he controlled 225-226 of what he described as 256 total nodes on the network

2)That he sent one transaction from each of those node addresses to his own wallet "to have proof"
That the access allowed him to "reorganize blocks, double-spend, and fork" the network

  1. That this capability, if discovered by someone else first, would have meant "XDC would not have existed today"

I want to be fully transparent: I have no independent way to confirm whether any of this is accurate, exaggerated, or unrelated to an actual event on your end. I'm not making an accusation — I'm trying to responsibly verify a serious claim before it factors into anything I write or share publicly.

Could you confirm:

  1. Whether XDC Network received a responsible disclosure from Prime Numbers Labs / Arturo Cantera around March 22, 2026

  2. Whether any vulnerability involving validator/node-level control was confirmed, and if so, its actual scope and severity

  3. Whether it was patched, and whether there's any public documentation (advisory, CVE, changelog) I could reference

I appreciate any clarity you can provide. Happy to share the on-chain transaction hashes directly if useful for your team to locate the records.

Thank you for your time.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions