Hello
I'm reaching out to verify a security claim that's been shared with me directly, and I want to be straightforward about the full context so you have what you need to check your records.
I've been in direct communication with Arturo Cantera, founder of Prime Numbers Labs (a staking platform built on XDC — primestaking.xyz), regarding an unrelated withdrawal delay issue. During that conversation, he shared the following claims with me, which I'm now trying to independently verify:
On-chain messages he pointed me to (via XDCScan IDM):
March 22, 2026, 11:17:43 AM UTC — a transaction message reading: "XDC Security Audit — Responsible Disclosure | Prime Numbers Labs | 60 findings reported to XDC Team | Report SHA256: [60 findings reported to XDC Team | Report SHA256: f42d6f461e7bfdbfd005d26a349ed3f4a891c3fbfd13e46ba2a25ddfb75c4f78]
March 25, 2026, 09:18:52 AM UTC — a follow-up message reading: "XDC Security Audit Follow-Up | Prime Numbers Labs still has access | Vulnerability remains unpatched after responsible disclosure on 2026-03-22"
Verbal claims made directly to me in conversation, escalating over the course of the discussion:
- That he controlled 225-226 of what he described as 256 total nodes on the network
2)That he sent one transaction from each of those node addresses to his own wallet "to have proof"
That the access allowed him to "reorganize blocks, double-spend, and fork" the network
- That this capability, if discovered by someone else first, would have meant "XDC would not have existed today"
I want to be fully transparent: I have no independent way to confirm whether any of this is accurate, exaggerated, or unrelated to an actual event on your end. I'm not making an accusation — I'm trying to responsibly verify a serious claim before it factors into anything I write or share publicly.
Could you confirm:
-
Whether XDC Network received a responsible disclosure from Prime Numbers Labs / Arturo Cantera around March 22, 2026
-
Whether any vulnerability involving validator/node-level control was confirmed, and if so, its actual scope and severity
-
Whether it was patched, and whether there's any public documentation (advisory, CVE, changelog) I could reference
I appreciate any clarity you can provide. Happy to share the on-chain transaction hashes directly if useful for your team to locate the records.
Thank you for your time.
Hello
I'm reaching out to verify a security claim that's been shared with me directly, and I want to be straightforward about the full context so you have what you need to check your records.
I've been in direct communication with Arturo Cantera, founder of Prime Numbers Labs (a staking platform built on XDC — primestaking.xyz), regarding an unrelated withdrawal delay issue. During that conversation, he shared the following claims with me, which I'm now trying to independently verify:
On-chain messages he pointed me to (via XDCScan IDM):
March 22, 2026, 11:17:43 AM UTC — a transaction message reading: "XDC Security Audit — Responsible Disclosure | Prime Numbers Labs | 60 findings reported to XDC Team | Report SHA256: [60 findings reported to XDC Team | Report SHA256: f42d6f461e7bfdbfd005d26a349ed3f4a891c3fbfd13e46ba2a25ddfb75c4f78]
March 25, 2026, 09:18:52 AM UTC — a follow-up message reading: "XDC Security Audit Follow-Up | Prime Numbers Labs still has access | Vulnerability remains unpatched after responsible disclosure on 2026-03-22"
Verbal claims made directly to me in conversation, escalating over the course of the discussion:
2)That he sent one transaction from each of those node addresses to his own wallet "to have proof"
That the access allowed him to "reorganize blocks, double-spend, and fork" the network
I want to be fully transparent: I have no independent way to confirm whether any of this is accurate, exaggerated, or unrelated to an actual event on your end. I'm not making an accusation — I'm trying to responsibly verify a serious claim before it factors into anything I write or share publicly.
Could you confirm:
Whether XDC Network received a responsible disclosure from Prime Numbers Labs / Arturo Cantera around March 22, 2026
Whether any vulnerability involving validator/node-level control was confirmed, and if so, its actual scope and severity
Whether it was patched, and whether there's any public documentation (advisory, CVE, changelog) I could reference
I appreciate any clarity you can provide. Happy to share the on-chain transaction hashes directly if useful for your team to locate the records.
Thank you for your time.