Sunday, February 5, 2023
BitWolf
  • Home
  • Cryptocurrency
  • Blockchain
  • Nft & Metaverse
  • Market
  • Bitcoin
  • Ethereum
  • More
    • Solana
    • Litecoin
    • Dogecoin
  • Live Prices
No Result
View All Result
No Result
View All Result
BitWolf

ETHW confirms contract vulnerability exploit, dismisses replay attack claims

bitwolf by bitwolf
September 19, 2022
in Ethereum
0 0
0
Home Ethereum



Submit-Ethereum Merge proof-of-work (PoW) chain ETHW has moved to quell claims that it had suffered an on-chain replay assault over the weekend.

Sensible contract auditing agency BlockSec flagged what it described as a replay assault that occurred on Sept. 16, during which attackers harvested ETHW tokens by replaying the decision knowledge of Ethereum’s proof-of-stake (PoS) chain on the forked Ethereum PoW chain.

In response to BlockSec, the basis reason for the exploit was because of the truth that the Omni cross-chain bridge on the ETHW chain used previous chainID and was not accurately verifying the proper chainID of the cross-chain message.

Ethereum’s Mainnet and take a look at networks use two identifiers for various makes use of, specifically, a community ID and a sequence ID (chainID). Peer-to-peer messages between nodes make use of community ID, whereas transaction signatures make use of chainID. EIP-155 launched chainID as a way to forestall replay assaults between the ETH and Ethereum Traditional (ETC) blockchains.

1/ Alert | BlockSec detected that exploiters are replaying the message (calldata) of the PoS chain on @EthereumPow. The basis reason for the exploitation is that the bridge would not accurately confirm the precise chainid (which is maintained by itself) of the cross-chain message.

— BlockSec (@BlockSecTeam) September 18, 2022

BlockSec was the primary analytics service to flag the replay assault and notified ETHW, which in flip shortly rebuffed preliminary claims {that a} replay assault had been carried out on-chain. ETHW made makes an attempt to inform Omni Bridge of the exploit on the contract degree:

Had tried each method to contact Omni Bridge yesterday.

Bridges have to accurately confirm the precise ChainID of the cross-chain messages.

Once more this isn’t a transaction replay on the chain degree, it’s a calldata replay because of the flaw of the precise contract. https://t.co/bHbYR4b2AW pic.twitter.com/NZDn61cslJ

— EthereumPoW (ETHW) Official #ETHW #ETHPoW (@EthereumPoW) September 18, 2022

Evaluation of the assault revealed that the exploiter began by transferring 200 WETH by the Omni bridge of the Gnosis chain earlier than replaying the identical message on the PoW chain, netting an additional 200ETHW. This resulted within the stability of the chain contract deployed on the PoW chain being drained.

Related: Cross-chains in the crosshairs: Hacks call for better defense mechanisms

BlockSec’s evaluation of the Omni bridge supply code confirmed that the logic to confirm chainID was current, however the verified chainID used within the contract was pulled from a worth saved within the storage named unitStorage.

The group defined that this was not the proper chainID collected by the CHAINID opcode, which was proposed by EIP-1344 and exacerbated by the ensuing fork after the Ethereum Merge:

“That is in all probability because of the truth that the code is kind of previous (utilizing Solidity 0.4.24). The code works positive on a regular basis till the fork of the PoW chain.”

This allowed attackers to reap ETHW and probably different tokens owned by the bridge on the PoW chain and go on to commerce these on marketplaces itemizing the related tokens. Cointelegraph has reached out BlockSec to establish the worth extracted throughout the exploit.

Following Ethereum’s successful Merge event which noticed the sensible contract blockchain transition from PoW to PoS, a bunch of miners determined to proceed the PoW chain by a tough fork. 



Source link

Related

Tags: attackclaimsconfirmscontractdismissesETHWexploitreplayvulnerability
ShareTweetShare
bitwolf

bitwolf

Next Post
Bitcoin, Ethereum, Dogecoin Plunged Last Week But This Coin Bucked The Trend Decisively, Gaining Almost 13% – Bitcoin (BTC/USD)

Bitcoin, Ethereum, Dogecoin Plunged Last Week But This Coin Bucked The Trend Decisively, Gaining Almost 13% - Bitcoin (BTC/USD)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Bitcoin Holds Above $17K Despite DCG Uncertainty – CoinDesk

Bitcoin Holds Above $17K Despite DCG Uncertainty – CoinDesk

January 10, 2023
Bitcoin community not happy with Peter Zeihan’s criticisms on Joe Rogan podcast

Bitcoin community not happy with Peter Zeihan’s criticisms on Joe Rogan podcast

January 10, 2023
MULN Stock: Mullen Is the New Dogecoin… Without Any of the Fun

MULN Stock: Mullen Is the New Dogecoin… Without Any of the Fun

January 22, 2023
Why Polygon could play a key role in mass blockchain adoption despite MATIC’s…

Why Polygon could play a key role in mass blockchain adoption despite MATIC’s…

January 10, 2023
Trezor and Wasabi Join Forces To Make Bitcoin More Private

Trezor and Wasabi Join Forces To Make Bitcoin More Private

5
Bitcoin could become the foundation of DeFi with more single-sided liquidity pools

Bitcoin could become the foundation of DeFi with more single-sided liquidity pools

1
DOGE Proponents Express Hope And Concerns Related To Dogecoin-Ethereum Bridges

DOGE Proponents Express Hope And Concerns Related To Dogecoin-Ethereum Bridges

0
Petrousus Token Set to Top the Cryptocurrency Market Like Uniswap and Solana

Petrousus Token Set to Top the Cryptocurrency Market Like Uniswap and Solana

0
Sri Lanka against Bitcoin adoption, rejects Draper’s anti-corruption pitch

Sri Lanka against Bitcoin adoption, rejects Draper’s anti-corruption pitch

February 5, 2023
Fiat is in ‘jeopardy’ but Bitcoin, stablecoins aren’t the answer either: Ray Dalio

Fiat is in ‘jeopardy’ but Bitcoin, stablecoins aren’t the answer either: Ray Dalio

February 5, 2023
How AI can make the metaverse a more interactive space

How AI can make the metaverse a more interactive space

February 5, 2023
Tax strategies allow crypto investors to offset losses

Tax strategies allow crypto investors to offset losses

February 5, 2023

Recent News

Sri Lanka against Bitcoin adoption, rejects Draper’s anti-corruption pitch

Sri Lanka against Bitcoin adoption, rejects Draper’s anti-corruption pitch

February 5, 2023
Fiat is in ‘jeopardy’ but Bitcoin, stablecoins aren’t the answer either: Ray Dalio

Fiat is in ‘jeopardy’ but Bitcoin, stablecoins aren’t the answer either: Ray Dalio

February 5, 2023
How AI can make the metaverse a more interactive space

How AI can make the metaverse a more interactive space

February 5, 2023

Categories

  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Litecoin
  • Market & Analysis
  • Nft & Metaverse
  • Solana
  • Uncategorized

Tags

Big Binance Bitcoin Blockchain BNB BTC Cardano Coin Cointelegraph crypto Cryptocurrency Data DOGE Dogecoin ETH Ethereum Exchange eyes FTX Heres Inu Investors Latest Litecoin LTC Magazine market merge News NFT NFTs Polygon price rally Shiba SOL Solana Today token Top Trading Tweet Web3 Week XRP

© 2022 BitWolf All Rights Reserved

No Result
View All Result
  • Home
  • Cryptocurrency
  • Blockchain
  • Nft & Metaverse
  • Market
  • Bitcoin
  • Ethereum
  • More
    • Solana
    • Litecoin
    • Dogecoin
  • Live Prices

© 2022 BitWolf All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In