Hackers target cross-chain contract exploit on Ethereum PoW fork chain.
Post-Ethereum Merge proof-of-work chain ETHW has moved to quell claims that it had suffered an on-chain replay attack over the weekend.as a replay attack that took place on Sept. 16, in which attackers harvested ETHW tokens by replaying the call data of Ethereum’s proof-of-stake chain on the forked Ethereum PoW chain.
According to BlockSec, the root cause of the exploit was due to the fact that the Omni cross-chain bridge on the ETHW chain used old chainID and was not correctly verifying the correct chainID of the cross-chain message. Ethereum’s Mainnet and test networks use two identifiers for different uses, namely, a network ID and a chain ID . Peer-to-peer messages between nodes make use of network ID, while transaction signatures make use of chainID.
introduced chainID as a means to prevent replay attacks between the ETH and Ethereum Classic blockchains.. The root cause of the exploitation is that the bridge doesn't correctly verify the actual chainid of the cross-chain message.BlockSec was the first analytics service to flag the replay attack and notified ETHW, which in turn quickly rebuffed initial claims that a replay attack had been carried out on-chain.
Again this is not a transaction replay on the chain level, it is a calldata replay due to the flaw of the specific contract.
Österreich Neuesten Nachrichten, Österreich Schlagzeilen
Similar News:Sie können auch ähnliche Nachrichten wie diese lesen, die wir aus anderen Nachrichtenquellen gesammelt haben.
Ethereum (ETH) Price Analysis for September 17When can one expect a reversal of ETH? crypto Ethereum ETH $ETH cryptoexchange VitalikButerin ethereum
Weiterlesen »
Ethereum PoW Sees 'Replay' Exploit For 200 ETHW Days After Rocky Start.EthereumPoW took immediate steps to communicate the issue. The exploit did not affect the main Ethereum PoW network itself. By shauryamalwa
Weiterlesen »
Profanity tool vulnerability drains $3.3M despite 1Inch warningIf you've not yet moved your funds away from wallet addresses generated with Profanity tool, this might be your final chance to do so.
Weiterlesen »
Scam Alert: EthereumPoW (ETHW) Community Targeted by Twitter Scam CampaignMalefactors created numerous impersonating accounts to steal user data of ETHW community
Weiterlesen »