|

Ethereum PoW sees 'replay' exploit for 200 ETHW days after rocky start

Ethereum PoW, the version of the Ethereum blockchain that continues to run on a proof-of-work (PoW) consensus mechanism, experienced a replay exploit over the weekend due to a faulty third-party contract.

Developers of Ethereum PoW were alerted of the issues and immediately took steps to rectify the problem.

The blockchain was established as a fork of the Ethereum network, which switched to a proof-of-stake (PoS) consensus mechanism on Thursday in an event known as the Merge. The PoS network now continues as Ethereum.

The replay exploit refers to the same transaction being duplicated on both chains when they’re not supposed to.

This means if a user transacted on Ethereum PoW, the same was executed on Ethereum – which eventually allows attackers to illicitly trick smart contracts into releasing tokens from one chain, even as the actual transaction was executed on another chain.

Attackers used the Omni bridge of the Gnosis network to conduct the exploit. Some 200 weighted ether (wETH) was transferred through the bridge on Saturday, and the same transaction was replayed on the PoW chain – resulting in the attacker gaining 200 ETHW, or approximately $1,600 at the time.

Faulty data from the Ethereum PoW network’s Chain ID used by a contract caused the issue, security firm BlockSec said in a tweet. A Chain ID is a set of numbers used by the browser-based crypto wallet MetaMask to sign transactions for the network. An incorrect Chain ID causes transactions to fail because users aren't connected to the correct network, rendering a network unusable.

BlockSec warned that the issue might eventually cause the balance of the chain contract deployed on the PoW chain to “be drained.”

Meanwhile, Ethereum PoW developers said in a Sunday post that the attack exploited the contract vulnerability of the bridge, and not their blockchain itself.

"We have contacted the bridge in every way and informed them of the risks," it said. "Bridges need to correctly verify the actual ChainID of the cross-chain messages," the developers wrote.

As such, the network saw glitches on its first day with users stating they weren't able to access the blockchain's servers using public information provided by Ethereum PoW. CoinDesk verified the claims and wasn't able to access Ethereum PoW’s web servers using those links provided, as reported.

ETHW tokens tumbled in the past 24 hours following the exploit, falling some 37%, and extending weekly losses to over 80%, CoinGecko data shows.

Author

CoinDesk Analysis Team

CoinDesk is the media platform for the next generation of investors exploring how cryptocurrencies and digital assets are contributing to the evolution of the global financial system.

More from CoinDesk Analysis Team
Share:

Markets move fast. We move first.

Orange Juice Newsletter brings you expert driven insights - not headlines. Every day on your inbox.

By subscribing you agree to our Terms and conditions.

Editor's Picks

Solana dips as hawkish Fed cuts dampen market sentiment
Solana (SOL) price is trading below $130 at the time of writing on Thursday, after being rejected at the upper boundary of its falling wedge pattern. The broader market weakness following the Federal Reserve’s hawkish rate cut has added to downside momentum.
Pi Network Price Forecast: PI declines as core team offloads 2 million tokens

Pi Network (PI) edges lower by 3% at press time on Thursday, marking its fifth consecutive day of losses. A transfer of 2 million PI tokens from the liquidity reserve, part of the Pi core team wallets, bolsters the bearish sentiment.

Cardano Price Forecast: ADA flips bearish as derivatives markets flout network growth

Cardano (ADA) extends losses by 5% at press time on Thursday, following the 3% decline on the previous day and breaking the local resistance trendline. Derivatives data indicate a bearish shift in the narrative, as Open Interest and the number of active long positions decline.

Sei Price Forecast: SEI slips despite volume surge as Xiaomi partnership boosts adoption outlook

Sei (SEI) price trades in red, below $0.137 at the time of writing on Thursday, after retesting its key resistance level the previous day. Despite the pullback, on-chain data and market sentiment remain bullish.

Orange Juice Newsletter – Smart insights by real people. Every day.

A free newsletter highlighting key market trends to help traders stay a step ahead. Daily insights on the most relevant trading topics, compiled by our experts in an easy-to-read format so you never miss an important move.

Crypto Today: Bitcoin, Ethereum, XRP pare gains despite increasing hopes of upcoming Fed rate cut

Bitcoin (BTC) is steadying above $91,000 at the time of writing on Friday. Resistance at $94,150 capped recovery on Wednesday, but in the meantime, bulls have contained downside risks above $90,000.