follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here

Author Topic: Ethereum Token Hit by Malicious Minting Attack  (Read 1451 times)

Offline ayatoslaw

  • Legendary
  • *
  • *
  • *
  • *
  • Activity: 2060
  • points:
    27118
  • Karma: 86
  • Trade Count: (0)
  • Referrals: 12
  • Last Active: March 30, 2024, 10:52:29 AM
    • View Profile

  • Total Badges: 24
    Badges: (View All)
    Fifth year Anniversary Fourth year Anniversary 10 Posts
Ethereum Token Hit by Malicious Minting Attack
« on: November 22, 2018, 04:56:03 PM »
Ethereum Smart contract and dApp developer Level K has uncovered the existence of a vulnerability within the Ethereum framework that potentially allows bad actors to mint large amounts of GasToken when receiving ETH.

In a blogpost published on November 21, the company revealed that the weakness has been flagged to most at-risk exchanges who have since effected software patches to contain the threat.

Potential GasToken Security Weakness
The vulnerability arises when ETH is sent to an address, which is then able to carry out arbitrary computations that the transaction originator pays for, which comes with a risk of ‘griefing’ – an action by a bad-faith actor designed to cause damage to network users. In theory, an attacker would be able to make a transaction originator such as an exchange pay for an arbitrary amount of computation if the exchange has no protections like gas limits in place.

By minting vast amounts of GasToken while receiving ETH, it would thus be possible at least in theory for such a griefing attack to become profitable to a bad actor.

What is more, the risk is not limited to ETH, but also includes all Ethereum-based tokens such as those built on ERC-721 and ERC-20 standards. In the course of carrying out contract calls to effect transfers, exchanges that do not set a gas limit for transactions with these tokens can end up paying for vast amounts of computation and suffering  similar fate.

An excerpt from material published by Level K explaining the threat using a hypothetical case study reads as follows:

“In the simplest exploit scenario, Alice runs an exchange, which Bob wants to harm. Bob can initiate withdrawals to a contract address he controls with a computationally intensive fallback function. If Alice has neglected to set a reasonable gas limit, she will pay transaction fees out of her hot wallet. Given enough transactions, Bob can drain Alice’s funds. If Alice fails to enforce Know Your Customer (KYC) policies, Bob can create numerous accounts to circumvent single-account withdrawal limits. In addition, if Bob also wants to make a profit, he can mint GasToken in his fallback function, and make money while causing Alice’s wallet to drain.”

According to Level K, exchanges potentially affected by the vulnerability were notified privately on November 13, and because it was not possible to say exactly which ones had no protections in place, this notification was sent to as many exchanges as possible, all of whom have now implemented patches to fix the problem.

source: https://www.ccn.com/ethereum-token-hit-by-malicious-minting-attack/

Altcoins Talks - Cryptocurrency Forum

Ethereum Token Hit by Malicious Minting Attack
« on: November 22, 2018, 04:56:03 PM »

This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here Ads bidding Bidding Open


 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod