Categories: Ethereum

Ethereum Vulnerability Could Have Ruined Many Wallets

Click here to view original web page at cryptodaily.co.uk

The Ethereum based GasToken could have seen many malicious individuals take advantage of it to drain cryptocurrency exchanges’ hot wallet or even mint new tokens in order to make a profit.

According to a recently published disclosure, the bug affects mainly digital currency exchanges that don’t set gas usage capacity on withdrawing currency. Exchanges could pay massively in gas fees to drain it wallets after someone has withdrawn tokens.

In the disclosure it states:

“In the simplest exploit scenario, Alice runs an exchange, which Bob wants to harm. Bob can initiate withdrawals to a contract address he controls with a computationally intensive fallback function. If Alice has neglected to set a reasonable gas limit, she will pay transaction fees out of her hot wallet. Given enough transactions, Bob can drain Alice’s funds.”

If cryptocurrency exchanges don’t enforce know your customer checks then it will add a malicious actor to circumvent the withdrawing capacity. Actors who are more experienced could implement a ‘tax’ on transactions and create new token for profit.

As reported by CryptoGlobe, it is worth noting that the glitch only seemed to impact those that initiate Ethereum transactions and not those who process them. With this, decentralised cryptocurrency exchanges like ForkDelta and other smart contract based exchanges which process payments started by users won’t be affected.

Currently, it is unknown how many exchanges (if any) were affected by the glitch. The researchers that caught it privately disclosed the vulnerability, which was discovered at the end of last month. This was before it made known to the public and contacted all possibly affected exchanges.

In order to make sure their funds are secure, exchanges were informed that they should integrate reasonable gas limits on withdrawals. The researchers also advised that affected platforms should potentially review their logs as ‘attacks may have co-discovered this vulnerability’.

Got more safety measures the researchers said:

“In the long term, contracts that implement ERC721, ERC777, and ERC677 should put restrictions on gas usage when making calls to unknown addresses. Alternatively, the front-end of decentralized applications that use these contracts can warn users when an unusually large amount of gas is being used.”

What are your thoughts? Let us know what you think down below in the comments!

cinerama

Illuminati, Mason, Anonymous I'll never tell. I can tell you this, global power is shifting and those who have the new intelligence are working to acquire this new force. You matter naught except to yourself, therefore prepare for the least expected and make your place in the new world order.

Disqus Comments Loading...
Share
Published by
cinerama
Tags: currency decentral decentralised decentralized eth ether exchange platform wallet

Recent Posts

  • Ethereum

Ethereum technical analysis: ETH/USD bears take over for the second day in a row

ETH/USD went down from $225.45 to $216.40 this Monday. Technical analysis shows that the bulls are attempting to come back… Read More

1 min ago
  • Ethereum

Ethereum Price Analysis: ETH Facing Uphill Task, Could Extend Losses

Ethereum price failed to surpass the $234 resistance area and trimmed gains against the US Dollar. ETH price is now… Read More

2 mins ago
  • Altcoins

Denarius – A true cryptocurrency in a sea of ICOs

In a sea of altcoins, Denarius is by far one of the more interesting, innovative blockchain projects released yet. With… Read More

13 mins ago
  • Bitcoin Business

Donald Trump’s bitcoin takedown signals global currency war

US President Donald Trump’s tweet attacking bitcoin ( BTC-USD ) highlights his increasing interest in controlling global currency markets —… Read More

6 hours ago
  • Bitcoin Business

Iran Legalizes Crypto-Mining As “Official Industry”

After weeks of uncertainty, the Iranian government’s Economic Commission has approved a mechanism of cryptocurrency mining in the country, according… Read More

6 hours ago
  • Bitcoin Business

Bullish For Bitcoin? Trump Turns Up Pressure on Federal Reserve to Cut Interest Rates

President Trump is continuing to pressure the Federal Reserve for dragging its feet on interest rate cuts. For some, such… Read More

6 hours ago

This website uses cookies. We use these cookies to collect data about your interaction with our website for the purpose of continuously improving your experience with our site. For more information we encourage you to read our privacy policy.

Read More