ETHW confirms contract vulnerability exploit, dismisses replay attack claims

ETHW confirms contract vulnerability exploit, dismisses replay attack claims



Post-Ethereum Merge proof-of-work (PoW) chain ETHW has moved to quell claims that it had suffered an on-chain replay attack over the weekend.

Smart contract auditing firm BlockSec flagged what it described as a replay attack that took place on Sept. 16, in which attackers harvested ETHW tokens by replaying the call data of Ethereum’s proof-of-stake (PoS) chain on the forked Ethereum PoW chain.

According to BlockSec, the root cause of the exploit was due to the fact that the Omni cross-chain bridge on the ETHW chain used old chainID and was not correctly verifying the correct chainId of the cross-chain message.

Ethereum’s Mainnet and test networks use two identifiers for different uses, namely, a network ID and a chain ID (chainID). Peer-to-peer messages between nodes make use of network ID, while transaction signatures make use of chainID. EIP-155 introduced chainID as a means to prevent replay attacks between the ETH and ETC blockchains.

okex

BlockSec was the first analytics service to flag the replay attack and notified ETHW, which in turn quickly rebuffed initial claims that a replay attack had been carried out on-chain. ETHW made attempts to notify Omni Bridge of the exploit at the contract level:

Analysis of the attack revealed that the exploiter started by transferring 200 WETH through the Omni bridge of the Gnosis chain before replaying the same message on the PoW chain, netting an extra 200ETHW. This resulted in the balance of the chain contract deployed on the PoW chain being drained.

Related: Cross-chains in the crosshairs: Hacks call for better defense mechanisms

BlockSec’s analysis of the Omni bridge source code showed that the logic to verify chainId was present, but the verified chainID used in the contract was pulled from a value stored in the storage named unitStorage.

The team explained that this was not the correct chainId collected through the CHAINID opcode, which was proposed by EIP-1344 and exacerbated by the resulting fork after the Ethereum Merge:

“This is probably due to the fact that the code is quite old (using Solidity 0.4.24). The code works fine all the time until the fork of the PoW chain.”

This allowed attackers to harvest ETHW and potentially other tokens owned by the bridge on the PoW chain and go on to trade these on marketplaces listing the relevant tokens. Cointelegraph has reached out BlockSec to ascertain the value extracted during the exploit.

Following Ethereum’s successful Merge event which saw the smart contract blockchain transition from PoW to PoS, a group of miners decided to continue the PoW chain through a hard fork. 





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest

Crypto-Trend
Changelly
Crypto-Trend
ETHW confirms contract vulnerability exploit, dismisses replay attack claims
okex
Bybit
Optimism On The Road To Decentralization
Ethereum (ETH) Price Action Shows Strength as Bulls Target $3,800 Mark
Spot Ether ETFs End 19-Day Inflow Streak with First Outflow
Sharplink Gaming Shares Plunge Amid Looming Ether Buy
Astar First to Launch SuperchainERC20 Token with Chainlink CCIP
BTC trades at $109.7K after weekend surge; Ethereum
bitcoin
ethereum
tether
binancecoin
solana
ripple
usd-coin
staked-ether
dogecoin
binance-usd
Blockonomics
Changelly
Copy Trading Boom Creates $118 Billion ‘Financial DNA’ Market
Ripple case paused again as SEC, Ripple seek to finalise $50 million settlement
Optimism On The Road To Decentralization
Theminermag Bitcoin Mining Update: May/June 2025
EigenLayer Gets $70M From a16z to Launch Off-Chain Verifiability Platform
Copy Trading Boom Creates $118 Billion ‘Financial DNA’ Market
Ripple case paused again as SEC, Ripple seek to finalise $50 million settlement
Optimism On The Road To Decentralization
Theminermag Bitcoin Mining Update: May/June 2025
bitcoin
ethereum
tether
binancecoin
solana
ripple
usd-coin
staked-ether
dogecoin
binance-usd
bitcoin
ethereum
tether
binancecoin
solana
ripple
usd-coin
staked-ether
dogecoin
binance-usd