Bitcoin Forum
June 27, 2024, 01:40:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ethereum Token Hit by Malicious Minting Attack  (Read 101 times)
Lmaooo (OP)
Full Member
***
Offline Offline

Activity: 694
Merit: 108


santacoin.io


View Profile
November 22, 2018, 07:00:27 AM
 #1

Ethereum Smart contract and dApp developer Level K has uncovered the existence of a vulnerability within the Ethereum framework that potentially allows bad actors to mint large amounts of GasToken when receiving ETH.

In a blogpost published on November 21, the company revealed that the weakness has been flagged to most at-risk exchanges who have since effected software patches to contain the threat.

Potential GasToken Security Weakness
The vulnerability arises when ETH is sent to an address, which is then able to carry out arbitrary computations that the transaction originator pays for, which comes with a risk of ‘griefing’ – an action by a bad-faith actor designed to cause damage to network users. In theory, an attacker would be able to make a transaction originator such as an exchange pay for an arbitrary amount of computation if the exchange has no protections like gas limits in place.

By minting vast amounts of GasToken while receiving ETH, it would thus be possible at least in theory for such a griefing attack to become profitable to a bad actor.

CCN | https://www.ccn.com/ethereum-token-hit-by-malicious-minting-attack/

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!