Fun

News Feed - 2023-10-27 05:10:19

Gareth Jenkinson3 minutes agoFireblocks, UniPass wallet tackle Ethereum ERC-4337 account abstraction vulnerabilityFireblocks assists smart contract wallet UniPass to address ERC-4337 account abstraction vulnerability.12 Total viewsListen to article 0:00NewsJoin us on social networksCryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.


An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a ‘whitehat’ hacking operation.


According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of UniPass wallet by manipulating Ethereum"s account abstraction process.


As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.


Related: Account abstraction will drive a billion users from Asia to Web3: ConsenSys exec


Conventional Ethereum transactions involve two types of accounts, externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract"s code.


Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts just like an EOA.


As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to make sure only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”


According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.


Several hundred users that had the ERC-4337 module activated in their wallets were vulnerable to the attack which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds and the issue has been mitigated at an early stage.


Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a whitehat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”


Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensuring the protocol works on layer-2 solutions.


Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?# Blockchain# Security# Ethereum# Cybersecurity# DevelopersAdd reactionAdd reactionRead moreBlockchain improves charity transparency — But is it right for everyone?Blockchain companies are creating AI chatbots to help developersQ3 2023 crowned most ‘damaging’ quarter for crypto amid $700M losses: Report

News Feed

Moneygram Halts Using Ripple Due to SEC Lawsuit Over XRP Cryptocurrency
Moneygram Halts Using Ripple Due to SEC Lawsuit Over XRP Cryptocurrency Moneygram has announced that it has suspended using Ripple’s platform due to the la
Gracy Chen6 hours agoExpect new crypto regulations to follow Bitcoin ETFsWill Bitcoin ETFs attract more regulatory attention to the crypto industry? We can only hope, because many questions need to be answered.3293 Total
Geopoly Launches Alpha Version Of Blockchain-Based Game
Geopoly Launches Alpha Version Of Blockchain-Based Game press release PRESS RELEASE.Geopoly has announced the launch of a blockchain-based alpha version of the game, which will be p
Bitcoin, Ethereum Technical Analysis: BTC, ETH Lower on Saturday, as Bears Reenter the Market
Bitcoin, Ethereum Technical Analysis: BTC, ETH Lower on Saturday, as Bears Reenter the Market Bearish sentiment returned to cryptocurrency markets on Saturday, as bitcoin was once
Thailand approves personal income tax exemption for token earnings
Ezra Reguerra11 hours agoThailand approves personal income tax exemption for token earningsThe tax measures aim to promote fundraising using investment tokens and establish the country as an investment hub.1377 Total vie
David Attlee14 hours agoIMF head: CBDCs can replace cash, help financial inclusionInternational Monetary Fund managing director Kristalina Georgieva urged the public sector to “keep preparing to deploy” central bank
4-week correction for Bitcoin? Mt. Gox, Germany gov't add sell-pressure
Zoltan Vardai8 hours ago4-week correction for Bitcoin? Mt. Gox, Germany gov"t add sell-pressureBitcoin price risks a potential fall below $60,000, due to Mt. Gox repayments and Germany"s government selling its 50,000 BTC
Indian Prime Minister Modi’s Twitter Account Hacked, Bitcoin Donations Requested
Indian Prime Minister Modi"s Twitter Account Hacked, Bitcoin Donations RequestedThe verified Twitter account for Indian Prime Minister Narendra Modi’s personal website and mob
Brayden Lindrea19 hours agoFake Ledger Live app sneaks into Microsoft’s app store, $588K stolenThe $588,000 was stolen across 38 transactions, with the largest transfer totaling $81,200.23329 Total views124 Total share
DePINs to decentralize internet access and connectivity in India
Savannah Fortis10 hours agoDePINs to decentralize internet access and connectivity in IndiaWifi Dabba, an Indian internet service provider, is launching a second round of its DePIN-powered devices on the Solana network t
XRP $100 Target: Financial Expert Sheds Light On The Claim
Este artículo también está disponible en español. XRP has taken the spotlight as Linda P. Jones, a well-known figure in finance, recently sparked conversations within the
EU MiCA implementation a ‘pivotal moment’ for crypto regulations — Compliance exec
Zoltan Vardai10 hours agoEU MiCA implementation a ‘pivotal moment’ for crypto regulations — Compliance execThe European Central Bank recently joined forces with Crystal Intelligence as its blockchain analytics part