Fun

News Feed - 2023-10-27 05:10:19

Gareth Jenkinson3 minutes agoFireblocks, UniPass wallet tackle Ethereum ERC-4337 account abstraction vulnerabilityFireblocks assists smart contract wallet UniPass to address ERC-4337 account abstraction vulnerability.12 Total viewsListen to article 0:00NewsJoin us on social networksCryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.


An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a ‘whitehat’ hacking operation.


According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of UniPass wallet by manipulating Ethereum"s account abstraction process.


As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.


Related: Account abstraction will drive a billion users from Asia to Web3: ConsenSys exec


Conventional Ethereum transactions involve two types of accounts, externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract"s code.


Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts just like an EOA.


As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to make sure only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”


According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.


Several hundred users that had the ERC-4337 module activated in their wallets were vulnerable to the attack which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds and the issue has been mitigated at an early stage.


Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a whitehat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”


Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensuring the protocol works on layer-2 solutions.


Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?# Blockchain# Security# Ethereum# Cybersecurity# DevelopersAdd reactionAdd reactionRead moreBlockchain improves charity transparency — But is it right for everyone?Blockchain companies are creating AI chatbots to help developersQ3 2023 crowned most ‘damaging’ quarter for crypto amid $700M losses: Report

News Feed

Fidelity Digital to Accept Bitcoin as Collateral for Cash Loans
Fidelity Digital to Accept Bitcoin as Collateral for Cash Loans Fidelity Digital says it will allow institutional customers to pledge bitcoin as collateral again
Dutch Central Bank Fines Crypto Exchange Binance $3.4 Million Citing ‘Very Serious’ Violations
Dutch Central Bank Fines Crypto Exchange Binance $3.4 Million Citing "Very Serious" Violations The Dutch central bank has fined cryptocurrency exchange Binance 3.325 million euros
Terra was a ‘house of cards’ — SEC in opening statements for civil trial
Turner Wright5 hours agoTerra was a ‘house of cards’ — SEC in opening statements for civil trialTerraform Labs co-founder Do Kwon remained in Montenegro as the SEC trial kicked off in New York on March 25.4571 Tota
Defi Lending Startup Aave Launches Permissioned Platform to Entice Financial Institutions
Defi Lending Startup Aave Launches Permissioned Platform to Entice Financial Institutions On January 5, the open-source non-custodial decentralized finance (defi) lending platform
Fintech Study Estimates 4.4 Billion Global Users Will Adopt Mobile Wallets by 2024
Fintech Study Estimates 4.4 Billion Global Users Will Adopt Mobile Wallets by 2024 According to a recently published study by Merchant Machine, mobile wallets are predicted to have
Binance founder should be jailed for 36 months, US prosecutors say
Helen Partz2 hours agoBinance founder should be jailed for 36 months, US prosecutors sayBinance founder and former CEO Changpeng Zhao is expected to be sentenced on April 30 after pleading guilty to money laundering in N
Bitcoin, Ethereum Technical Analysis: BTC Below $16,000 Amid Increased Market Volatility
Bitcoin, Ethereum Technical Analysis: BTC Below $16,000 Amid Increased Market Volatility Bitcoin slipped below $16,000 on Nov. 21, as markets continued to react to the news that th
Mastercard Launches Global Program to Help Cryptocurrency Startups Scale Their Innovations
Mastercard Launches Global Program to Help Cryptocurrency Startups Scale Their Innovations Payments giant Mastercard has launched a new, global program for crypt
Solana Price Will Complete 1,800% Surge To $4,000 With This Formation: Analyst
Este artículo también está disponible en español. Recent market price action in the past 48 hours has brought up bullish talksfor cryptocurrencies, with assets like Solan
XRP Price Explosion Above $3 Is A Matter Of When, Not If: Analyst Reveals Timeline
Este artículo también está disponible en español. A crypto analyst has made a bold prediction about the XRP price, highlighting that an explosive rise above $3 is not a m
Microstrategy CEO Advises Nigeria and Zimbabwe to Adopt Bitcoin Standard, Says BTC Is ‘Kingmaker’
Microstrategy CEO Advises Nigeria and Zimbabwe to Adopt Bitcoin Standard, Says BTC Is "Kingmaker" Microstrategy CEO Michael Saylor has suggested Nigeria and Zimbabwe issue currenci
XRP Price Prediction To $4.9: How The 1-Day 50 MA Will Drive The Next Wave
Este artículo también está disponible en español. A crypto analyst has issued a new XRP price prediction, forecasting a potential breakout that could see the prominent cr