Fun

News Feed - 2023-10-27 05:10:19

Gareth Jenkinson3 minutes agoFireblocks, UniPass wallet tackle Ethereum ERC-4337 account abstraction vulnerabilityFireblocks assists smart contract wallet UniPass to address ERC-4337 account abstraction vulnerability.12 Total viewsListen to article 0:00NewsJoin us on social networksCryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.


An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a ‘whitehat’ hacking operation.


According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of UniPass wallet by manipulating Ethereum"s account abstraction process.


As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.


Related: Account abstraction will drive a billion users from Asia to Web3: ConsenSys exec


Conventional Ethereum transactions involve two types of accounts, externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract"s code.


Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts just like an EOA.


As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to make sure only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”


According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.


Several hundred users that had the ERC-4337 module activated in their wallets were vulnerable to the attack which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds and the issue has been mitigated at an early stage.


Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a whitehat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”


Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensuring the protocol works on layer-2 solutions.


Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?# Blockchain# Security# Ethereum# Cybersecurity# DevelopersAdd reactionAdd reactionRead moreBlockchain improves charity transparency — But is it right for everyone?Blockchain companies are creating AI chatbots to help developersQ3 2023 crowned most ‘damaging’ quarter for crypto amid $700M losses: Report

News Feed

Bitcoin’s Flash Rally to $10,400 was “Fake”, Short the Cryptocurrency, Warns Renowned Trader Bollinger
Bitcoin"s Flash Rally to $10,400 was "Fake", Short the Cryptocurrency, Warns Renowned Trader BollingerLong time trader John Bollinger has warned that bitcoin’s flash rally to
Treasury Secretary Yellen Privately Lobbies Against Tax Amendment Crypto Industry Wants: Report
Treasury Secretary Yellen Privately Lobbies Against Tax Amendment Crypto Industry Wants: Report U.S. Treasury Secretary Janet Yellen has reportedly raised object
Ethereum price drops 20% in a week, but investors are still bullish
Marcel Pechman4 hours agoEthereum price drops 20% in a week, but investors are still bullishETH price fell by 20% in the past week, but futures data shows investors still believe in the bull trend.4644 Total views137 Tot
Coinbase posts $1.2B net income in Q1, surpasses entire 2023 earnings
Ana Paula Pereira2 hours agoCoinbase posts $1.2B net income in Q1, surpasses entire 2023 earningsCoinbase Q1 earnings exceeded full-year 2023 results thanks to market conditions driven by new Bitcoin ETFs.806 Total views
Canadian Regulator Alerts Police to Tweets by Coinbase and Kraken Advocating Non-Custodial Wallets
Canadian Regulator Alerts Police to Tweets by Coinbase and Kraken Advocating Non-Custodial Wallets Canada’s securities regulator has flagged tweets by Coinbase CEO Brian Arm
XRP Price Targets $13 After Completing Highest Candle Body Close In History – Details
Este artículo también está disponible en español. The XRP price ended the month of December at around $2.08 after a period of back and forth between gains and declines. A
Q2 earnings: AI sector enters flat spin as consumer disinterest in chatbots intensifies
Tristan Greene5 hours agoQ2 earnings: AI sector enters flat spin as consumer disinterest in chatbots intensifiesDespite unbridled optimism and massive spending, generative AI is still a solution looking for a problem.465
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate Following Recent Highs
Bitcoin, Ethereum Technical Analysis: BTC, ETH Consolidate Following Recent Highs Bitcoin consolidated on Jan. 16, as U.S. markets closed in celebration of the Martin Luther King J
Biggest Movers: MATIC Climbs to 5-Week High, ATOM Extends Recent Gains
Biggest Movers: MATIC Climbs to 5-Week High, ATOM Extends Recent Gains Polygon was one of Tuesday’s notable gainers, as the token rose to its highest point since mid-Septem
Bitcoin price reclaims $70K as Coinbase BTC supply hits 9-year low
Zoltan Vardai6 hours agoBitcoin price reclaims $70K as Coinbase BTC supply hits 9-year lowBitcoin supply on cryptocurrency exchange Coinbase has reached a nine-year low as BTC accumulation resumes to push price back abov
Showcase your talent: Web3 hackathon at BlockShow festival
Savannah Fortis7 hours agoShowcase your talent: Web3 hackathon at BlockShow festivalJoin the Hackathon co-organized with Epic Web3 in Hong Kong on May 8-9, 2024, as part of the BlockShow x BlockDown Festival, co-organize
5 Best Cryptocurrency to Invest In as Bitcoin Reaches $108K All-Time High & $WLFI Buys $48M $ETH
Este artículo también está disponible en español. Bitcoin is showing no signs of slowing down, and why would it? As Donald Trump, w