Ethereum Attack | A Billion Laughs | Current Market News

in #blockchain7 years ago (edited)

ETH's Current Status

Ethereum has been taking a hit lately, as rumors of hacks spread in the Poloniex troll box, and fear of a 1-year anniversary of the DAO attack. Yesterday I reported that an ETH private key was generated accidentally, giving someone access to another person's wallet. This is a wallet problem, and akin to winning the lotto, but it still caused quite a stir. ETH is only down around 1.4% in the last 24 hours and most likely is experiencing a normal dip. In all likelihood those who are not influenced by FUD will profit by buying ETH right now.

eth_down.PNG

Ethereum Attack

Ethereum smart contracts are being tested by an apparent exploit to copy code and create many, many loops. It can be done using zero ETH, but must pay a gas price. It was described by one person as being similar to the "billion laughs" XML bomb which unpacked code until it took up all the memory. It looks like the gas has expired at the address.

Read the thread on Reddit here
Read about the vulnerability on GitHub here

It may be that this was part of a bug hunt, though it wasn't on the testnet. however, there doesn't seem to be any shortage of potential attacks, according to this site which has tested a few potential exploits.

The DAO Attack

A year ago in June, the venture capital fund, The DAO, raised $150 million only to be immediately robbed of $70 million by an attacker using a "recursive calling vulnerability." They essentially asked for the same ETH back from the DAO multiple times before the DAO could update its balance.

The problem was not with Ethereum, of course, but with the DAO application built upon it.

A note by the alleged attacker claimed:

I have carefully examined the code of The DAO and decided to participate after finding the feature where splitting is rewarded with additional ether. I have made use of this feature and have rightfully claimed 3,641,694 ether, and would like to thank the DAO for this reward.

This problem with solved by attacking the hacker, and doing a hard fork which basically un-wrote the attack, as well as with the hacker dropping the attack voluntarily.

Source 1

Please resteem & upvote if you found this interesting :D

Coin Marketplace

STEEM 0.20
TRX 0.14
JST 0.030
BTC 68854.36
ETH 3283.36
USDT 1.00
SBD 2.67