Trading ETHPoW tokens could open users to risk of losing Mainnet $ETH

2022-9-10 18:11

Warning: There is a risk of relay attacks on individual users’ wallets if the ETHPoW ChainID is not updated as planned. Such attacks will cause users to lose $ETH equivalent to the ETHPoW sold.

Recent concerns over The Merge were exacerbated after discovering that the Ethereum proof-of-work chain had not updated its ChainID to a unique number. The team behind ETHPoW updated its GitHub on Friday morning to state that it would use the ChainID ‘10001’ after the Merge.

However, the team asserted that the ChainID would remain at ‘1’ (the same as Ethereum Mainnet) until the day of The Merge in response to Coinbase requesting it be updated.

“The code you mentioned in the above comments has to keep because chainID 1 is needed to validate chain data for blocks before the merge, and all chain data after the merge will be chainID 10001.”

Should ETHPoW retain the same ChainID and nonce as Mainnet, users could risk losing funds when they try to trade any ETHPoW tokens they may receive.

CryptoSlate spoke to Temoc Webber and Igor Mandrigin, CEO and CTO of Gateway.fm respectively about the potential for relay attacks through the ETHPoW chain. Gateway.fm is a web3 infrastructure company focused on building decentralized RPC solutions that do not rely on centralized services such as AWS.

During the conversation, Mandrigin stated that there is “no reason” for the ETHPoW team not to update the code before The Merge. “They could fork it today,” he asserted before suggesting a simple solution:

“You could simply add some code that allows ETHPoW to use ChainID until the TTD of The Merge is reached and then automatically revert to a ChainID of ‘10001.’”

Adding a few simple lines of code would allow the Ethereum community to relax, knowing that ETHPoW is not preparing to create chaos on Mainnet post-merge. However, the opposite appears to be confirmed as a core Ethereum developer, Lefteris Karapetsas, was blocked by EthereumPoW’s Twitter account after pointing out the issues with not changing the ChainID in good time.

Pointing out that ETHPoW are incompetent and will cause people to lose funds gets you blocked.

All you need to know about that chain. Use them at your peril. https://t.co/E1SBpSb5ux pic.twitter.com/CYUZL5Ye1Y

— Lefteris Karapetsas | Hiring for @rotkiapp (@LefterisJP) September 9, 2022

If the ChainID and nonce of ETHPoW are not updated, then any trades that occur on the ETHPoW chain could be replicated on Mainnet. Here is an example of how this could be exploited.

A malicious actor sets up an empty upgradeable proxy smart contract on Ethereum Mainnet prior to The Merge. After The Merge, the malicious actor upgrades the ETHPoW smart contract to allow users to sell their ETHPoW at a premium of $500 per ETHPoW. On Ethereum Mainnet, the malicious actor upgrades the smart contract to send any ETH it receives to Tornado Cash. The ETHPoW smart contract is marketed as the best DEX to trade ETHPoW, and users sell their ETHPoW for USDT for $500 per ETHPoW. The trade also goes through on the Ethereum Mainnet, given that the same ChainID, nonce, and private keys are identical. However, the Mainnet contract has been updated to send the ETH to Tornado Cash and not return any USDT. The user now has USDT on ETHPoW and nothing in their Mainnet wallet. Given that USDT does not support ETHPoW, the user has essentially been rugged of their ETHPoW and ETH. A word of warning for anyone planning to dump any ETHPoW tokens they receive after The Merge.

Pay attention to whether the ChainID of ETHPoW has been updated before you transact. The ChainID should NOT be ‘1’ but ‘10001.’ If the ChainID is ‘1’, you risk losing funds from your Mainnet Ethereum wallet.

The post Trading ETHPoW tokens could open users to risk of losing Mainnet $ETH appeared first on CryptoSlate.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

RiskCoin (RISK) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 RISK

risk users ethpow trading mainnet eth losing

risk users → Результатов: 126


Crypto transaction monitoring platform Merkle Science adds support for 1200+ ERC20 tokens

Merkle Science, a predictive crypto risk and intelligence platform, announced it has now extended support to over 1,2000 ERC-20 tokens. This additional coverage allows users to have better visibility over a substantial portion of the DeFi space, allowing them to monitor flows of funds across some of the most popular DeFi tokens and stablecoins.

2022-5-20 04:59


India-based crypto exchange CoinDCX beefs up AML protection with Solidus Labs

CoinDCX, the popular India-based crypto exchange, announced today that it has selected crypto-native risk monitoring firm Solidus Labs as a strategic compliance partner. With the aim to protect its users from known forms of market abuse and emerging crypto-specific risks, partnering with Solidus will enable CoinDCX to forge greater trust and transparency on its platform.

2022-2-15 08:53


COTI Expands Staking Opportunities With Launch Of Its COTI Treasury

The COTI Treasury is finally up and running, giving community members with an appetite for greater risk more options to capitalize on their ecosystem investments. Described as an “algorithmic and decentralized $COTI pool”, the COTI Treasury will grow over time as it collects fees on all COTI ecosystem transactions, and users will have the opportunity to earn some of those rewards by staking their tokens in it.

2022-2-2 17:27


Фото:

Merkle Science adds support for Bitcoin SV to predictive transaction monitoring and intel platform

Merkle Science, a predictive blockchain monitoring and investigative platform, today announced that it has introduced support for Bitcoin SV (BSV) to its transaction monitoring coverage. From today, Merkle Science customers will be able to use the platform’s Blockchain Monitor tool; a behavior-based transaction monitoring and risk reporting solution which allows users to easily identify and respond […] The post Merkle Science adds support for Bitcoin SV to predictive transaction monitoring and intel platform appeared first on CryptoNinjas.

2021-6-18 18:17


With $1M Worth of Funding, KnitFinance Charges Ahead to Unlock Trillion Dollar Market in DeFi

KnitFinance’s objective is to enable DeFi on Multiple chains which is limited to only two at present and to reduce entry barriers and asset risk for potential users. The platform has been designed to achieve the same with an architecture that is completely decentralized and is solely dependent on user consensus for governance. Its the […]

2021-5-6 18:00


With $1M Worth of Funding, KnitFinance Charges Ahead to Unlock Trillion Dollar Market in DeFi

KnitFinance’s objective is to enable DeFi on Multiple chains which is limited to only two at present and to reduce entry barriers and asset risk for potential users. The platform has been designed to achieve the same with an architecture that is completely decentralized and is solely dependent on user consensus for governance. Its the […]

2021-5-6 17:00


Фото:

Bridge Mutual Launches IDO, Gives Users Control Over Risk Exposure

Attacks on major cryptocurrency exchanges are regrettably common. Over $200 million dollars have been lost to hacks and exploits on services such as KuCoin and, more recently, Origin Protocol. Although these events are an inescapable risk, there are new services that offer protection against loss of funds for these scenarios. Bridge Mutual is a decentralized […]

2021-1-30 12:39