Unknown attacker causes headaches during Pectra upgrade on Sepolia


An atherium developer says that the recent pectra of the sepolia testnet went into upgrade errors, which an attacker made worse after using a “age case” to cause mining of empty blocks.

Pactra rolled out his final Testnet, Sepolia at 7:29 am on March 5, but Ethereum Developer Marius Van Der Wisden said on 8 March. Post The team immediately started looking at the error messages on their gath node and empty blocks.

The error was that the deposit contract triggers the wrong type of incident – according to the van der Wisden, a transfer event instead of the deposit.

A fix was rolled out, but van der Wisden says he missed an edge case, and an unknown user exploited it by sending 0-token transfer to the deposit address, which again triggered the error.

“After a few minutes we saw a lot of empty blocks again, so we again saw in the transaction pool and found another derogatory transaction that triggers the same edge cases,” he said.

Fork

Source: Marius van der wisden

“Earlier we thought that any of the reliable verifications made a mistake, but we quickly realized that the transaction has recently originated from a new account funded by Nal.”

The ERC -20 standard does not refuse a zero token transfer; This allows anyone, even if they are not the owners of any tokens, to move to another address, which the unknown user felt, said Van Der Wisden.

“The only way to prevent the attack will be to filter all the transactions interacting with the deposit contract. So we fixed the following private, which we deployed in some Devops nodes. ,

He said, “We suspected that the attacker was reading some of our chats, so we decided not to propagate the fix, but only update some nodes that we had controlled to get a more full block on the network,” he said.

Corn, hard forces, upgrade

Source: Marius van der wisden

By 2 pm, all nodes were updated with fix, and unknown user transactions were successfully mined.

Van Der Wisden said he never lost finally during the incident, and the issue was separated to Sepolia as they were using a token-graded deposit contract instead of the general mennet deposit contract.

Earlier, the developers tested the pectra upgrade on Holesky Testnet on 26 February, which also faced issues.

As a result, developers have decided to postpone the pectra upgrade until more testing can be done.

Connected: Ether feeling less annually but it can be a good thing: satisfaction

The Pactra Forec Network follows Denkun upgrade, which reduced the transaction fee for layer -2 network and improved the economics of atherium rollup. On 13 March 2024, Dankun Hard Fork rolled out.

The Etharium Foundation recently took a new leadership structure with two co-directions of the Foundation, Hsiao-Weang and Tomasz Stackzak, hull.

magazine: Megaeth launch can save the atherium … but at what cost?