24 Nov dApp Developer ‘Level K’ Discovers GasToken Vulnerability In Ethereum Network
[ad_1]
On Wednesday, November 23, 2018, the decentralized applications producer, Level K, published new revelations about Ethereum on their official Medium channel.
The brief report was written as a warning that the Ethereum network has a potential protocol vulnerability which could easily be exploited by hackers to harm unsuspected users, mainly cryptocurrency exchanges.
A danger for crypto exchanges
According to Level K, if an attacker was to withdraw Ether (ETH) from the exchange’s hot wallet address, he would able to do an arbitrary computation which is paid for by the owner of the wallet from which the ETH is sent (exchange’s hot wallet).
This procedure is known as grieving vector.
Provided that the cryptocurrency exchange in question doesn’t have a reasonable gas limit implemented on their platform, a hacker could perform enough transactions to generate GasToken, turning a grieving vector into a lucrative form of attack.
Since gas on the Ethereum network is paid in ETH, we can see…
[ad_2]
Source link