{"id":36318,"date":"2022-09-21T07:33:13","date_gmt":"2022-09-21T11:33:13","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=36318"},"modified":"2022-09-21T07:33:17","modified_gmt":"2022-09-21T11:33:17","slug":"ethereum-network-fee-slash-plan-faces-new-obstacle","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/ethereum-network-fee-slash-plan-faces-new-obstacle\/","title":{"rendered":"Ethereum Network Fee Slash Plan Faces New Obstacle"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-because-of-the-flaw-attackers-could-have-taken-all-of-the-ether-that-was-put-into-arbitrum-nitro\">Because of the flaw, attackers could have taken all of the ether that was put into <a href=\"https:\/\/www.google.com\/search?q=Arbitrum+Nitro&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">Arbitrum Nitro<\/a>.<\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"744\" height=\"520\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/image-115.png\" alt=\"Ethereum Network Fee Slash Plan Faces New Obstacle\" class=\"wp-image-36320\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/image-115.png 744w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/image-115-300x210.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/image-115-150x105.png 150w\" sizes=\"(max-width: 744px) 100vw, 744px\" \/><figcaption>Ethereum Network Fee Slash Plan Faces New Obstacle<\/figcaption><\/figure>\n\n\n\n<p>In their rush to find a way to lower transaction costs on the <a href=\"https:\/\/coinscreed.com\/staging\/ethereum-blockchain-generates-10-7-billion-year.html\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum blockchain<\/a>, the developers of the scaling tool Arbitrum missed a change in the latest version that would have let attackers steal all funds sent to the network.<\/p>\n\n\n\n<p>Arbitrum gave the hacker who found the flaw about 400 ether, which is worth about $53,000.<\/p>\n\n\n\n<p>The threat was found in the way transactions are sent to the network and processed. This is done with the help of a tool called a bridge, which lets users move tokens between different blockchains. One of the biggest <a href=\"https:\/\/coinscreed.com\/staging\/binance-promises-security-during-philippine-senate-hearing.html\" target=\"_blank\" rel=\"noreferrer noopener\">security risks<\/a> in crypto is now attacks on bridges, which have led to almost $1 billion being stolen in the past year.<\/p>\n\n\n\n<p>The white-hat hacker, who goes by the name 0xriptide, said in a post on Tuesday that the flaw would affect anyone who tried to move funds from Ethereum to Arbitrum Nitro, the latest version of Arbitrum.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">My bug bounty write-up on a critical vulnerability I discovered on Arbitrum Nitro which allowed an attacker to steal all incoming ETH deposits to the L1-&gt;L2 bridge<br> <a href=\"https:\/\/t.co\/WuR4RYUL3L\" target=\"_blank\">https:\/\/t.co\/WuR4RYUL3L<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><br><br>@icodeblockchain <a href=\"https:\/\/twitter.com\/samiamka2?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@samiamka2<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/Mudit__Gupta?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Mudit__Gupta<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/0xRecruiter?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@0xRecruiter<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/BowTiedCrocodil?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BowTiedCrocodil<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/BowTiedDevil?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@BowTiedDevil<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; riptide (@0xriptide) <a href=\"https:\/\/twitter.com\/0xriptide\/status\/1572051111246467074?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 20, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>0xriptide found that all transactions that came in through the bridge were sent as a message to the Delayed Inbox of the <a href=\"https:\/\/coinscreed.com\/staging\/top-7-secure-nft-blockchains-with-pros-and-cons.html\" target=\"_blank\" rel=\"noreferrer noopener\">Arbitrum blockchain<\/a>. This ran a check to see if the contracts behind those transactions were either in the process of being completed or had already been completed.<\/p>\n\n\n\n<p>0xriptide found that slots that were supposed to hold data were empty because a Nitro function that was supposed to check the transactions changed the data on its own. That would have let a bad guy change the bridge's smart contract, which is open-source software and can be changed by anyone, to use their own address as a receiver address.<\/p>\n\n\n\n<p>With just one line of code, no one would have been able to change the important contract. It was taken away, though, to make transactions cheaper, and the security hole it opened up wasn't noticed, 0xriptide said.<\/p>\n\n\n\n<p>&#8220;The biggest deposit recorded on the inbox contract was 168,000 ETH, which is about $250 million.&#8221; The average amount of <a href=\"https:\/\/coinscreed.com\/staging\/kyber-compensates-affected-wallet-as-it-curbs-attack.html\" target=\"_blank\" rel=\"noreferrer noopener\">money deposited<\/a> in a 24-hour period is between 1,000 and 5,000 ETH. This means that the weakness could have led to the theft of hundreds of millions of dollars.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Because of the flaw, attackers could have taken all of the ether that was put into Arbitrum Nitro. In their rush to find a way to lower transaction costs on the Ethereum blockchain, the developers of the scaling tool Arbitrum missed a change in the latest version that would have let attackers steal all funds [&hellip;]<\/p>\n","protected":false},"author":39,"featured_media":36320,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[23,9],"tags":[202,128,11478],"class_list":["post-36318","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum-news","category-tech","tag-blockchain","tag-ethereum","tag-oxriptide"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/image-115.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/36318","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=36318"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/36318\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/36320"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=36318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=36318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=36318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}