Security reminder: Beware of Filecoin RBF fake recharge attacks

Security reminder: Beware of Filecoin RBF fake recharge attacks

According to the news from SlowMist, Filecoin has a "double-spending transaction" and many exchanges have closed FIL recharge channels. The SlowMist security team analyzed the relevant information and found that this was a Filecoin RBF fake recharge attack rather than a "double-spending attack".

The attacker sends a low gas-feecap transaction in advance, and then replaces the original transaction (RBF transaction) by increasing the gas-premium and gas-feecap. At this time, the RBF transaction is packaged on the chain first, and the old transaction is discarded. However, due to a feature of Filecoin lotus RPC, when querying the execution status of the old transaction (using the lotus state exec-trace command or obtaining it through the REST interface Filecoin.StateGetReceipt), the execution status of the RBF transaction is returned, causing the exchange to record the two transactions repeatedly.

The SlowMist security team reminds exchanges and related wallets that when depositing, they need to compare the cid in the query return result with the cid in the query, and use interfaces such as ChainGetParentMessages and ChainGetParentReceipts to query and compare to avoid duplicate deposits. Unlike the fake deposit attacks previously discovered in the SlowMist area, this attack method is more covert and is caused by the characteristics of the Filecoin node. Exchanges and related wallets should check the deposit and deposit procedures again. In addition to RBF, there are also regular To, Value, transfer type Method, and execution result ExitCode fields. If necessary, you can ask a security audit company to assist in the detection.


<<:  A man was cheated of 10 bitcoins by a fake Musk and lost $750,000

>>:  CCTV: Graphics cards are still in great demand despite a 100% price increase. The market will charge as many "miners" as possible.

Recommend

What kind of women do men love?

I love beauty more than power. Since ancient time...

Glassnode: Has BTC entered a correction phase? What is the near-term outlook?

summary Bitcoin has entered a correction phase, t...

Five reasons to remain bullish on cryptocurrencies

In case you haven’t noticed, market sentiment lat...

What are the facial features of women with troubled marriages?

Some women tend to have more bumpy marriages, and...

How to resolve the problem of eyebrows pressing on eyes

Eyes are the windows to the soul, and a person...

Don’t just focus on Layer 2 airdrops, Layer 1 may be on the rise again

In the first quarter of this year , the popularit...

Is Virtual Reality (VR) Really Necessary for Bitcoin and Blockchain?

Recently, the popularity of virtual reality has m...

What kind of facial features will make women healthy and long-lived?

Facial features can be used to predict a person...

As Bitcoin plummets, what are the movements of the top Bitcoin whales?

We know that whales are the largest creatures in ...

Which palmistry is most likely to win the lottery?

Which palmistry is most likely to win the lottery...

What does a mole on the right side of a woman's neck mean?

We will find that in our lives, a black mole will...

Why are there so few women with dimples? Because they are so lucky.

As we all know, not everyone has dimples. Only a ...

Bitcoin prices are rising “with fear”

The price of Bitcoin has been pulled to a new hig...