According to the news from SlowMist, Filecoin has a "double-spending transaction" and many exchanges have closed FIL recharge channels. The SlowMist security team analyzed the relevant information and found that this was a Filecoin RBF fake recharge attack rather than a "double-spending attack". The attacker sends a low gas-feecap transaction in advance, and then replaces the original transaction (RBF transaction) by increasing the gas-premium and gas-feecap. At this time, the RBF transaction is packaged on the chain first, and the old transaction is discarded. However, due to a feature of Filecoin lotus RPC, when querying the execution status of the old transaction (using the lotus state exec-trace command or obtaining it through the REST interface Filecoin.StateGetReceipt), the execution status of the RBF transaction is returned, causing the exchange to record the two transactions repeatedly. The SlowMist security team reminds exchanges and related wallets that when depositing, they need to compare the cid in the query return result with the cid in the query, and use interfaces such as ChainGetParentMessages and ChainGetParentReceipts to query and compare to avoid duplicate deposits. Unlike the fake deposit attacks previously discovered in the SlowMist area, this attack method is more covert and is caused by the characteristics of the Filecoin node. Exchanges and related wallets should check the deposit and deposit procedures again. In addition to RBF, there are also regular To, Value, transfer type Method, and execution result ExitCode fields. If necessary, you can ask a security audit company to assist in the detection. |
<<: A man was cheated of 10 bitcoins by a fake Musk and lost $750,000
I love beauty more than power. Since ancient time...
summary Bitcoin has entered a correction phase, t...
In case you haven’t noticed, market sentiment lat...
Some women tend to have more bumpy marriages, and...
Eyes are the windows to the soul, and a person...
Last night, CCTV's "Focus Interview"...
In the first quarter of this year , the popularit...
Recently, the popularity of virtual reality has m...
Facial features can be used to predict a person...
We know that whales are the largest creatures in ...
Which palmistry is most likely to win the lottery...
We will find that in our lives, a black mole will...
As we all know, not everyone has dimples. Only a ...
The price of Bitcoin has been pulled to a new hig...
Binance founder Zhao Changpeng (CZ) posted on the...