Researchers say they discovered consensus level attack on Ethereum — miners cheating the system to earn more

2022-08-08 20:58:42 By : Ms. Rita Guo

The global crypto market cap is $ with a 24-hour volume of $. The price of Bitcoin is $23,856.02 and BTC market dominance is %. The price of Ethereum is $1,770.43 and ETH market dominance is %. The best performing cryptoasset sector is Sports, which gained 7%.

The Right Place to Buy, Earn, Exchange and Borrow against Your Crypto.

At its core, the paper highlights an issue where miners can change the timestamp related to a mined block to avoid increased difficulty on the network.

Cover art/illustration via CryptoSlate

A research paper published by The Hebrew University in Israel reports having discovered the “first evidence of a consensus-level attack on a major cryptocurrency.” The paper is currently awaiting peer review but utilizes publicly available on-chain data and Ethereum’s open source codebase to affirm its conclusions.

At its core, the paper highlights an issue where miners can change the timestamp related to a mined block to avoid increased difficulty on the network. On-chain data appears to support the claim as Aviv Yaish, one of the paper’s authors, highlighted F2Pool’s block timestamps being artificially altered to improve rewards.

(9/12) Whenever F2Pool's block timestamps reach the point where mining difficulty is supposed to decrease, they artificially set them to be one second earlier. F2Pool has been executing this attack over the past two years, and the evidence has been hiding in plain sight! … pic.twitter.com/mDEG2UqXZh

— Aviv Yaish (@yaish_aviv) August 5, 2022

Ethereum is maintained through a proof-of-work consensus mechanism, which will be moved to proof-of-stake this September. However, to this point, the network appears to be susceptible to the attack identified in by The Hebrew University.

The consensus-level attack is referred to as an Uncle Maker attack within the paper in reference to the “uncle” blocks used in the exploit. Blocks within the Ethereum blockchain act as a set of records that are checked, distributed, and verified across the entire network. Uncle blocks are valid blocks that have been removed from the main chain but still receive rewards.

“The attack allows an attacker to replace competitors’ main-chain blocks after the fact with a block of its own, thus causing the replaced block’s miner to lose all transactions fees for the transactions contained within the block, which will be demoted from the main-chain.”

Miners can set a block’s timestamp within “a certain reasonable bound,” typically within a few seconds. One mining pool that was singled out in the research was F2Pool, which “in the past two years, F2Pool didn’t have even a single block with a timestamp” that matched the expected outcome. F2Pool is one of the largest Ethereum pools operating with a hashrate of 129 TH/s and generating roughly 1.5K ETH in daily rewards.

The paper also highlighted that F2Pool’s “founder has made a relatively well publicized condemnation of competing mining pools, blaming them for attacking his own mining pool” while, in reality, “F2Pool are attacking other mining pools.”

The monetary impact of the attack has not yet been officially identified, but CryptoSlate reached out Yaish who told us,

“For each successful instance of the attack, F2Pool earned 14% more from block rewards, and in addition earned all the transaction fees contained within.

We are currently attempting to give concrete estimations for both of your questions using real-world data, which will be published immediately when we have them!”

The Hebrew University has “concrete fixes for Ethereum’s protocol” and created a patch for consideration. Yaish stated in a blog post that the information was “responsibly disclosed to the Ethereum Foundation” before publication.

Liam first got into crypto by mining Dogecoin after hours at his video production company in 2013. Since then he has become a ‘blockchain maximalist’ and subsequently, a web3 strategic consultant.

Become a member of CryptoSlate Edge and access our exclusive Discord community, more exclusive content and analysis.

Disclaimer: Our writers' opinions are solely their own and do not reflect the opinion of CryptoSlate. None of the information you read on CryptoSlate should be taken as investment advice, nor does CryptoSlate endorse any project that may be mentioned or linked to in this article. Buying and trading cryptocurrencies should be considered a high-risk activity. Please do your own due diligence before taking any action related to content within this article. Finally, CryptoSlate takes no responsibility should you lose money trading cryptocurrencies.

Ethereum is a global, open-source platform for decentralized applications. Learn more

Bitcoin mining is coming under increasing fire for ecological reasons, however, data shows its environmental impact is less than that of the gold and banking sectors.

Gaurav Dubey, the CEO of TDeFi, says a cataclysmic economic meltdown could be good for cryptocurrencies.

Despite the brutal drawdown, DeFi protocols continue to run as intended, and it's this that will set it apart from CeFi going forward.

Got a story tip? Email [email protected]

Disclaimer: By using this website, you agree to our Terms and Conditions and Privacy Policy. CryptoSlate has no affiliation or relationship with any coin, business, project or event unless explicitly stated otherwise. CryptoSlate is only an informational website that provides news about coins, blockchain companies, blockchain products and blockchain events. None of the information you read on CryptoSlate should be taken as investment advice. Buying and trading cryptocurrencies should be considered a high-risk activity. Please do your own diligence before making any investment decisions. CryptoSlate is not accountable, directly or indirectly, for any damage or loss incurred, alleged or otherwise, in connection to the use or reliance of any content you read on the site.

© 2022 CryptoSlate. All rights reserved. Terms | Privacy

Please add "[email protected]" to your email whitelist.