Cryptocurrencies

Ethereum Constantinople upgrade delayed

 

The Ethereum Constantinople update has been postponed due to possible issues in EIP 1283 discovered by ChainSecurity, a smart contract auditing research company.

As highlighted in the Ethereum Foundation’s announcement, EIP-1283 introduces cheaper gas costs for SSTORE operations, but some smart contracts (that are already part of the chain) may utilise code patterns that would make them vulnerable to a re-entrancy attack after the Constantinople upgrade took place. These smart contracts would not have been vulnerable before the Constantinople upgrade.

An unexpected attack vector

This code is vulnerable in an unexpected way. The code simulates a secure treasury sharing service, where two parties can jointly receive funds, decide on how to split them, and receive a payout if they agree. By using certain functionality, an attacker could empty such a smart contract by using a fallback function to keep siphoning funds to the attacker’s address until the contract is empty.

ChainSecurity underlined how damaging this bug could be:

“In short, the attacker just stole other people’s Ether out of the PaymentSharer contract and can continue to do so.”

The new attack vector is only possible as EIP 1283 introduces reduced gas fees for certain storage operations, meaning an attacker could have the right economic incentive to act malicious.

What happens now?

After receiving the analysis and discussing the findings internally, core Ethereum Foundation members met through a video call and decided to postpone Constantinople, according to an Ethereum Foundation blog post.

As there were certain known risks and not enough time to safely analyse all threats, a decision was reached to postpone the fork out of an abundance of caution.

The parties involved in the discussions included:

 

At the time of writing, no revised date has been set for the Constantinople upgrade to take place.

Let’s hope the Ethereum developer team can defuse the situation and get on with the roadmap, which has already been delayed a number of times.

 

Pedro Febrero

Pedro Febrero is a technologist with hands-on blockchain experience. He's the founder of Bityond, a skills-matching platform between candidates and jobs, a Blockchain Consultant for multiple projects and an Op-Ed writer for ccn.com.

Disqus Comments Loading...

Recent Posts

3DOS Launching Decentralized “Uber for 3D Printing” on Sui

Grand Cayman, Cayman Islands, 12th September 2024, Chainwire

2 weeks ago

Flipster Announces Collaboration with Tether

Warsaw, Poland, 20th August 2024, Chainwire

1 month ago

PEXX Announces Strategic Acquisition of Chain Debrief

Singapore, Singapore, 20th August 2024, Chainwire

1 month ago

Kwenta and Perennial Kickstart Arbitrum Expansion with 1.9M ARB

Grand Cayman, Cayman Islands, 26th July 2024, Chainwire

2 months ago

Ethereum could soon surpass the 3K price point

As usual, the crypto market is keeping everyone guessing what could happen next. After an…

2 months ago