4 ms·
> Had the issue not been promptly resolved, malicious users on the chain could have exploited the flaw. This means a cyber actor could have gained access to the
by vinnymac 5y ago
> Had the issue not been promptly resolved, malicious users on the chain could have exploited the flaw. This means a cyber actor could have gained access to the unlimited generation of fresh ETH tokens.
I am curious, would it be easy to detect an individual who was exploiting this vulnerability?
- saurik 5y agoIn my post-mortem I go into this a bit: someone had actually triggered the bug (on accident while debugging the Etherscan block explorer) but it hadn't been noticed by anyone (and the person at Etherscan didn't realize the ramifications). I believe, due to the atypical mechanism used to store the account balance state on Optimism (which is discussed in detail in my post-mortem as this is also what I claim to be the root cause of the bug), it would have taken quite a long time to notice someone taking advantage of this issue if they weren't being egregiously ostentatious with it (and even then it would have taken "too long" before tons of extremely-difficult-or-arguably-even-impossible-to-unwind economic confusion and damage would have resulted as the whole ecosystem is so heavily automated).
- vinnymac 5y agoThanks, I only read the article linked and had not yet dug any further. I appreciate how much work you put into this! For anyone who may have missed the link in the article or thread, this is it: https://www.saurik.com/optimism.html https://www.saurik.com/optimism.html