4 ms·
Seems that an Elements rangeproof cache bug may've gotten exploited. Fix for suspicious issue was committed just last week and attackers could've monitored the
by cypherpunks01 26d ago
Seems that an Elements rangeproof cache bug may've gotten exploited. Fix for suspicious issue was committed just last week and attackers could've monitored the public commits and exploited the bug before fix was ever pushed?
Sort of self-fulfilling prophecy if true, that's a leading theory anyhow.
fix: range proof cache bind to asset and scriptpubkey
https://github.com/ElementsProject/elements/commit/c26d719c29 https://github.com/ElementsProject/elements/commit/c26d719c2...
- solenoid0937 26d agolmao, PR description says: > Fixes a number of small issues picked up during LLM scans
- greyface- 25d agoIt appears this commit actually introduced the bug the attacker exploited by adding additional flexibility for cache key confusion via scriptPubKey. https://twitter.com/mononautical/status/2096928595432374706 https://twitter.com/mononautical/status/2096928595432374706 The mechanism reminds me of this classic AWS request signature forgery bug from 2008: https://news.ycombinator.com/item?id=401876 https://news.ycombinator.com/item?id=401876