Fireblocks, UniPass Wallet tackle Ethereum ERC-4337 account abstraction vulnerability

0

[ad_1]

Cryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.

An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a white hat hacking operation.

According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process.

As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.

Related: Account abstraction will drive a billion users from Asia to Web3: Consensys exec

Conventional Ethereum transactions involve two types of accounts: externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract’s code.

Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts, just like an EOA.

As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to ensure that only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:

“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”

According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.

Several hundred users who had the ERC-4337 module activated in their wallets were vulnerable to the attack, which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds, and the issue has been mitigated at an early stage.

Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a white hat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:

“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”

Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensure the protocol works on layer-2 solutions.

Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,368.00
ethereum
Ethereum (ETH) $ 2,961.78
tether
Tether (USDT) $ 0.999342
bnb
BNB (BNB) $ 848.94
xrp
XRP (XRP) $ 1.88
usd-coin
USDC (USDC) $ 0.999758
tron
TRON (TRX) $ 0.283504
staked-ether
Lido Staked Ether (STETH) $ 2,960.61
dogecoin
Dogecoin (DOGE) $ 0.130734
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
cardano
Cardano (ADA) $ 0.364699
whitebit
WhiteBIT Coin (WBT) $ 57.02
bitcoin-cash
Bitcoin Cash (BCH) $ 582.01
wrapped-steth
Wrapped stETH (WSTETH) $ 3,619.65
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,319.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,217.91
usds
USDS (USDS) $ 0.999552
wrapped-eeth
Wrapped eETH (WEETH) $ 3,210.85
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999453
chainlink
Chainlink (LINK) $ 12.32
monero
Monero (XMR) $ 439.65
leo-token
LEO Token (LEO) $ 8.05
weth
WETH (WETH) $ 2,961.42
stellar
Stellar (XLM) $ 0.217147
zcash
Zcash (ZEC) $ 417.27
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,374.00
ethena-usde
Ethena USDe (USDE) $ 0.998591
litecoin
Litecoin (LTC) $ 76.66
hyperliquid
Hyperliquid (HYPE) $ 24.38
sui
Sui (SUI) $ 1.44
avalanche-2
Avalanche (AVAX) $ 12.19
susds
sUSDS (SUSDS) $ 1.09
hedera-hashgraph
Hedera (HBAR) $ 0.111335
dai
Dai (DAI) $ 0.999829
shiba-inu
Shiba Inu (SHIB) $ 0.000007
usdt0
USDT0 (USDT0) $ 0.999224
paypal-usd
PayPal USD (PYUSD) $ 0.999985
uniswap
Uniswap (UNI) $ 6.01
crypto-com-chain
Cronos (CRO) $ 0.095115
world-liberty-financial
World Liberty Financial (WLFI) $ 0.132196
the-open-network
Toncoin (TON) $ 1.45
mantle
Mantle (MNT) $ 1.08
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
canton-network
Canton (CC) $ 0.085910
polkadot
Polkadot (DOT) $ 1.76
usd1-wlfi
USD1 (USD1) $ 0.998835
bitget-token
Bitget Token (BGB) $ 3.44
rain
Rain (RAIN) $ 0.006942
aave
Aave (AAVE) $ 154.17
tether-gold
Tether Gold (XAUT) $ 4,488.61
Shares