Ravencoin could erase several days of transactions after attackers exploited a critical flaw in its software, the project said Tuesday.
The project is a small blockchain launched in 2018 from Bitcoin’s code, but built mainly for issuing and moving digital assets. Like Bitcoin, it relies on miners to add new blocks and agree on the transaction history. Its network is far smaller, however, which means a handful of mining pools can wield much more influence over which version of the chain survives when the network splits.
That concentration matters now. Two mining pools, 2Miners and RavenMiner, that together control most of Ravencoin's computing power are now rebuilding its blockchain record from just before the first one appeared, data shows, and if enough miners follow them, everything written since would be replaced.
A blockchain is a running record of transactions, written in batches called blocks and added by miners, who run banks of computers competing to produce the next one. Miners usually work in pools, combining their machines and splitting the proceeds. Whichever version of the record has the most computing power behind it is the one the network treats as real.
The consequence is simpler for a user. A payment that looked complete over the weekend could vanish from Ravencoin's record, with the coins returning to whoever sent them and the recipient left with nothing.
The exposure sits with anyone who gave something up on the strength of a payment that no longer exists. An exchange that credited a deposit and allowed the customer to withdraw against it would be left short, which is why several have stopped taking RVN in at all.
Amsterdam-based Bitvavo suspended RVN deposits and withdrawals as a precaution, citing the exploited vulnerability. South Korea's Upbit placed an investment warning on RVN across its won, bitcoin and tether markets and also stopped deposits.
The first bad block appeared at height 4,487,776 at 15:44 UTC on Aug. 7. Once the weakness had been demonstrated on the live network, others appeared to copy it and produce invalid blocks of their own. Ravencoin has since released a fix, but patching the software does not undo what is already written.
The two pools, 2Miners and RavenMiner, are building their version from block 4,487,775, the last one before the exploit. The project said it asked them to restart from a more recent point, which would put less history at risk, but they declined.
As such, RavenMiner said in a message on its website that its nodes are already running an emergency fix and mining what it called the clean chain. Blocks produced during the attack window are being discarded across the whole network, it said, so mining earnings from that period are reversed everywhere rather than only on its pool.
It has paused payouts until the chain settles, promised to cover any shortfall itself, and said earnings from before 15:44 UTC on Aug. 7 are unaffected.
Meanwhile, Ravencoin has been here before. In 2020, attackers exploited a flaw that let RVN be created beyond what the rules allowed, minting roughly 31 million extra tokens before it was fixed.
Source
This article is syndicated for educational reading. For the latest updates, visit the original publisher.
Read on coindesk.com