Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Fireblocks, UniPass Wallet tackle Ethereum ERC-4337 account abstraction vulnerability

CryptoExpert by CryptoExpert
October 27, 2023
in Ethereum News
0
Fireblocks, UniPass Wallet tackle Ethereum ERC-4337 account abstraction vulnerability
  • Facebook
  • Twitter
  • Pinterest



You might also like

Ethereum Faces $2.4K Resistance as Foundation Sells 10K ETH in OTC Market Move

$467K In Crypto Seized As Spain Cracks Down On Illegal Piracy Platform

Inside the fight to turn prediction apps into nonstop leverage casinos

Cryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.

An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a white hat hacking operation.

According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process.

As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.

okex

Related: Account abstraction will drive a billion users from Asia to Web3: Consensys exec

Conventional Ethereum transactions involve two types of accounts: externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract’s code.

Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts, just like an EOA.

As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to ensure that only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:

“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”

According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.

Several hundred users who had the ERC-4337 module activated in their wallets were vulnerable to the attack, which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds, and the issue has been mitigated at an early stage.

Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a white hat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:

“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”

Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensure the protocol works on layer-2 solutions.

Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Ethereum
CryptoExpert

CryptoExpert

Recommended For You

Ethereum Faces $2.4K Resistance as Foundation Sells 10K ETH in OTC Market Move

by CryptoExpert
April 25, 2026
0
Ethereum Faces $2.4K Resistance as Foundation Sells 10K ETH in OTC Market Move

TLDR: Ethereum trades near $2.3K, staying below the weekly 200 MA and EMA, with $2.4K acting as key resistance. CryptosRus reports the Ethereum Foundation sold 10,000 ETH OTC...

Read more

$467K In Crypto Seized As Spain Cracks Down On Illegal Piracy Platform

by CryptoExpert
April 24, 2026
0
crypto

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Spanish police made an unusual discovery during their raid — two crypto cold wallets tucked...

Read more

Inside the fight to turn prediction apps into nonstop leverage casinos

by CryptoExpert
April 23, 2026
0
New York demands $3.4B in crypto fines: Inside the fight to turn prediction apps into nonstop leverage casinos

Make CryptoSlate preferred on Top prediction market platforms, including Kalshi and Polymarket, are rushing to offer highly leveraged crypto derivatives at the exact moment state and federal authorities...

Read more

OCBC Issues Tokenized Physical Gold Fund on Ethereum and Solana

by CryptoExpert
April 22, 2026
0
OCBC Issues Tokenized Physical Gold Fund on Ethereum and Solana

The value of tokenized real-world assets on public blockchains is estimated at more than $29 billion, up more than 10% in the last 30 days.OCBC, one of Singapore’s...

Read more

Bitmine Adds 101,627 ETH in Biggest Weekly Accumulation in 4 Months

by CryptoExpert
April 21, 2026
0
Bitmine Adds 101,627 ETH in Biggest Weekly Accumulation in 4 Months

TLDR: Bitmine added 101,627 ETH last week, its fastest accumulation pace since December 15, 2025. The company now holds 4.976M ETH, equal to 4.12% of Ethereum’s total supply...

Read more
Next Post
Bitcoin beats S&P 500 in October as $40K BTC price predictions flow in

Bitcoin beats S&P 500 in October as $40K BTC price predictions flow in

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 77,685.00
ethereum
Ethereum (ETH) $ 2,315.52
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 1.43
bnb
BNB (BNB) $ 636.80
usd-coin
USDC (USDC) $ 0.999837
solana
Solana (SOL) $ 86.40
tron
TRON (TRX) $ 0.322671
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?