🔊 Update: 4337 Canonical Module v0.1.0 Bug Fix Update
TLDR; No funds at risk.
We’ve identified and addressed an issue related to the optional paymaster feature in 4337 Canonical Module v0.2.0.
🧐 Read on for details:
https://t.co/EAf3CUBqaD
Test in Prod is not passing the quorum for rPGF😢
As a core dev building OP Stack days & nights, it's a bit discouraging. Come on.
https://t.co/OahPMnXOre
@fasc1nate Technically it is more likely to Korean version of DIA not CIA because it is military based intelligence group. CIA equivalent of Korean was KCIA(now NIS), which is civil spy agency.
@ekzhang1 It may differ by culture. As an Asian, this might be rude at some point. Cuz we tend to deliver the message without revealing our identity directly. But, I haven't experienced it yet, another culture that might prefer direct conversation would like this way.
Breaking @erc4337 infra for fun
tl;dr
- erc4337 hash function is not generating consistent userOpHash
- manipulating userOp calldata can make inconsistent userOpHash
- I developed a wallet that generates same userOpHash for any userOpHash 🤯 and quite secure(but don't use it)
Disclosing the vulnerability that could have drained funds.
tl;dr
• latest commit of EIP4337Manager can be destructed but does not risk user’s fund
• 0.4.0 @safe based 4337 wallets are in risk of losing fund
• affected wallets are safely migrated
We, Superblock, raised $7.5M last week. We will accelerate the development of a new mainnet named "Over," which provides a lightweight full node to enable anyone to run their own node. "Over" will be the most secure and stable mainnet through powerful decentralization.
Last weekend, I found vulnerable signature usage in erc4337 sample contract. Since I have been approved to share this to public, here is a full thread about the detail.
TLDR; VerifyingPaymaster's deposit can be drained with various replay attacks
HEADS UP ✋ We’re back with @PhilosophiaVC
Presenting
2022–2023 Crypto Market Analysis — Part 3 🥳
This time @ORobbie taking you through…
Terra and FTX in order of events, their structural limitations and what ⛳️ to look out for in the future!
https://t.co/210eu0Vvuw