Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
Moderate severity
GitHub Reviewed
Published
Aug 6, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Aug 5, 2022
Published to the GitHub Advisory Database
Aug 6, 2022
Reviewed
Aug 11, 2022
Last updated
Jan 27, 2023
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.
References