Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Futures demand and ETF momentum build case for $1

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » Sepolia Incident | Ethereum Foundation Blog

    Sepolia Incident | Ethereum Foundation Blog

    Michael JohnsonBy Michael JohnsonApril 24, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    This blog post discloses a threat against the Ethereum network that was present from the Merge up until the Dencun hard fork.

    Background

    Prior to the merge, different message size limits for RPC communication were set to protect clients from denial-of-service (DOS) attacks. These limits, applied to messages received via HTTP endpoints, were carried over to the engine API, which plays a crucial role in connecting Execution and Consensus Layer clients during block production. Due to the engine API’s involvement in block production, it became possible for blocks to be produced that surpassed the RPC size limits of some clients but remained within the acceptable range for others.

    If an attacker creates a message that exceeds the size limit of the client with the lowest setting, while still adhering to the gas limit requirements, and then waits for a block to be produced, it could result in a situation where some clients regard the block as valid, while others reject it, issuing a HTTP error code “413: Content Too Large.”

    Impact

    An attacker that could craft these messages would be able to force the majority of nodes (=geth) to reject blocks that a minority would accept. These blocks would be forked away and the proposer would miss out on rewards.

    In the beginning we thought that it was only possible to create these blocks by using builders or a modified version of a client. Geth has a builtin limit of 128KB for transactions, which means that a big transaction like the one under discussion would not end up in the transaction pools of any geth node. It was however possible to still trigger the limit by having a client with a higher limit propose the block and the CL requesting validation of this proposed bigger block.

    We proposed a solution in temporarily lowering the RPC limit on all clients to the lowest value (5MB). This would make the block invalid and an attacker would be very limited in the chaos they can cause in the network since the majority of the nodes would reject their blocks.

    However on February 7th we discovered that it was possible to create a block that would hit the 5MB limit with a bunch of transactions that are below the 128KB limit and not exceed 30 million gas.

    This is a bigger issue because we realized an attacker could create a bunch of high paying transactions and send them to the network. Since he outpays everyone else in the mempool, every node (even geth nodes) would include the attack transactions in their block thus creating a block that would not be accepted by the majority of the network, resulting in a lot of forks (all being deemed valid by the minority nodes) and the chain keeps reorging over and over again.

    Later on February 7th, we came to the conclusion that everyone raising their RPC limits would be the safer alternative.

    Timeline

    • 2024-02-06 13:00: Toni (EF), Pari (EF) and Justin (Besu) try to submit a specificly grinded transaction to the network. The transaction contributes to up to 2.7 MB blocks when snappy compressed.
    • 2024-02-06 13:25: Pari receives errors from his local Geth node although the transaction should be valid.
    • 2024-02-06 15:14: Justin managed to put the transaction in a block and submitted it through the Besu client.
    • 2024-02-06 20:46: Sam (EF) alerts Pari (special thanks to mysticryuujin on X), Toni and Alex about certain Sepolia nodes struggeling.
    • 2024-02-06 21:05: Team double checks with Marius from Geth and confirms the bug.
    • 2024-02-06 21:10: The gang gets together to debug it
    • 2024-02-07 23:40: We decided for all clients to limit their RPC request limit to 5MB
    • 2024-02-07 6:40: We discovered that there might be a bigger issue and the attack can be executed with transactions less than 128KB size.
    • 2024-02-07 10:00: We decided for all clients to increase the RPC request limit.
    • 2024-02-07 21:00: The fix was merged in geth.
    • 2024-02-09: Geth was released


    While Geth was the only client affected by this bug, other clients have also updated their defaults to be safe of this attack even if gas limits are increased.
    The client teams indicated that the following updates have the safe rpc limits:

    Geth: v1.13.12

    Nethermind: v1.25.4

    Besu: 24.1.2

    Erigon: v2.58.0

    Reth: v0.1.0-alpha.18





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Michael Johnson

    Related Posts

    V1.0 Announcing the Trillion Dollar Security Initiative

    May 14, 2025

    Ethereum (ETH) sees major uptick as Pectra upgrade goes live

    May 8, 2025

    Allocation Update – Q1 2025

    May 8, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Futures demand and ETF momentum build case for $1

    Crypto May 14, 2025

    Dogecoin price has rallied this month, mirroring the performance of Bitcoin and most altcoins.  Dogecoin…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    30 Minutes of Exercise vs 100 Steps a Day: Which One is Better?

    May 16, 2021

    Quisque consectetur libero elit

    September 1, 2020

    Winter Fitness: These Poses Can Keep You Warm

    January 14, 2021

    Futures demand and ETF momentum build case for $1

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025
    9.3

    Facilisis tincidunt justo eget urna leo dapibus at

    December 19, 2020
    8.9

    Review: Denmark Proposes Corona Pass Mandate for Workers

    January 9, 2020
    8.9

    Laoreet Sed: Suscipit nec dapibus at elit

    December 19, 2020
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    8.5

    Review: How Research Could Help with Spinal Cord Injuries

    March 14, 2021
    8.9

    Review: How AI in Soccer could Predict Injuries?

    January 15, 2021
    8.9

    Review: Can Wisconsin Clinch the Big Ten West this Weekend

    January 15, 2021
    Demo
    Top Posts

    Atua AI Extends Bitcoin-Backed Infrastructure for Intelligent Enterprise Operations

    April 23, 202513 Views

    AGII Launches AI-Powered Web3 App To Advance Real-Time Decentralized Infrastructure

    April 26, 20251 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 20250 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 20250 Views
    Don't Miss

    Futures demand and ETF momentum build case for $1

    Crypto May 14, 2025

    Dogecoin price has rallied this month, mirroring the performance of Bitcoin and most altcoins.  Dogecoin…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Atua AI Extends Bitcoin-Backed Infrastructure for Intelligent Enterprise Operations

    April 23, 202513 Views

    AGII Launches AI-Powered Web3 App To Advance Real-Time Decentralized Infrastructure

    April 26, 20251 Views

    Futures demand and ETF momentum build case for $1

    May 14, 20250 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 20250 Views
    Don't Miss

    Futures demand and ETF momentum build case for $1

    Crypto May 14, 2025

    Dogecoin price has rallied this month, mirroring the performance of Bitcoin and most altcoins.  Dogecoin…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Futures demand and ETF momentum build case for $1

    May 14, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 14, 2025

    Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining

    May 14, 2025
    Recent Posts
    • Futures demand and ETF momentum build case for $1
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • Kazakhstan proposes ’70/30′ model to fund energy upgrades through crypto mining
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • David Bailey explains why Nakamoto would sell bitcoin
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.