Sitemap

SlowMist: EOS DApp New Transaction Congestion Attack and General Defense Suggestions (Released in 2019)

3 min readMay 8, 2023
Press enter or click to view image in full size

According to the analysis of the SlowMist threat intelligence analysis system, in the early morning of January 11, 2019, EOS.WIN was attacked. The exploiter “loveforlover” of EOS.WIN adopted a new attack method “Transaction Congestion Attack”, which is the same attack method as the previous attack method on bocai.game.

The attacker first used loveforlover to initiate a normal transfer transaction, and then used another contract account to detect the winning behavior. If the attacker does not win, a large number of defer transactions will be initiated to “squeeze” the project party’s lottery transactions into the next block. This attack stems from the use of time seeds in the random number algorithm of the project party, which increases the chances of winning the prize and leads to the success of the attack.

It is worth noting that at around 2:40 a.m. on January 13, the SlowMist threat intelligence system captured a similar attack again. The attacker deployed the attack contract sil******day to target the well-known competitive game DApp FarmEOS Attack. In just 7 minutes, the attacker made a profit of more than 5,000 EOS through the Dice game, and quickly transferred the funds to the exchange. The attack method is the same as the attack method of EOS.WIN. After the attack contract sil******day bets on FarmEOS, and when the attack contract receives the transfer notification, it initiates a large number of defer transactions, so that the subsequent lottery action of FarmEOS is delayed.

The SlowMist security team has synchronized the attack information to relevant exchanges as soon as possible, and at the same time recommends that all project parties and developers do not add time seeds to the random number algorithm. At present, FarmEOS Dice has also been suspended.

In response to this new attack method of EOS DApp, the SlowMist security team gave some general defense suggestions against new or unknown attacks such as “Transaction Congestion Attack”:

  1. The random number scheme recommends adopting the random number security practice “Randomization in Contracts” officially recommended by EOS.
  2. The contract should be equipped with a complete risk control mechanism, such as setting automatic suspension when certain key thresholds are exceeded.
  3. Collect and model all the data on the contract chain, and construct the most suitable abnormal alarm notification mechanism through scenario learning.

The SlowMist security team is also continuing to build a complete set of SaaS services for EOS DApp threat discovery and threat defense, covering the three major technical links of DevSecOps. There are not only the best security development guidelines for EOS smart contracts for developers, but also EOS SkyEye and FireWall.X for operation and maintenance personnel, which are integrated to form a joint defense system that integrates on-chain and off-chain security governance.

EOS DApp is still in the early stage of rapid development. Attackers have already automated various attack methods. This is a continuous challenge for all DApps. Security is the bottom line of the project, and risk control is the bottom line of security. I hope more Participate in power, come from the community, return to the community, and jointly promote the safe development of the EOS ecology.

About SlowMist

SlowMist is a blockchain security firm established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as Huobi, OKX, Binance, imToken, Crypto.com, Amber Group, Klaytn, EOS, 1inch, PancakeSwap, TUSD, Alpaca Finance, MultiChain, O3Swap, etc.

Website:
https://www.slowmist.com
Twitter:
https://twitter.com/SlowMist_Team
Github:
https://github.com/slowmist/

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.