Ravencoin could roll back four days of transactions after critical block flaw

Bitcoin-linked Ravencoin falls 17% as miners move to rewrite transactions since Friday

Tech

Two mining pools controlling most of Ravencoin’s hashpower are building a replacement chain from before Friday’s first invalid block, putting deposits, withdrawals and payments made since then at risk of reversal.

By Shaurya Malwa|Edited by Oliver Knight

2min read

Share this article

A bug over a delete button. Ravencoin might erase four days of blockchain history after a critical flaw in how it processes transactions. (Shutterstock)

Summary

Ravencoin could erase several days of transactions after attackers exploited a critical flaw in its software, the project said Tuesday.

A blockchain is a running record of transactions, written in batches called blocks and added by miners, who run banks of computers competing to produce the next one. Miners usually work in pools, combining their machines and splitting the proceeds. Whichever version of the record has the most computing power behind it is the one the network treats as real.

The flaw let bad blocks slip into that record on Friday. Two pools that together control most of Ravencoin’s computing power are now rebuilding the record from just before the first one appeared, data shows, and if enough miners follow them, everything written since would be replaced.

The consequence is simpler for a user — that a payment that looked complete over the weekend could vanish from Ravencoin’s accepted history.

RVN fell 17% over 24 hours to about $0.0029, cutting its market value to roughly $48 million on $10 million of trading volume. The token is down 77% over the past year.

The first bad block appeared at height 4,487,776 at 15:44 UTC on Aug. 7. Once the weakness had been demonstrated on the live network, others appeared to copy it and produce invalid blocks of their own. Ravencoin has since released a fix, but patching the software does not undo what is already written.

The two pools, 2Miners and RavenMiner, are building their version from block 4,487,775, the last one before the exploit. The project said it asked them to restart from a more recent point, which would put less history at risk, but they declined.

Some transactions caught in the gap may be picked up again and recorded on the replacement chain. Ravencoin further warned exchanges and other services not to assume that deposits or withdrawals wiped out this way will return on their own, and advised them to suspend both until the network settles on a single version.

Exchanges have started responding. Bitvavo suspended RVN deposits and withdrawals as a precaution, citing the exploited vulnerability. South Korea’s Upbit placed an investment warning on RVN across its won, bitcoin and tether markets and also stopped deposits.

The project stopped short of endorsing the pools’ plan, saying the details were being shared for transparency rather than as support for any particular version of the chain.

That leaves an unusual amount of control with whoever supplies the computing power, as two operators are deciding which version of the past few days the rest of the network will have to accept, and the project that maintains the software cannot overrule them.

Ravencoin has been here before. In 2020, attackers exploited a flaw that let RVN be created beyond what the rules allowed, minting roughly 31 million extra tokens before it was fixed.


 

Leave a Reply

Your email address will not be published. Required fields are marked *