A night of horror: Filecoin "double spend"?
POW POWER
2021-03-19 05:36
本文约1037字,阅读全文需要约4分钟
Blockchain, as a machine for producing "trust" in the new era, should not be a victim of the power struggle.

Last night and this morning, it was really a night of horror. The Filecoin mainnet successfully staged "a good show", and the people who eat melons were in a fog. In the end what happened? It is reported that on the evening of the 18th, some community users reported that they can still receive an equal amount of FIL after recharging FIL in the exchange. It is suspected that they have encountered a "double spend" problem. In response to this incident, the official Filecoin team, Filfox and FileStar developers, and the Lotus team all spoke out. After careful and careful analysis, the Filfox and FileStar developers stated that they can confirm that there is a serious problem in the recharge process recommended by the Filecoin official website to the exchange. The perpetrators can cheat the exchange's recharge detection by constructing a special transaction, so as to realize double spending on a transaction.

The word "Double-spending" is very familiar to the old players in the currency circle. As the name suggests, it refers to the behavior of multiple false transactions with the balance of the digital assets held by the user. . The Bitcoin Gold BTG two years ago was a typical case. A malicious miner temporarily controlled the BTG blockchain, quickly withdrew coins after recharging to the exchange, and then reversed the block, successfully implementing a double-spending attack. At that time, Liao Xiang, the founder of Bit Gold BTG, responded: "We have worked closely with various exchanges, and the number of temporary confirmations has reached more than 20 times, and the attack has been invalidated, and we are collecting evidence to report the case to the FBI (Federal Bureau of Investigation). However." , in this attack, the attacker may have stolen more than 388,200 BTG from the exchange, worth up to 18.6 million US dollars, which brought immeasurable losses to BTG and never recovered.

Going back to the Filecoin incident itself, as of now, an exchange has falsely recharged Filecoin worth about $5 million. Huobi, Binance, Ouyi and other mainstream exchanges responded quickly and have now closed the Filecoin mainnet token FIL. recharge function.

How did the Filecoin official and the Lotus team respond to this? Its team members said that the development team confirmed that Filecoin has no double-spend problem. The possible reason is that the front end of the Filfox browser has caused misleading, making some users think that there is a possibility of double-spend during the process of recharging Filecoin on the exchange. With the escalation of the dispute, Filecoin The official tweeted urgently, saying that the Lotus team received a report from the exchange involving incorrect use of the Lotus API to judge transfers/deposits in the Filecoin network. The team investigated and found no network issues or API errors. They are working with relevant exchanges to ensure proper use of these APIs. In the subsequent event review report, Filecoin officially stated that the exchange should use the Lotus API to keep accounts accurately.

It turned out that the "double flower" incident that caused a lot of trouble was nothing but an own thing, and it was completely non-existent. However, maintaining the security and credibility of the blockchain ledger is still an insurmountable red line. As a machine for producing "trust" in the new era, the blockchain should not become a victim of the power struggle.

POW POWER
作者文库