Crypto: a zero transfer blocks the Pectra d'Ethereum update

While the crypto ecosystem held its breath for the Pectra d'Ethereum update, an anonymous actor played the spoilsports on the Sepolia test network. A subtle attack, exploiting an unexpected fault, revealed vulnerabilities that question as much as they educate. Decryption of an incident halfway between technical bug and psychological warfare.

A character representing the crypto eth try to move forward

When a “ghost” transfer paralyzes Sepolia

On March 5, Ethereum deployed Pectra on Sepolia, its latest test network before the official launch. But hardly the blockchain clock started when error messages have invaded Geth knots. Empty, useless blocks accumulated. Marius van der Wijdena key developer, says: “The attacker has transformed an ERC-20 functionality into a weapon. »»

Everything is based on a neglected technical detail: the ERC-20 standard authorizes the transfer of tokens … without tokens. An unknown user sent a transaction of 0 token to the Sepolia deposit contract, triggering a cascade of erroneous events.

Result ? The network began to undermine empty blocks, such as an engine that would run empty. “We thought of an internal error, but the address was new, funded via a facet,” says Van der Wijden. The attack was deliberate, almost elegant in its simplicity.

However, the team had anticipated a correction. Too late. The attacker, seeming to read in their thoughts, revived the assault with an identical transaction.

“We realized that he may monitor our communications,” admits the developer. A race against the clock begins: filter suspicious transactions without blocking the network. The fix, secretly deployed on a few nodes, finally stopped the hemorrhage. At 2 p.m., Sepolia breathed again.

Crypto: security and psychology, new invisible fronts

This incident is not just a technical bug. He raises a burning question: how to secure protocols designed to be without permission against malicious actors who play with their rules? The exploited flaw was not one in the classic sense: ERC-20 worked perfectly. It is the interaction between this standard and the specific deposit contract in Sepolia which created a breach.

Van der Wijden recognizes this: “We had underestimated this limit case. »Euphemism. Because in crypto, the “limits” are often the playground of attackers.

The anonymous behind this attack has demonstrated a fine understanding of Ethereum's mechanisms. His gesture is less like a hacking than a show of strength, a reminder that decentralized networks must anticipate the unpredictable.

Faced with this threat, the team adopted a counter-intuitive strategy: not to publish the corrective. For what ? For fear that the attacker would adapt his methods. “We have discreetly updated our nodes to regain control,” explains Van der Wijden. A decision that combines computer security and mental poker. Because in the crypto space, each correction can become a double -edged weapon if it is too exposed.

In parallel, this episode relaunches the debate on test networks. Sepolia uses a different deposit contract from *Mainnet *, a particularity that has limited the damage. But Holesky, tested at the end of February, had already revealed weaknesses. Proof that even the blockchain test benches require … test benches.

Maximize your Cointribne experience with our 'Read to Earn' program! For each article you read, earn points and access exclusive rewards. Sign up now and start accumulating advantages.

Similar Posts