The root cause of the problem was a hidden assumption in the ERC4337 code. Illustration: Gwen P; Source: Shutterstock.The root cause of the problem was a hidden assumption in the ERC4337 code. Illustration: Gwen P; Source: Shutterstock.

Ethereum Foundation awards $50,000 to researchers who identified ‘high-severity’ attack vector

2026/02/06 00:51
3 min read

The Ethereum Foundation has awarded a $50,000 bug bounty, its maximum award, to researchers who identified a “high-severity” attack vector impacting the Ethereum blockchain.

The previously unseen attack vector, disclosed by the foundation on Thursday, affected ERC4337, the protocol that powers a feature called account abstraction.

It allowed a malicious actor to intentionally cause certain account-abstraction transactions to revert and pay for gas, even though they were valid and correctly signed.

“Huge thanks to the EF for handling the issue responsibly and granting us a $50k bounty, the maximum high-severity award,” Trust Security, the firm that identified the attack, said in an X post.

“This is a censorship and griefing vector, not a fund-theft vector,” the Ethereum Foundation said in a blog post, adding that the attack had been patched in its latest release.

At the time of discovery, use of the specific vulnerable ERC4337 transaction type was small, so the attack vector’s real-world impact was limited.

Ethereum users sent around 1.7 million vulnerable ERC4337 transactions over the past week, according to crypto data platform BundleBear.

That’s around 9% of all Ethereum transactions made during that period.

The issue was important to address before broader adoption amplifies its effects, the Ethereum Foundation said.

Bug bounties

The code that underpins the vast majority of the $135 billion DeFi sector is open source, meaning that anyone can inspect, modify, or enhance it freely.

This open-source ethos is viewed favourably by most crypto enthusiasts, as it enables community-driven audits, makes it easier for developers to collaborate, and allows users to verify that the code does what it is supposed to do.

But it’s also a double-edged sword.

Any vulnerabilities in open-source code are also visible to attackers, who could exploit them to steal funds or harm users.

That’s why bug bounties — rewards offered to people who identify errors or vulnerabilities in code — are critical to the security of open source code.

Immunefi, the largest crypto bug bounty platform, has paid out over $125 million in total, according to its website.

In addition to the $50,000 bounty from the Ethereum Foundation, Trust Security said it accepted an additional $59,500 in bounties from DeFi apps that rely on ERC4337.

Safe, the multi-signature wallet provider, and Biconomy, a crypto bridge, are among the biggest users of the vulnerable ERC4337 transaction type, though Trust Security has not yet said which apps it accepted bounties from.

Root cause

Account abstraction is a concept in Ethereum that enables programmable transactions, making features like scheduled payments possible.

The root cause of the problem was a hidden assumption in the ERC4337 code.

Developers assumed that all account abstraction transactions would run cleanly, isolated, and uninterrupted, just like normal Ethereum transactions.

In fact, an attacker could frontrun certain pending account abstraction transactions that interact with protocols with reentrancy protection, or that can be reverted through temporary state changes.

“This would cause the inner transaction to revert while paying for the spent gas, griefing account abstraction users,” the Ethereum Foundation’s blog post said.

To fix the issue, developers required that certain contract functions be called only from non-account abstraction wallets.

Protocols that use ERC4337 should upgrade to the newest release as soon as possible, the foundation said.

Tim Craig is DL News’ Edinburgh-based DeFi Correspondent. Reach out with tips at tim@dlnews.com.

Market Opportunity
PoP Planet Logo
PoP Planet Price(P)
$0.01092
$0.01092$0.01092
-0.81%
USD
PoP Planet (P) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Woman shot 5 times by DHS to stare down Trump at State of the Union address

Woman shot 5 times by DHS to stare down Trump at State of the Union address

A House Democrat has invited Marimar Martinez to attend President Donald Trump's State of the Union address in Washington, D.C., after she was shot by Customs and
Share
Rawstory2026/02/06 03:36
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
WLFI Drops 20% Weekly as Price Tests the Crucial $0.113 Support

WLFI Drops 20% Weekly as Price Tests the Crucial $0.113 Support

On Thursday, February 5, World Liberty Financial (WLFI) is continuing its decline and is trading at $0.1281, decreased by 5.89% in the past day. The token has lost
Share
Tronweekly2026/02/06 03:00