CryptoMediaClub
Monday, September 15, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home Blockchain

Fireblocks, UniPass wallet tackle Ethereum ERC-4337 account abstraction vulnerability

27.10.2023
A A
0
130
VIEWS
ShareShare

Cryptocurrency infrastructure firm Fireblocks has identified and assisted in tackling what it describes as the first account abstraction vulnerability within the Ethereum ecosystem.

An announcement on Oct. 26 unpacked the discovery of an ERC-4337 account abstraction vulnerability in the smart contract wallet UniPass. The two firms worked together to address the vulnerability, which was reportedly found in hundreds of mainnet wallets during a ‘whitehat’ hacking operation.

According to Fireblocks, the vulnerability would allow a potential attacker to carry out a full account takeover of UniPass wallet by manipulating Ethereum's account abstraction process.

As per Ethereum’s developer documentation on ERC-4337, account abstraction allows for a shift in the way transactions and smart contracts are processed by the blockchain to provide flexibility and efficiency.

Related: Account abstraction will drive a billion users from Asia to Web3: ConsenSys exec

Conventional Ethereum transactions involve two types of accounts, externally owned accounts (EOAs) and contract accounts. EOAs are controlled by private keys and can initiate transactions, while contract accounts are controlled by the code of a smart contract. When an EOA sends a transaction to a contract account, it triggers the execution of the contract's code.

Account abstraction introduces the idea of a meta-transaction or more generalized abstracted accounts. Abstracted accounts are not tied to a specific private key and are able to initiate transactions and interact with smart contracts just like an EOA.

As Fireblocks explains, when an ERC-4337-compliant account executes an action, it relies on the Entrypoint contract to make sure only signed transactions get executed. These accounts typically trust an audited single EntryPoint contract to ensure that it receives permission from the account before executing a command:

“It’s important to note that a malicious or buggy entrypoint could, in theory, skip the call to “validateUserOp” and just call the execution function directly, as the only restriction it has is that it’s called from the trusted EntryPoint.”

According to Fireblocks, the vulnerability allowed an attacker to gain control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once the account takeover was complete, an attacker would be able to access the wallet and drain its funds.

Several hundred users that had the ERC-4337 module activated in their wallets were vulnerable to the attack which could be performed by any actor on the blockchain. The wallets in question only held small amounts of funds and the issue has been mitigated at an early stage.

Having ascertained that the vulnerability could be exploited, Fireblocks’ research team managed to carry out a whitehat operation to patch the existing vulnerabilities. This involved actually exploiting the vulnerability:

“We shared this idea with the UniPass team, who took it upon themselves to implement and run the whitehat operation.”

Ethereum co-founder Vitalik Buterin previously outlined challenges in expediting the proliferation of account abstraction functionality, which includes the need for an Ethereum Improvement Proposal (EIP) to upgrade EOAs into smart contracts and ensuring the protocol works on layer-2 solutions.

Magazine: Ethereum restaking: Blockchain innovation or dangerous house of cards?

Share10Tweet6ShareSharePin2

Related Posts

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei
Blockchain

Ondo Finance Unleashes Revolutionary Tokenized US Treasuries on Sei

18.07.2025
0

Skip to content

Read moreDetails
Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

Hashed stablecoin: South Korea’s Crypto Giant Unveils Bold Trademark Play

17.07.2025
LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

LA Token’s Strategic Move: Lagrange Foundation Considers Crucial Buyback for Price Stability

14.07.2025
Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

Shocking Loss: Crypto Influencer Accidentally Burns $75K in PUMP Token

14.07.2025
Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

Dubai’s Historic Approval: Qatar National Bank Launches Revolutionary Tokenized Money Market Fund in DIFC

08.07.2025
Load More
Next Post
Fantasy football game on Telegram: Fanton joins Cointelegraph Accelerator

Fantasy football game on Telegram: Fanton joins Cointelegraph Accelerator

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Shape FLOCKERZ’s Path Forward and Earn Free FLOCK as a Reward

Shape FLOCKERZ’s Path Forward and Earn Free FLOCK as a Reward

11 months ago
ASIC Warns Australians Against Bitget’s “Unlicensed” Crypto Futures Offerings

ASIC Warns Australians Against Bitget’s “Unlicensed” Crypto Futures Offerings

2 months ago
Latest ChatGPT 5 Predicts XRP, SOL and ETH Prices for End of 2025

Latest ChatGPT 5 Predicts XRP, SOL and ETH Prices for End of 2025

4 weeks ago
The Elusive $0.001 Target for Shiba Inu (SHIB): A Reality Check

The Elusive $0.001 Target for Shiba Inu (SHIB): A Reality Check

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Native Markets Becomes Issuer of Hyperliquid’s Stablecoin USDH

XRP Whales Dump 40 Million Tokens, While Retail Investors Turn to DOT Miners

Tether Launches U.S. Dollar Stablecoin for Domestic Market

Why Is Crypto Down Today? – September 15, 2025

8-Year Bitcoin Holder Offloads Another $136M Following Massive $4B ETH Trade – Whales Dumping Again?

Bank of England Plan to Cap Stablecoin Holdings Draws Fire From Crypto Sector

Trending

If OCC grants Ripple a national charter, does RLUSD sideline XRP or supercharge it?
Analysis

If OCC grants Ripple a national charter, does RLUSD sideline XRP or supercharge it?

15.09.2025
0

Ripple’s bid for an OCC national trust bank charter would put RLUSD inside the U.S. banking perimeter...

Circle Prepares to Launch Native USDC in Hyperliquid Blockchain Ecosystem

Circle Prepares to Launch Native USDC in Hyperliquid Blockchain Ecosystem

15.09.2025
Hyperscale Data Announces $100M Bitcoin Treasury as Company Pivots to AI and Digital Assets

Hyperscale Data Announces $100M Bitcoin Treasury as Company Pivots to AI and Digital Assets

15.09.2025
Native Markets Becomes Issuer of Hyperliquid’s Stablecoin USDH

Native Markets Becomes Issuer of Hyperliquid’s Stablecoin USDH

15.09.2025
XRP Whales Dump 40 Million Tokens, While Retail Investors Turn to DOT Miners

XRP Whales Dump 40 Million Tokens, While Retail Investors Turn to DOT Miners

15.09.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz