Advertisement

Critical Ravencoin Flaw Raises Risk of Reverting Four Days of Transactions

Ravencoin could be forced to reverse several days of blockchain activity after two mining pools controlling most of the network’s computing power began rebuilding the chain from before the first invalid block was produced Friday. Deposits, withdrawals and payments recorded after that point could be removed if the replacement chain becomes the network’s accepted history.

The Ravencoin project said Tuesday that an attacker exploited a critical vulnerability in its software, leaving the network facing the possibility of a multi-day transaction rollback.

Ravencoin was launched in 2018 as a modified version of Bitcoin’s code, with its main purpose focused on issuing and transferring digital assets. Like Bitcoin, it depends on miners to create blocks and maintain a common transaction ledger. Its mining network is considerably smaller, however, giving a small number of pools greater influence over the blockchain when competing chains emerge.

That concentration is now at the center of the incident. Data shows that 2Miners and RavenMiner collectively control most of Ravencoin’s hashpower and are reconstructing the chain from block 4,487,775, which was the last block created before the exploit. If enough miners support their version, transactions added afterward could effectively disappear from the official ledger.

Blockchain transactions are grouped into blocks and secured by miners using computing power to compete for the right to add the next block. Most miners participate through pools, combining resources and sharing rewards. The version of the blockchain backed by the greatest amount of computing power generally becomes the chain recognized by the network.

For ordinary users, a rollback could have immediate consequences. A transaction that appeared to have been successfully completed could later be erased, potentially returning the coins to the original sender while leaving the recipient without the funds.

Exchanges and other businesses that credited customers based on those transactions could also suffer losses. If a platform accepted an RVN deposit, credited the user and allowed the funds to be withdrawn, a subsequent rollback could leave the exchange responsible for a missing balance. Several platforms have therefore halted RVN deposits and withdrawals.

Bitvavo, based in Amsterdam, suspended Ravencoin deposits and withdrawals as a precaution after the vulnerability was exploited. South Korea’s Upbit issued an investment warning for RVN across its KRW, BTC and USDT markets and also stopped accepting deposits.

How the exploit unfolded

The first invalid block appeared at height 4,487,776 at 15:44 UTC on Aug. 7. Once the vulnerability was demonstrated on the live network, additional participants began exploiting the same weakness to produce invalid blocks.

Ravencoin has released a patch designed to close the vulnerability, but fixing the software does not automatically restore the blockchain to an earlier state or undo blocks that have already been produced.

Both 2Miners and RavenMiner are now building their preferred version from block 4,487,775, immediately before the attack began. Ravencoin said it asked the pools to restart from a later block so that less transaction history would be placed at risk, but the request was rejected.

RavenMiner said its nodes have been upgraded with an emergency fix and are mining what it calls the clean chain. According to the pool, blocks generated during the exploit period are being discarded across the entire network, meaning mining rewards from that period would be reversed for all miners rather than only those using RavenMiner.

The pool has also temporarily stopped payouts while the network reaches a final resolution. It said it would cover any resulting deficit itself and that mining income earned before 15:44 UTC on Aug. 7 would not be affected.

Ravencoin has previously experienced a serious security incident. In 2020, attackers exploited a separate vulnerability that allowed them to create RVN beyond the permitted issuance rules. Around 31 million additional tokens were generated before developers fixed the problem.

The latest incident has also hit the token’s market performance. RVN dropped about 17% in 24 hours to roughly $0.0029, bringing its market capitalization to around $48 million. Trading volume was approximately $10 million, while the token remains down about 77% over the past year.