October 10, 2026

Capitalizations Index – B ∞/21M

Duplication – Paul Vienhage

Duplication – Paul Vienhage

I recently launched a CTF with prizes totaling 1.75 Ether coordinated from this mainnet contract: https://etherscan.io/address/0x7cd03C9f1D2dc95358B1992e9afc857aeaab45D5 . Of that total only 0.75 Ether was claimed.

Today we are going to do a detailed walkthrough of how to solve this CTF, we will cover an investigation strategy and then an edge case of elliptic curve signature generation. Starting out, the contract contains four state objects: a signer address, an owner address, a boolean called paused, and an array of winner addresses. Its initial state contains 0.25 Ether and the code doesn’t contain a clear way getting more Ether than that.

As for the functions, there are two that would help us reach our goals of breaking the smart contract: one called withdraw which will send the caller of the contract the funds it contains if the bool paused is false, and one called win which adds a requested address to the winners mapping. These give us two clear goals: find a way to set paused to false and find a way to send a message from the owner address.

A cursory check of the addresses provided for owner and sender shows that these are not contract accounts. Since they are not smart contracts a priori it seems impossible to send any messages from them, but they do contain the additional 1.5 ether so there must be some way to unlock them. With no clear path here we turn back to the smart contract.

As of the start of the CTF there were three transactions listed on etherscan. The first is contract creation which won’t give us more information. The second reverted, perhaps it was an accidental transaction. The third is a call to lock which succeeded and told us that (r,s) is a valid signature of the hash of “Pause”. If we could get the private key of signer from this transaction all of ethereum would be broken so lets take a closer look at the reverted transaction.

We can move over to remix and initialize the contract with the signer and owner addresses from the contract. After doing so we can try the unlock transaction with the same data as was submitted to the contract and debug it to see what is causing the revert to happen. Going through the remix debugger we notice something weird, the revert is occurring after the signature validation. It is reverting because the contract isn’t locked and required(paused) doesn’t get paused. However what this means is that if we call lock with the signature then call unlock with the same data the second unlock will work. This is called a signature replay and if we replay the signature to unlock then call withdraw we can claim the first 0.25 ether!

However this is slightly odd, how did someone manage to call unlock instead of lock? If we examine the transactions we notice something weird, that the r and s values that are submitted with the first unlock transaction are the same as the r and s. That’s odd… When you call unlock it checks that either ecrecover(hash2, r, s, 27) or ecrecover(hash2, r, s, 28) are equal to the address. But this means that (r,s) signs both hash1 and hash2. Which should be impossible, by strict probability this has a 1/(2²⁵⁶ — 432420386565659656852420866394968145599)⁴ chance of happening.

Given how small the chance of this happening is the best assumption is there must be some algorithm which allows you to compute a duplicate signature of two different hashes. So there are two options either (1) We try to derive the algorithm our self (2) We research to find the algorithm is described. If we try approach 2 and are lucky we will find this paper https://www.di.ens.fr/david.pointcheval/Documents/Papers/2002_cryptoA.pdf

Here we are going to take approach (1) so that the algorithm becomes more clear. If our main goal is to find matching signatures, we start with r, hash1, and hash2 values then try to derive the private key and s value from them. So we pick a random k and calculate r = f((k * g)), then if we assume we have a d_a private key we can calculate s = k^-1 (h_1 + d_a * r). To calculate the d_a we observe that the elliptic curve points r and –r have the same x coordinate and we try to preform signature verification of hash2 using the r and s we have derived.

[Image since medium doesn’t allow latex]

Indeed if we calculate x = -(hash1 + hash2)/2r mod n is the private key of the signing address from the contract. So then we can transfer the 0.5 eth in that account to our account! But what about the final 1 ether and the winner mapping?

The answer to this is a simple but unintuitive step from the previous one. Our algorithm calls for a random k but what is its actual value? To get the value we calculate k = s^-1 (hash1 + xr). If we check if this private key has any ether associated with it then we will find out that it has a balance of 1 ether and that it is the owner address. Using this we can pay ourselves and call the win function to add our real address to the winners mapping.

Published at Thu, 10 Jan 2019 22:14:49 +0000

Previous Article

Circle CEO: Crypto Will Have a Bigger Impact than the Web

Next Article

5 Crypto Exchanges Have Been Licensed in Gibraltar Since Regulation

You might be interested in …

Paycent – The Easiest Way to Connect Crypto and Fiat

Holding cryptocurrency is all very well, but these days it hardly seems to be used to pay for anything. Merchant uptake is slower than the momentum needed to reach the mainstream. The merchants still take cash, but transferring between the two is an extra step that we could do without. Paycent may just be the crypto-fiat bridge we are looking for, with a whole host of other benefits too.

[Note: This is a sponsored article.]


What is Paycent?

Paycent is, in essence, a mobile payment system. It functions as a dual e-wallet which can be funded by both cryptocurrencies and fiat within the same app. It also allows conversion from crypto to fiat and vice-versa, in real time and from within the wallet, acting as an internal exchange.

Over a thousand online merchants and counting already accept Paycent as a method of payment. However, the option of having a debit card linked to your wallet opens up 36 million points of sale in over 200 countries. This includes withdrawing local currency from ATMs worldwide.

[youtube https://www.youtube.com/watch?v=n7fET7C32Y4?feature=oembed&w=500&h=281]

How is Paycent different?

Paycent already has an established fiat network and is collaborating with mainstream financial institutions and governmental regulators, to both expand this network and push into the world of cryptocurrencies. 

They already have regulatory licenses in UAE and the Philippines, along with approval in principal in Hong Kong and Singapore. Negotiations are also underway to host the Paycent Realtime Exchange in Dubai, with the oversight of the Central Bank of UAE. 

In addition to this, Paycent is in tier 2 talks to acquire a physical banking presence in the Philippines. Paycent would function as the online channel for the bank, providing financial services to the unbanked.

They are also in advanced talks with Egypt and Jordan to develop and host a unified digital payment infrastructure for their banking and government services.

Why should I invest? 

Investors in the ICO starting on November 2nd will receive PYN tokens. Holders of these tokens will receive rewards paid in ETH. These rewards will initially be paid quarterly and are as follows: 

  • 33% of the aggregate exchange rate profit for crypto to fiat and fiat to crypto, converted using the Paycent dual e-wallet.
  • 33% of the total interest profit on microloans to Paycent lenders.

Users of the Paycent Debit Card will also receive an additional 0.1% of each spend in PYN tokens. Investors of 100 or 500 ETH or more are eligible for special debit cards which increase these loyalty rewards to 0.5% and 1% of each spend.

These ‘cash-back’ reward tokens will create a secondary distribution of PYN tokens, creating an open market for PYN, with price support and increase.

https://platform.twitter.com/widgets.js

How can I invest?

Paycent already concluded their pre-ICO, reaching the hard cap of 22,500 ETH in 10 days. Around 857 contributors took part from over 41 countries.

The main ICO is being held in 8 separate phases over the course of four years. There is a minimum investment purchase of 15 PYN and investors can participate using Ethereum, bitcoin, or Litecoin.

The first phase of the ICO begins on November 2, 2017, at 9 am Singapore time (UTC+8) and will last for 7 days or until the Phase 1 hard cap of 30 million PYN has been reached.

Bonus incentives are being given to encourage participation:

  • First 24 hours: 27% bonus PYN
  • Days 2 – 4: 18% bonus PYN
  • Days 5 – 7: 12% bonus PYN 

Subsequent ICO phases are scheduled as shown below, with existing token holders receiving generous bonuses:

Phase 2 (Last week of May 2018)
Hard cap: 35 million PYN
25% bonus to PYN token holders

Phase 3 (2nd week of November 2018)
Hard cap: 35 million PYN
23% bonus to PYN token holders

Phase 4 (Last week of May 2019)
Hard cap: 35 million PYN
21% bonus to PYN token holders

Phase 5 (2nd week of November 2019)
Hard cap: 35 million PYN
19% bonus to PYN token holders

Phase 6 (Last week of May 2020)
Hard cap: 30 million PYN
17% bonus to PYN token holders

Phase 7 (2nd week of November 2020)
Hard cap: 30 million PYN
15% bonus to PYN token holders

Phase 8 (2nd week of November 2018)
Hard cap: 22,045,000 PYN
13% bonus to PYN token holders

For more information about Paycent please visit paycent.com.

Do you think a ‘bridge’ between cryptocurrencies and fiat currency is something that the crypto community needs? Let us know in the comments below.


Images courtesy of Paycent

The post Paycent – The Easiest Way to Connect Crypto and Fiat appeared first on Bitcoinist.com.

Angelic - in tai ping shan

Angelic – in Tai Ping Shan

Angelic – in Tai Ping ShanIf you enjoy my photos, you are welcome to #‎donate #‎bitcoin to me at: 1Q2LV3bsxZjRBQoRXAXikpUGPCrNeGSUWcBy antwerpenR on 2013-09-07 13:13:34[wpr5_ebay kw=”bitcoin” num=”1″ ebcat=”” cid=”5338043562″ lang=”en-US” country=”0″ sort=”bestmatch”]

Dsc03458

DSC03458

DSC03458Etherium Meetup Hong Kong organized by Jehan Chu. Vitalik Buterin test codes (illustrates) one of the features of Caring Currency using Etherium. Photo: Philip McMaster, Caring Currency – World Sustainability Project www.CaringCurrency.com www.RepublicOfConscience.com www.WorldSustainability.OrgBy Philip […]