Transaction malleability is a loophole in the bitcoin protocol that was most famously used in February 2014 to allegedly withdraw funds from Mt Gox.
The idea behind transaction malleability is that a user who is tracking transactions via their hash would not be able to trace the transaction if the hash was changed.
The risk could have been easily mitigated through simplistic internal checks and balances.
A transaction is in the blockchain is referred to by its hash, and their value is included in the merkle tree for that block. A transaction is also signed by the private key associated with the transaction input. So if the transaction can be altered before being hashed and signed with the signature and then propagated to the network – the sender would not be able to track the transaction as its hash has been altered.
The attackers using transaction malleability against Mt Gox would request a withdrawal. When they received a hash of the transaction from the Company they would alter it by changing the <scriptPubKey> whilst using the <ScriptSig> and re-flooding the network with this new transaction. Mt Gox would then look for their transaction and assume there was an issue and resubmit the funds to the user. The user could then repeat this attack. Their flaw was that if they didn’t manage to propagate their updated transaction quick enough then they would still receive the Bitcoin but wouldn’t receive the extra funds. In this case they just tried again – they hadn’t lost much – just a bit of time.
This meant that Mt Gox’s funds were gradually leached away. However basic accounting checks and reports would have been able to detect this breach or loophole. In fact when summing up the process this was due to a lack of oversight by the management.
- Meet Business.Club: A Crypto Wallet Provider with Debit Cards Sponsored
- A Guide to Using the Tokens.Net Exchange Sponsored
- Top Cryptocurrency Faucets to Earn Free Crypto in 2020
- CRYPOTAG's New ‘Zeus’ Product: Leaner and Easier Than Ever
- 5 Easy and Safe Ways to Earn Free Ethereum in 2020
- How Blockchain Technology Can Provide A Global Software-as-a-Service Platform
- Meet Utopia: The All-In-One Superapp for Privacy-Conscious Cryptocurrency Users
- Lykke: A 'World-Class' Cryptocurrency Exchange
- eToro Debuts CopyTrader in the U.S. to Drive Mass-Market Participation in Cryptocurrency Trading
- Get an Edge in Trading Forex, Stocks and Crypto With Elitetrading
This website is only provided for your general information and is not intended to be relied upon by you in making any investment decisions. You should always combine multiple sources of information and analysis before making an investment and seek independent expert financial advice.
Where we list or describe different products and services, we try to give you the information you need to help you compare them and choose the right product or service for you. We may also have tips and more information to help you compare providers.
Some providers pay us for advertisements or promotions on our website or in emails we may send you. Any commercial agreement we have in place with a provider does not affect how we describe them or their products and services. Sponsored companies are clearly labelled.