Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»ETHEREUM NEWS»Sepolia incident | Ethereum Foundation Blog
ETHEREUM NEWS

Sepolia incident | Ethereum Foundation Blog

By Crypto FlexsMarch 21, 20244 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Sepolia incident |  Ethereum Foundation Blog
Share
Facebook Twitter LinkedIn Pinterest Email

This blog post exposes threats to the Ethereum network that existed from the Merge to the Dencun hard fork.

background

Prior to the merge, various message size limits were set for RPC communications to protect clients from denial of service (DOS) attacks. These restrictions, which apply to messages received via HTTP endpoints, are passed on to the Engine API, which plays an important role in connecting execution and consensus layer clients during block creation. The engine API’s participation in block generation allows block generation to exceed the RPC size limit for some clients but remain within an acceptable range for others.

If an attacker generates a message that exceeds a client’s size limit at the lowest settings while respecting gas limit requirements, and then waits for a block to be generated, a situation may arise where some clients consider that block. We consider it valid, but others reject it and issue an HTTP error code: “413: Content too large”.

effect

An attacker who can manipulate these messages can force the majority of nodes (=geth) to reject blocks that the minority accepts. These blocks will fork and the proposer will miss out on the reward.

Initially, we thought it would only be possible to create these blocks using a modified version of the builder or client. Geth has a default 128KB limit for transactions. This means that large transactions like the one being discussed will not be included in any geth node’s transaction pool. However, it was still possible to trigger the limit by having a client with a higher limit propose a block and have the CL request validation of this proposed larger block.

We proposed a solution that temporarily lowered the RPC limit for all clients to the lowest value (5 MB). This invalidates the block and causes most nodes to reject the block, thus very limiting the disruption an attacker can cause to the network.

However, on February 7, we discovered that it is possible to create a block that hits the 5MB limit with multiple transactions that are below the 128KB limit and do not exceed 30 million gas.

This is a bigger problem because attackers have realized that they can generate many high-value transactions and send them onto the network. Because he pays more than everyone else in the mempool, all nodes (even geth nodes) include attack transactions in their blocks, creating blocks that are not accepted by the majority of the network, resulting in many forks (all are considered ). valid by a small number of nodes) the chain is continuously re-formed.

By late February 7th, we had all come to the conclusion that raising the RPC limit was a safer alternative.

timeline

  • 2024-02-06 13:00: Toni (EF), Pari (EF) and Justin (Besu) are attempting to submit a specifically refined transaction to the network. Transactions contribute up to 2.7 MB blocks when compressed quickly.
  • 2024-02-06 13:25: The transaction should be valid, but Pari receives an error from the local Geth node.
  • 2024-02-06 15:14: Justin put the transaction into a block and submitted it through the Besu client.
  • 2024-02-06 20:46: Sam (EF) warns Pari (special thanks) Mystic Ryujin X), Toni and Alex talk about a particular Sepolia node they are having trouble with.
  • 2024-02-06 21:05: Team checks again with Marius on Geth and checks for bugs.
  • 2024-02-06 21:10: The gang gets together to debug.
  • 2024-02-07 23:40: Decided to limit all clients to RPC request limit to 5MB.
  • 2024-02-07 6:40: There may be a bigger problem, and we have discovered that the attack can be executed with transactions less than 128KB in size.
  • 2024-02-07 10:00: Decided to increase RPC request limit for all clients.
  • 2024-02-07 21:00: Fix merged into geth.
  • 2024-02-09: Geth is released.


This issue has been addressed by the individual client team in the next release.

Geth: v1.13.12

Nethermind: v1.25.4

believe: 24.1.2

Erigon: v2.58.0

Res: v0.1.0-alpha.18

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ethereum’s 2026 roadmap includes more validator risk than you might think.

December 29, 2025

Devcon 8 will be launched in Mumbai, India in November 2026.

December 25, 2025

Marshall Islands tests cryptocurrency for universal basic income amid cash and bank shortages.

December 21, 2025
Add A Comment

Comments are closed.

Recent Posts

South Korea fines Korbit $1.8 million for failing to comply with regulations

January 1, 2026

Lighter Token (LIT) Overtakes Jupiter — Are Hyperliquids Dangerous?

January 1, 2026

3 Small Cap Altcoins to Watch in the 2026 Prediction Market Boom

December 31, 2025

Test proxy contracts securely using Wake Framework

December 30, 2025

SlotGPT Launches A New AI Slot Platform Transforming Players Into Creators

December 30, 2025

Cango Inc. Secures US$10.5 Million Investment From EWCL To Accelerate Growth

December 30, 2025

Maya Preferred launches mandatory token conversion for regulatory infrastructure transition.

December 30, 2025

Ethereum price target surpasses $3,000, bull opportunity

December 29, 2025

Bitmine Immersion (BMNR) Announces ETH Holdings Reach 4.11 Million Tokens, And Total Crypto And Total Cash Holdings Of $13.2 Billion

December 29, 2025

Moneta Markets Review 2026 MT4/MT5 Crypto CFD Broker With ECN Spreads

December 29, 2025

Risk of Solana price collapse due to Double Top pattern formation and TVL decline

December 29, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

South Korea fines Korbit $1.8 million for failing to comply with regulations

January 1, 2026

Lighter Token (LIT) Overtakes Jupiter — Are Hyperliquids Dangerous?

January 1, 2026

3 Small Cap Altcoins to Watch in the 2026 Prediction Market Boom

December 31, 2025
Most Popular

The trader updated his outlook for SYN, saying that Memecoin is showing tremendous strength, having gained over 27,000% in less than a year.

August 25, 2024

Analyst predicts Solana’s ‘amazing’ parabolic leg and names altcoin outperforming other coins.

January 4, 2024

Dora Factory announces historic $DORA airdrop to over 1 million ATOM stakers in largest MACI vote ever

June 6, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.