← Back to News

Cryptocurrency

Cardano Rejoices as Ethereum Hard Fork Constantinople is Delayed

Ethereum’s hard fork, Constantinople, was scheduled to occur earlier in the week but has now been delayed due to a critical security vulnerability found within the source code. The vulnerability was discovered by ChainSecurity, a formal audit platform for smart contracts. In a recent medium article, ChainSecurity describes the newfound vulnerability: “The upcoming Constantinople Upgrade […]

By CJ Reichel · January 18, 2019
Cardano Rejoices as Ethereum Hard Fork Constantinople is Delayed

Ethereum’s hard fork, Constantinople, was scheduled to occur earlier in the week but has now been delayed due to a critical security vulnerability found within the source code. The vulnerability was discovered by ChainSecurity, a formal audit platform for smart contracts. In a recent medium article, ChainSecurity describes the newfound vulnerability:

“The upcoming Constantinople Upgrade for the Ethereum network introduces cheaper gas cost for certain SSTORE operations. As an unwanted side effect, this enables reentrancy attacks when using address.transfer(…) oraddress.send(…) in Solidity smart contracts. Previously these functions were considered reentrancy-safe, which they aren’t any longer.”

One of the upgrade features to Constantinople was intended to decrease gas prices in Ethereum smart contracts allowing for cheaper long term storage operations. In the past, this vulnerability was not a problem, but one of the new features of Constantinople enabled the possibility of a reentrancy attack.

Storage operations before Constantinople were relatively expensive and as a result, this kind of vulnerability was not possible. By altering the gas restrictions to allow for cheaper smart contract storage, this vulnerability became exploitable within the system.

What is a Reentrancy Attack?

When a smart contract sends money to another smart contract, the recipient smart contract has control over the execution. For example, smart contract A has a function which is sending money to smart contract B. When this transfer happens, smart contract B now has the ability to call another function in smart contract A. If smart contract B is able to change storage of smart contract A, then smart contract B can begin to alter prior conditions which were previously fixed in smart contract A. Altering different conditions in smart contract A will allow smart contract B to steal funds.

The Ethereum network is very complex and when one aspect of the system is changed it has a high probability of breaking another aspect of the network.

Vitalik Buterin, creator of Ethereum, wrote a post on Reddit describing the issue:

“If you have N protocol features, there are N^2 ways they could potentially break. I would say my personal takeaway from this is to be much more explicit about writing down invariants (properties guaranteed by the protocol) that we rely on so we can check against them when changing things.”

If a project does not have a good foundation, more features introduced into a particular software will increase the probability of potential vulnerabilities. This can be a nightmare for developers because this function is not linear, but rather exponential.

This chart shows that as the number of features increases, the potential vulnerabilities increases

Essentially, creating an invariant is a way to create a model which mathematically defines what is possible on the network. Mathematically defining the Ethereum network is not easy, but ultimately it would allow developers to understand what kind of side effects or bugs should not be included in their source code. Whenever there is an implementation or improvement to the network, developers can plug their new code into the mathematical model to test if it will break any other parts of the network. An invariant is just a way to mathematically define the relationship between two variables.

Cardano Rejoices

This is where Cardano begins to rejoice. Another word for a mathematical model to define a network is known as formal verification. In a formal way, one can mathematically define what their software is doing. Cardano wants to build their network in a functional programming language so that it is easier to create formal verification for the entire network. Therefore, making updates and future changes becomes more flexible and reduces the risks of introducing additional errors into the existing source code.

As a result, many Cardano enthusiasts went to Twitter to criticize Ethereum. Sabastien Guillemot said the following,

“In the wake of the Constantinople delay, Vitalik talks about importance of writing down the properties of your program & checking them. This is exactly why @InputOutputHK engineers wrote formal & semi-formal specs for Byron & Shelley. Avoid bugs during design, not implementation”

Charles Hoskinson, creator of Cardano and CEO of Input OutputHK, then tweets,

“So in other words, vitalik says they should be like Cardano. Oh crypto, you never cease to amaze me.”

Cardano did not invent functional programming and formal verification, and these concepts are not new. However, Cardano has promoted formal verification since the beginning of its inception. It is optimal for Cardano to have a formal verification and mathematical model for their software, but the tone in which the Cardano community is voicing their opinion is somewhat distasteful.

Conclusion

Because Ethereum lacks formal verification, it has flaws in its foundation. Without question, it was lucky that the bug was found literally hours before the hard fork was scheduled to occur. Ultimately, it all comes back to the exponential relationship between adding features and breaking other parts of the system as a result of adding new features. If a project does not have a solid foundation with formal verification, every additional upgrade comes with more risk of breaking different elements of the network. Ethereum must take this vulnerability seriously, although it is not an impossible flaw to fix, it is a critical one.

Disclaimer: This is not financial advice. Please do your own research and make objective decisions. The purpose of this article is to highlight the recent Constantinople hard fork. The author of the article owns cryptocurrency.