On the L1 blockchain Decred tweeted about a security incident: between August 16 and 17, an inflation vulnerability present on the mainnet was exploited by an attacker, resulting in the additional generation of approximately 2,077.97 DCR.

Notably, this vulnerability had actually existed in the consensus code since the mainnet went live in February 2016. The issue stems from improper handling of edge cases when the standard transaction tree interacts with the ticket (stake) transaction tree, which allows double-spend inputs. This vulnerability was submitted to the team via the bug bounty program on August 12, but unfortunately, it was exploited before the official fix was completed.

In response to this incident, the Decred project made a somewhat controversial decision: not to roll back the chain. The project stated that this was to reduce the greater impact that a rollback operation could have on ordinary users.

In addition, the project emphasized that the issuance of about 2,000 DCR from this event will not affect the hard cap of 21 million DCR, and this amount is far lower than historical subsidies that were underissued due to factors such as missed payouts (more than 215,000). Overall, the impact on the coin price is considered controllable.

So far, the team has developed an additional double-spend monitoring service, and it also plans to improve the emergency upgrade signaling mechanism to prevent similar incidents from happening again.

$DCR #Decred #blockchain security