$1 074 000 USD

APRIL 2018

GLOBAL

VERGE

DESCRIPTION OF EVENTS

"Verge provides the security of blockchain based payments to everyday users with easy to use software tailored to real life needs and applications." "Verge gained attention in April 2018, when the world’s largest streaming pornography site, Pornhub, began accepting the cryptocurrency as an alternative way for clients to pay live webcam models."

 

"Verge (XVG) experienced multiple 51% attacks in 2018."

 

"In a short period of time, the attacker made off with around 250,000 coins."

 

"Verge uses five different cryptographic algorithms for mining, switching to a new one for every block, but the attacker figured out a way to fake the timestamps of his/her blocks, permitting them to be mined all with one algorithm. Because of this, he/she was able to capture the majority of the network’s mining power with far less computing power than would normally be required."

 

"The company came to its defense, calling the breach a “small hash attack” that has been “cleared up now” on Twitter."

 

"We had a small hash attack that lasted about 3 hours earlier this morning, it's been cleared up now. We will be implementing even more redundancy checks for things of this nature in the future!"

 

"The hack was discovered by “ocminer,” a poster on Bitcointalk forums, yesterday afternoon. According to ocminer, the attacker took advantage of “several bugs” in Verge’s code to mine an extraordinarily large number of new blocks on Verge’s blockchain, in turn rewarding him/herself with a large number of coins over a very short period of time."

 

"Ocminer and several media outlets called this a 51% attack, which is notable because this type of attack is theoretically possible on other blockchains which rely on proof-of-work (PoW) validation mechanisms."

 

"The attack is particularly serious as it requires a hard fork to exclude the blocks the attacker has mined. It’s also notable because it shows that even a seemingly foolproof PoW system can be compromised."

 

"[T]he over 20 Million XVG which were instamined by the attacker won't be blacklisted, reverted, filtered or rolled-back in anyway according to the verge-dev, so in my opinion you all (the miners and investors) got betrayed about that 20 M coins .. For some it might be only a few coins, for some it might be a lot.. For some this might all be drama for them, I see you there of course.."

 

"Verge (XVG) managed to implement a patch within 72 hours, including prepared updates for the wallets." "Verge was extremely impressed with the response time from Bittrex and Binance after a call was placed informing them of what was happening. They took immediate action and proactive measures to provide protection to all accounts and transactions. With so many exchanges popping up these days, unparalleled support like that is crucial to the ongoing success of cryptocurrency. This was also the case for all mining pools, as they have a direct line of communication to the team at all times."

 

"We will be releasing a new Qt wallet for windows and Mac OS tomorrow, along with a detailed explanation of the mining exploit we dealt with. thanks everyone for being patient!"

 

Explore This Case Further On Our Wiki

The Verge blockchain requires miners to switch between 5 different algorithms when mining, which is intended to slow down the mining and prevent the development of specialized mining machines. However, a bug in the algorithm allowed the same algorithm to be run multiple times in a row by faking timestamps.

 

There don't appear to have been any losses in this case, however the price of the token was evidently impacted by the additional token minting. The vulnerability has been fixed by adding additional redundancy checks on timestamps. Users have to download new wallets.

HOW COULD THIS HAVE BEEN PREVENTED?

There were no losses from this incident to any exchange platforms.

 

Check Our Framework For Safe Secure Exchange Platforms

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2019 - 2026 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.