BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home CRYPTO

Smart Contract Hack: Ethereum’s PoW Fork (ETWH) Gets Hacked

BlockNews Team by BlockNews Team
September 21, 2022
in CRYPTO, MEDIA, SOCIAL, TECHNOLOGY
Share on XShare in TelegramShare on Reddit

The Ethereum Proof of Work (PoW) Chain, ETHW, has been scrambling to quell the claims that an on-chain replay attack hit it over the weekend. The Ethereum PoW fork is already off to a negative start. The smart contracts hack has triggered a collapse in prices. A blockchain security firm, BlockSec, alerted ETHW users of a replay attack in the network.

1/ Alert | BlockSec detected that exploiters are replaying the message (calldata) of the PoS chain on @EthereumPow. The root cause of the exploitation is that the bridge doesn't correctly verify the actual chainid (which is maintained by itself) of the cross-chain message.

— BlockSec (@BlockSecTeam) September 18, 2022
Via @BlockSecTeam – Twitter

According to BlockSec, the replay attack occurred on September 16th. In this attack, the attackers obtained ETHW tokens by replaying Ethereum’s Proof of Stake (PoS) chain call data on the Ethereum fork PoW chain. Replay attacks are common when cryptocurrencies exist as a similar asset yet exist as separate blockchains. They are common in hard forks.

BlockSec, says that the root cause of the exploit was ETHW chain’s Omni cross-chain bridge. The bridge was using old ChainIDs and not correctly validating the correct ChainID for cross-chain messages. The Ethereum Mainnet and Testnet use two identifiers for different purposes: a Network ID and a Chain ID. Peer-to-peer messages between nodes use Network IDs, while transaction signing uses Chain IDs. EIP-155 introduced Chain ID to prevent replay attacks between ETH and Ethereum Classic (ETC) blockchains.

Events Leading to the ETWH Hack

By replaying similar transaction messages on Ethereum PoW, the hacker transferred 200 wrapped Ethereum ($260,000) using Omni bridge. OmniBridge is built on the Gnosis network, which is built on Ethereum Network. 

The hacker aimed to receive 200 ETHW from the web and a copy of the OmniBridge smart contract. Almost 40 minutes after the exploit happened, the ETHW market plummeted from $8 to $5. It is unclear if the attacker cashed out the 200 ETHW stolen in the attack. How could the attack be possible, yet cryptocurrency is secure?

Had tried every way to contact Omni Bridge yesterday.

Bridges need to correctly verify the actual ChainID of the cross-chain messages.

Again this is not a transaction replay on the chain level, it is a calldata replay due to the flaw of the specific contract. https://t.co/bHbYR4b2AW pic.twitter.com/NZDn61cslJ

— EthereumPoW (ETHW) Official (@EthereumPoW) September 18, 2022
Via @BlockSecTeam – Twitter

According to Gnosis Co-founder Martin Koppelman, the attack was possible because OmniBridge, which is on the PoW chain, continues to accept transactions pointing to the Chain ID of the Proof of Stake Ethereum blockchain. 

This creates a variable that serves as a unique identifier for various blockchain networks. PoW forks use different ChainIDs to separate actions between the two networks. Because of this, the balance of the chain contract deployed on the PoW chain depletes.

Security researchers had warned users that such attacks against ETHW could occur in preparation for the fork. Gnosis co-founder Martin Koppelmann later said that both Gnosis and Ethereum were utterly unaffected.  

Detecting and Preventing Ethereum Blockchain Smart Contract Reentrancy Attacks

Smart contracts are immutable, public, and distributed on the Ethereum blockchain. However, vulnerabilities can occur due to the developer’s programming. Between 2016 and 2018, seven cybersecurity incidents related to Ethereum smart contracts resulted in economic losses of over $289 million. Reentrancy vulnerabilities were at the root of two of these incidents.

The impact far exceeded the financial loss. Several reentrancy countermeasures are available based on defined patterns. These patterns help to prevent the exploitation of vulnerabilities before deploying smart contracts. Some current protective methods include;

  •     Smart Contracts Vulnerabilities Detection Tools
  •     SmartCheck
  •     Remix
  •     Oyente
  •     Mythril
  •     Security
  •     F* Framework
  •     Security Based on Programming Languages
  •     Security Based on the Development of Smart Contracts

Developers should make sure to put security first. Just as the Ethereum Merge occurred in stages, crypto network upgrades too should appear in stages. This prevents any possibility of losing millions.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: BlockchaincryptoethereumWeb3
Tweet1ShareShare
BlockNews Team

BlockNews Team

DON'T MISS THESE! HOT OFF THE PRESS

Jupiter Rebound Accelerates as Network Activity Jumps – Here Is Why Spot Selling May Cap the Rally
CRYPTO

Jupiter Rebound Accelerates as Network Activity Jumps – Here Is Why Spot Selling May Cap the Rally

March 1, 2026
Hyperliquid Crypto Jumps 20% From $25 Support – Here Is Why $38 Could Be Next
CRYPTO

Hyperliquid Crypto Jumps 20% From $25 Support – Here Is Why $38 Could Be Next

March 1, 2026
Bittensor TAO Rides AI Wave After NVIDIA Earnings – Here Is Why Supply Shock Talk Is Growing
CRYPTO

Bittensor TAO Rides AI Wave After NVIDIA Earnings – Here Is Why Supply Shock Talk Is Growing

March 1, 2026
Institutional Wallet Moves Shake Up DeFi – Here Is What’s Next for Uniswap and AAVE
CRYPTO

Institutional Wallet Moves Shake Up DeFi – Here Is What’s Next for Uniswap and AAVE

March 1, 2026
Cardano Sees $80M Inflows Amid Price Weakness – Here Is What It Means for ADA
CARDANO

Cardano Sees $80M Inflows Amid Price Weakness – Here Is What It Means for ADA

March 1, 2026
Solana Crypto Faces Heavy Resistance at $89 – Here Is Why the Next Move Could Target $110 or Slide to $60
CRYPTO

Solana Crypto Faces Heavy Resistance at $89 – Here Is Why the Next Move Could Target $110 or Slide to $60

March 1, 2026
Load More

Related News

Jupiter Rebound Accelerates as Network Activity Jumps – Here Is Why Spot Selling May Cap the Rally

Jupiter Rebound Accelerates as Network Activity Jumps – Here Is Why Spot Selling May Cap the Rally

March 1, 2026
Hyperliquid Crypto Jumps 20% From $25 Support – Here Is Why $38 Could Be Next

Hyperliquid Crypto Jumps 20% From $25 Support – Here Is Why $38 Could Be Next

March 1, 2026
Bittensor TAO Rides AI Wave After NVIDIA Earnings – Here Is Why Supply Shock Talk Is Growing

Bittensor TAO Rides AI Wave After NVIDIA Earnings – Here Is Why Supply Shock Talk Is Growing

March 1, 2026
Institutional Wallet Moves Shake Up DeFi – Here Is What’s Next for Uniswap and AAVE

Institutional Wallet Moves Shake Up DeFi – Here Is What’s Next for Uniswap and AAVE

March 1, 2026
Hedera Patent Boost vs Price Pressure – Here Is Why $0.10 Is the Line in the Sand

Hedera Patent Boost vs Price Pressure – Here Is Why $0.10 Is the Line in the Sand

March 1, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews