Executive brief
tBTC is a bridge protocol that allows Bitcoin to be used on other blockchains via Simplified Payment Verification (SPV) proofs. A flaw in how SPV proofs are validated allows a malicious maintainer to create fraudulent proofs of fake Bitcoin transactions, bypassing the normal computational cost that would otherwise make such an attack prohibitively expensive. While the maintainer role is trusted, this vulnerability significantly reduces the cost of exploitation.
Technical details
The vulnerability exploits malleability in Bitcoin's Merkle tree structure by allowing an attacker to construct a 64-byte transaction that serves dual purposes: it can be mined on the blockchain as a valid transaction (D), while its structure is crafted so that parts of it form valid Merkle proof nodes for a fraudulent transaction (E). By pre-computing transactions with specific hash relationships (requiring 2^60–2^81 operations, cheaper than mining 6 blocks), an attacker can transform a valid SPV proof for D into a seemingly valid proof for the malicious E. The attack requires the attacker to hold the SPV maintainer role. The fix, available in version 1.5.2, requires inclusion of the coinbase transaction and its Merkle proof, raising the computational cost to 2^224, making the attack infeasible.
Affected products
- Keep Network tBTC <= 1.5.1
- Keep Network tBTC-v2 (npm @keep-network/tbtc-v2) <= 1.5.1
Timeline
- 2024-01-19: disclosed: GHSA advisory published
- 2024-01-19: patched: Fix released in tBTC v1.5.2