flâneur — a map of the web's best reading

Post mortem: April 3rd, 2023 mev-boost relay incident and related timing issue - The Flashbots Ship - The Flashbots Collective

collective.flashbots.net · 2,257 words · saved by 1 readers

Please start by reading our Code of conduct, set a Custom Status and Introduce yourself before joining the conversation! You have selected 0 posts. select all cancel selecting On April 3rd, 2023, a malicious proposer exploited the ultra sound relay 150 through a vulnerability in the open sourced mev-boost-relay implementation 108 maintained by Flashbots to steal ~$20M from multiple sandwich bots. The attack was possible because of a vulnerability in the majority of mev-boost relays (mev-boost-relay 108, Dreamboat 52) detailed below which has since been patched 55. In following up to this event, a related timing attack was identified and mitigated, although more research is needed to understand if this mitigation is worth its negative externalities. mev-boost is an open-source proposer-builder separation (PBS) 64 protocol that allows proposers to sell their blockspace to an open market of specialized actors called builders. Builders compete to create the most valu

Post mortem: April 3rd, 2023 mev-boost relay incident and related timing issue - The Flashbots Ship - The Flashbots Collective Post mortem: April 3rd, 2023 mev-boost relay incident and related timing issue The Flashbots Ship mev-boost , post-mortem bert April 4, 2023, 11:51pm 1 Summary On April 3rd, 2023, a malicious proposer exploited the ultra sound relay through a vulnerability in the open sourced mev-boost-relay implementation maintained by Flashbots to steal ~$20M from multiple sandwich bots. The attack was possible because of a vulnerability in the majority of mev-boost relays ( mev-boos

Explore this link on the map →

related reading