Full Disclosure: CVE-2021-31876 Defect in Bitcoin Core's bip125 logic



Summary:

In a message to Antoine, the sender expresses gratitude for a disclosure. The message also notes that certain contract protocols, including Onchain DLC, Coinswap, and Vault, have multiple stages of execution with time-sensitive transactions that could be vulnerable to pinning attacks. While these protocols are not yet deployed or are in early phases, the sender recommends that any in-protocol competing transactions explicitly signal RBF. However, the sender notes that Revault is not vulnerable to this issue as all transactions signal RBF and there is no way to sneak a non-signaling competing transaction (as long as the CSV isn't matured yet).


Updated on: 2023-06-14T20:42:14.729626+00:00