How a Geth Fast-Sync Bug Could Have Caused an Ethereum Chain Split
Summary
The article explains a vulnerability in an older version of Geth’s fast-sync state downloader. Full synchronization independently executes transactions, while fast sync downloads state data from peers and checks it against cryptographic trie roots. The article introduces Merkle-Patricia tries, state roots, and how Geth stores trie nodes to show why distinguishing trie data from raw code blobs matters during synchronization.
The bug arose because requests for the same hash could be merged without preserving whether the data was expected to be a trie or a raw entry. The author describes how a crafted contract arrangement could exploit that confusion, leaving fast-synced nodes without state data and causing them to evaluate a later transaction differently from fully synced nodes. The post says the Geth team patched the issue by handling trie-read errors and distinguishing code blobs from trie blobs. This is a historical vulnerability analysis; it does not indicate that current clients remain vulnerable.
Key ideas
- Fast sync trades some independent validation for speed by downloading state data from peers.
- Merkle-Patricia trie roots let nodes verify downloaded state against hashes in block headers.
- Merging requests without preserving their data type could cause code blobs to be treated as trie data.
- The author outlines how crafted contracts could make fast-synced nodes reach a different state than fully synced nodes.
- Geth addressed the flaw with changes to error handling and blob-type distinctions.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.