Share this article

EthereumPOW Sees 'Replay' Exploit for 200 ETHW Days After Rocky Start

The exploit took place on a contract, however, and does not affect the main Ethereum POW network itself.

Updated May 11, 2023, 5:26 p.m. Published Sep 19, 2022, 8:07 a.m.
EthereumPOW users have previously reported network issues. (Karla Hernandez/Unsplash)
EthereumPOW users have previously reported network issues. (Karla Hernandez/Unsplash)

EthereumPOW, the version of the Ethereum blockchain that continues to run on a proof-of-work (PoW) consensus mechanism, experienced a replay exploit over the weekend due to a faulty third-party contract.

Developers of EthereumPOW were alerted of the issues and immediately took steps to rectify the problem.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The blockchain was established as a fork of the Ethereum network, which switched to a proof-of-stake (PoS) consensus mechanism on Thursday in an event known as the Merge. The PoS network now continues as Ethereum.

jwp-player-placeholder

The replay exploit refers to the same transaction being duplicated on both chains when they’re not supposed to.

This means if a user transacted on Ethereum PoW, the same was executed on Ethereum – which eventually allows attackers to illicitly trick smart contracts into releasing tokens from one chain, even as the actual transaction was executed on another chain.

Attackers used the Omni bridge of the Gnosis network to conduct the exploit. Some 200 weighted ether (wETH) was transferred through the bridge on Saturday, and the same transaction was replayed on the PoW chain – resulting in the attacker gaining 200 ETHW, or approximately $1,600 at the time.

Faulty data from the Ethereum PoW network’s Chain ID used by a contract caused the issue, security firm BlockSec said in a tweet. A Chain ID is a set of numbers used by the browser-based crypto wallet MetaMask to sign transactions for the network. An incorrect Chain ID causes transactions to fail because users aren't connected to the correct network, rendering a network unusable.

BlockSec warned that the issue might eventually cause the balance of the chain contract deployed on the PoW chain to “be drained.”

Meanwhile, EthereumPOW developers said in a Sunday post that the attack exploited the contract vulnerability of the bridge, and not their blockchain itself.

"We have contacted the bridge in every way and informed them of the risks," it said. "Bridges need to correctly verify the actual ChainID of the cross-chain messages," the developers wrote.

As such, the network saw glitches on its first day with users stating they weren't able to access the blockchain's servers using public information provided by Ethereum PoW. CoinDesk verified the claims and wasn't able to access EthereumPOW’s web servers using those links provided, as reported.

ETHW tokens tumbled in the past 24 hours following the exploit, falling some 37%, and extending weekly losses to over 80%, CoinGecko data shows.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Solana’s Drift Launches v3, With 10x Faster Trades

Drift (b52_Tresa/Pixabay)

With v3, the team says that about 85% of market orders will fill in under half a second, and liquidity will deepen enough to bring slippage on larger trades down to around 0.02%.

What to know:

  • Drift, one of the largest perpetuals trading platforms on Solana, has launched Drift v3, a major upgrade meant to make on-chain trading feel as fast and smooth as using a centralized exchange.
  • The new version will deliver 10-times faster trade execution thanks to a rebuilt backend, marking the largest performance jump the project has made so far.