evstack / evstack/ev-reth

Feature: Pre-built Emergency Address Freeze Hardfork

オープン
#110 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement
主要言語
Rust
スター
8
フォーク
9
平均マージ
2日 13時間
マージ済み PR(30日)
6

説明

## Summary

Chains using Reth lack ready-to-deploy tooling for freezing wallet activity during active exploits. This issue proposes a pre-tested hardfork template that can restrict token transfers from arbitrary addresses with minimal configuration.

## Problem

When an exploit occurs, engineering teams must build and test address-freezing logic under time pressure. This introduces risk of mistakes and extends chain downtime. A pre-built solution would let teams respond faster and with more confidence.

## Proposed Solution

### 1. Emergency Freeze Hardfork Template

A tested, documented hardfork module that can:

- Freeze native token, ERC20, and ERC721 movement from a configurable address list
- Allow transfers only to a designated rescue address
- Deploy with config-only changes (no code modifications required)
- Include pre-written tests for all freeze scenarios

**Implementation locations:**

- **Block validation** (`validate_post_block_execution`): Reject blocks containing prohibited transfers by inspecting receipt logs for `Transfer` events
- **Block building** (commit conditions): Prevent validators from proposing invalid blocks

### 2. Oracle-based Address Blocklist (Exploratory)

Investigate mechanisms to freeze addresses without chain downtime:

**Option A:** Consensus client maintains a blocklist oracle, injected into execution client via Engine API

**Option B:** Authorized oracle submits blocked addresses to an on-chain contract, read during post-block execution

Trade-offs to consider:
- Race condition risk (attacker may transact before rules update)
- Decentralization implications of authorized oracles
- Effectiveness depends on control over block builders

## Acceptance Criteria

- [ ] Emergency freeze hardfork template with configurable address list
- [ ] Coverage for native token, ERC20, and ERC721 transfers
- [ ] Kurtosis-based test suite validating freeze behavior
- [ ] Deployment documentation
- [ ] (Optional) Evaluation of oracle-based approach

## References

- Berachain's $12M Balancer V2 exploit recovery used this approach successfully: https://x.com/RezMah/status/1989172438031122499

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by reading the block validation entry point validate_post_block_execution and the block-building commit conditions described in the issue. Compare the proposed hardfork and oracle approaches, then use the acceptance criteria to scope the Kurtosis tests, transfer coverage, and deployment documentation needed for completion.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
rust
領域
blockchain, distributed-systems, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。