Ravencoin Network Hit by Critical Consensus Vulnerability
Ravencoin's network was hit by a critical consensus vulnerability that allowed attackers to create invalid blocks, which were accepted by vulnerable nodes. The first known invalid block appeared at height 4,487,776 on August 7, and the issue continued until an emergency patch was released.
The vulnerability affected the KAWPOW header validation process, allowing an attacker to bypass the normal memory-intensive mining process. By manipulating the nHeight field in the KAWPOW header, attackers could create blocks that carried no genuine ProgPoW work and were significantly cheaper to produce than honest blocks at the same difficulty.
The patch released by 2Miners rejects blocks whose declared header height differs from their actual chain position starting at 4,487,776. The project warned that a recovery chain being mined by 2Miners and RavenMiner could trigger a deep reorganization spanning approximately three days if it becomes dominant.