Skip to content
Blockchain

Why does a valid signature on one chain still authorize a transfer on another?

85

সুযোগ

Cross-chain bridges sign messages to authorize transfers, but most protocols do not include the destination chain ID or action type inside the signed payload itself. An attacker who sees a legitimate signed message can broadcast it to a different chain or replay it as a different action, and the receiving contract cannot distinguish the replay from a fresh authorization. The CrossCurve bridge lost $3M in February 2026 this way, and replay-class bridge incidents have totaled over $180M with a median six-week window from deployment to first exploit. ERC-7281 standardizes cross-chain token interfaces but does not mandate domain-separated signing across the broader message layer. No enforced standard today requires that every signed cross-chain payload carry a chain ID and action-type commitment that makes re-broadcasting structurally invalid.

কেন এটি গুরুত্বপূর্ণ

Domain-separated signing is the missing primitive that makes a signed cross-chain message valid exactly once on exactly one chain.

আমি কীভাবে সুযোগটি মূল্যায়ন করি

Opportunity Score হলো আমার নিজস্ব মূল্যায়ন, কোনো পরিমাপ নয়: এটি কতটা কষ্টের, কতবার সমস্যা তৈরি করে, এবং আজ এর সমাধান কতটা কম বিদ্যমান। বেশি স্কোর মানে আমার মতে এটি তৈরি করার বেশি মূল্য আছে।

তীব্রতা9/10

এটি উপস্থিত হলে কতটা ভোগান্তি সৃষ্টি করে।

ঘনত্ব7/10

মানুষ আসলে কতবার এটির মুখোমুখি হয়।

হোয়াইটস্পেস8/10

আজকের দিনে এর জন্য কতটা কম ভালো টুল রয়েছে।

সমাধানের যোগ্য আরও সমস্যা