Skip to content
Blockchain

Why does a valid signature on one chain still authorize a transfer on another?

85

기회

Cross-chain bridges sign messages to authorize transfers, but most protocols do not include the destination chain ID or action type inside the signed payload itself. An attacker who sees a legitimate signed message can broadcast it to a different chain or replay it as a different action, and the receiving contract cannot distinguish the replay from a fresh authorization. The CrossCurve bridge lost $3M in February 2026 this way, and replay-class bridge incidents have totaled over $180M with a median six-week window from deployment to first exploit. ERC-7281 standardizes cross-chain token interfaces but does not mandate domain-separated signing across the broader message layer. No enforced standard today requires that every signed cross-chain payload carry a chain ID and action-type commitment that makes re-broadcasting structurally invalid.

μ™œ μ€‘μš”ν•œκ°€

Domain-separated signing is the missing primitive that makes a signed cross-chain message valid exactly once on exactly one chain.

기회 평가 방식

기회 μ μˆ˜λŠ” 츑정값이 μ•„λ‹Œ 제 주관적 ν‰κ°€μž…λ‹ˆλ‹€. μ–Όλ§ˆλ‚˜ λΆˆνŽΈν•œμ§€, μ–Όλ§ˆλ‚˜ 자주 λ°œμƒν•˜λŠ”μ§€, ν˜„μž¬ 해결책이 μ–Όλ§ˆλ‚˜ λΆ€μ‘±ν•œμ§€λ₯Ό λ°˜μ˜ν•©λ‹ˆλ‹€. μ μˆ˜κ°€ λ†’μ„μˆ˜λ‘ λ§Œλ“€ κ°€μΉ˜κ°€ 더 λ†’λ‹€κ³  μƒκ°ν•©λ‹ˆλ‹€.

심각도9/10

λ°œμƒν–ˆμ„ λ•Œ μ–Όλ§ˆλ‚˜ 큰 λΆˆνŽΈμ„ μ΄ˆλž˜ν•˜λŠ”μ§€.

λΉˆλ„7/10

μ‹€μ œλ‘œ μ–Όλ§ˆλ‚˜ 자주 μ ‘ν•˜κ²Œ λ˜λŠ”μ§€.

곡백 μ˜μ—­8/10

ν˜„μž¬ 이λ₯Ό ν•΄κ²°ν•  λ§Œν•œ 도ꡬ가 μ–Όλ§ˆλ‚˜ λΆ€μ‘±ν•œμ§€.

ν•΄κ²°ν•  κ°€μΉ˜ μžˆλŠ” 더 λ§Žμ€ λ¬Έμ œλ“€