Potential Witness Malleability Ordering Attack #210
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Witness Malleability Ordering Attack
Attack Mechanics
You're a miner. You create TX-Alpha-W1 and TX-Alpha-W2, same txid, different wtxid. You include both in the same block you mine. Bitcoin doesn't care, both are valid transactions with different wtxids, and Bitcoin deduplicates by wtxid not txid at the block level.
If OPNet orders by txid, it now has two transactions with identical ordering keys. The priority queue or sorting logic has two entries that compare equal on txid. The behavior is undefined or implementation-dependent, different nodes might process them in different orders based on insertion order, memory layout, or however the sort handles duplicates.
Potential Outcome
Consensus divergence. Some nodes execute W1 first, some execute W2 first. If contract state depends on execution order, network splits.