VYPR
High severityNVD Advisory· Published Jan 21, 2020· Updated Aug 4, 2024

CVE-2020-6638

CVE-2020-6638

Description

Grin through 2.1.1 has Insufficient Validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insufficient validation in Grin through 2.1.1 allows block malleability, enabling chain splits; fixed in v3.0.0.

Vulnerability

CVE-2020-6638 is a consensus protocol vulnerability in Grin through version 2.1.1, caused by insufficient validation of block inputs. This flaw allows a malicious node to produce two distinct valid blocks that are otherwise identical, differing only in the exact set of outputs being spent, a condition referred to as block malleability [1].

Exploitation

To exploit, an attacker must control a node on the network and craft two variants of a block that both pass consensus rules. The malleability can then be used to introduce a chain split, where different parts of the network accept different blocks as the canonical chain [1]. No authentication or specific network position is required beyond being a peer.

Impact

A successful chain split could enable subsequent attacks on users, such as double-spending or disrupting services, if users are caught on the wrong side of the split [1]. However, the attack is exceptionally difficult to execute in practice, and there is no evidence of it ever being exploited [1][3].

Mitigation

The vulnerability was fixed in Grin version 3.0.0, which was released as part of a scheduled hard fork on January 15, 2020 [1]. Users running v3.0.0 or later are not affected. No additional action is required from node operators or wallet users [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
grincrates.io
< 3.0.03.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.