Now Swiss can registrate on Ethereum blockchain

Uport made user-centric data platform on the Ethereum for Zug’s citizens
24 November 2017

Recently Uport could ensure digital registration in partnership with Zug. This new opportunity is historically important, since it demonstrates the possibility of verifying digital citizenship by the government with the help of the Ethereum blockchain.

To register Zug’s citizen would download the Uport app and register his Uport ID on the Ethereum blockchain. It is creating a global identifier. This address is a smart contract. Citizen uses newly registered Uport ID to sign in to the Zug ID web portal with scanning a QR code. The Zug web portal is authenticated, the citizen enters a pre-existing Zug ID number along with personal information. This requires in-person verification by a city administrator. Then citizen gets 14 days to visit the Zug office with an official government ID document. Any authorized official can then cross check the citizen's information and his documents. If the application is approved, the citizen receives a Uport citizenship ID.

The development of digital citizenship can increase trust between government and citizens. It also provides opportunities for better digital interactions among them. Then in the Spring of 2018 Zug are going to develop an e-voting initiative.

Coinbase Bug to Provide Unlimited Ethereum

The bug was found by VI Company in December last year
21 March 2018

VI Company reported the discovery of a vulnerability in the system of smart contracts of the Coinbase exchange, which allowed users to credit an unlimited amount of ETH to their accounts. Experts informed the company about the vulnerability in December last year, and in January it was eliminated. For their work, VI Company employees received an award of $ 10,000. This is reported by The Next Web.

By using a smart contract to distribute ether over a set of wallets you can manipulate the account balance of your Coinbase account. If 1 of the internal transactions in the smart contract fails all transactions before that will be reversed. But on Coinbase these transactions will not be reversed, meaning someone could add as much ether to their balance as they want. When you look up the Coinbase wallet address after this transaction you will see that it is empty, but checking your Coinbase wallet will show your funds.

VI Company Report

In practice, this means that Coinbase users were able to enroll any amount of Ethereum on their accounts.

Researchers provided screenshots showing how Ethereum was credited to their account using the cancellation of the transaction.

Coinbase Bug


Steps to reproduce, provided by the researchers :

  • Setup a smart contract with a few valid Coinbase wallets and 1 final faulty wallet (always throw exception when receiving funds smart contract for example)
  • Transfer appropriate funds to smart contract.
  • Execute smart contract adding the set amount of ether to the Coinbase wallets without ever actually leaving the smart contract wallet because the complete transaction fails at the last wallet.
  • Repeat until you have more than enough ethereum in your Coinbase wallet.
  • Cash out, transfer to off site wallet.

Whether any of the users could detect and take advantage of this vulnerability for their own enrichment is unknown.