The MadBrooks Sage

Replay Attacks: When Transactions Get Copied Across Chains

Sep 16, 2026 · 9:11 AM CT · 8:19 · The MadBrooks Sage | Replay Attacks | When Transactions Get Copied Across Chains | 9/16/2026

How chain splits can allow the same signed transaction to be valid on multiple networks, and the technical protections that prevent it. We'll examine chain ID, the history of Ethereum/Ethereum Classic replay issues, and how wallets protect users.

Apple Podcasts Spotify Pocket Casts RSS

Transcript

One signature, two worlds, and your transaction playing out on both—that's the nightmare scenario of a replay attack.

When you sign a transaction in the blockchain world, you're putting your cryptographic seal on a message that says something like "I want to send five tokens from my address to this other address." That signature is your authorization, your digital fingerprint proving you approved this specific action. But here's where things get philosophically strange and technically dangerous. If two blockchains are similar enough, that same signature, that same transaction, can be valid on both chains simultaneously. Someone can take your transaction from one chain, copy it, and broadcast it on another chain where you also have assets. You intended to send five tokens on chain A, but now you've also sent five tokens on chain B without ever meaning to. Your intention got duplicated across realities.

This is called a replay attack, and it's not theoretical. It's happened at scale, cost people real money, and forced the development of clever protections that now live invisibly inside every transaction you send.

Let's go back to July 2016. Ethereum was about to experience the most contentious moment in its history. The DAO had been hacked, and the community was split on whether to hard fork and reverse the theft. Some said the code is law, others said we can't let thieves win. The decision was made. Ethereum would fork, rolling back the hack. But not everyone agreed to follow. A group of miners and users stayed on the original chain, which became Ethereum Classic.

Suddenly there were two Ethereums. Two separate blockchains with identical histories up to the fork point, and crucially, users had the same amount of ETH on the new chain as they had ETC on the old chain. Same addresses, same private keys, same balances. Everything perfectly mirrored up until that split second when the chains diverged.

Here's where the replay problem emerged. Imagine you wanted to sell your Ethereum Classic because you believed in the new Ethereum. You send your ETC to an exchange. You sign the transaction with your private key. That transaction includes your address, the exchange's address, the amount, and some other data. But here's the thing—nothing in that transaction explicitly says "this is only for Ethereum Classic." The transaction format is identical on both chains. So someone, maybe the exchange itself, maybe a malicious observer, could take that exact transaction, the exact signed message, and broadcast it on the Ethereum network. Your signature would still be valid because the math checks out. The addresses exist on both chains. The result? You've now sent both your ETC and your ETH to the exchange, when you only intended to send one.

This happened to people. They'd move coins on one chain and watch in horror as the same transaction executed on the other chain, draining both. Some exchanges actually exploited this, intentionally replaying customer transactions to claim both coins when customers only meant to deposit one. It was chaos, and it revealed a fundamental truth about blockchain architecture. Signatures alone aren't enough. Context matters. A transaction needs to know which reality it belongs to.

The solution already existed in theory but hadn't been needed until chains started splitting. It's called Chain ID, and it's elegantly simple. Every blockchain network gets a unique identifier, a number. Ethereum mainnet is one. Ethereum Classic is sixty-one. Binance Smart Chain is fifty-six. When you sign a transaction now, your wallet includes this Chain ID in the data being signed. The signature mathematically commits to that number. If someone tries to replay your transaction on a different chain with a different Chain ID, the signature becomes invalid. The math doesn't work anymore. It's like signing a check and writing "only valid at this specific bank"—try to cash it somewhere else and the signature fails verification.

This protection was formalized in EIP-155, proposed by Vitalik Buterin himself in October 2016, just months after the Ethereum Classic split. It wasn't a new invention exactly, but it was the standardization of replay protection that made it universal. After EIP-155 was activated, every transaction on Ethereum included the Chain ID in its signature. You literally cannot sign a valid Ethereum transaction that could be replayed on Ethereum Classic anymore. The chains have different IDs, so the signatures are incompatible.

Think of it like this. Imagine two parallel universes that split from a common origin point. In one universe, you sign a letter agreeing to sell your car. In the parallel universe, you also own that same car because history was identical up until the split. Without any protection, someone could take your signature from universe one and use it in universe two, claiming you agreed to sell your car there too. Chain ID is like writing "This signature only valid in Universe One" directly into the signature itself. The signature becomes universe-specific, reality-specific.

But here's where it gets more subtle. Chain ID only works if it's implemented from the start or if there's coordination around a split. When Ethereum and Ethereum Classic split, there was no Chain ID yet, so both chains were vulnerable. When Bitcoin Cash split from Bitcoin, similar issues emerged because Bitcoin doesn't use the same signature scheme. The Bitcoin Cash developers implemented something called strong replay protection, which changed the signature algorithm slightly so that Bitcoin and Bitcoin Cash signatures were fundamentally incompatible. Different approach, same goal—make it impossible for a transaction on one chain to be valid on another.

Modern wallets do even more to protect you. When you initiate a transaction, your wallet automatically includes the Chain ID for the network you're on. You never see it, never think about it, but it's there in every transaction you send. If you switch networks in MetaMask from Ethereum to Polygon, the Chain ID changes automatically. Your signatures become network-specific without any action on your part.

There's a deeper lesson here about digital scarcity and intention. When we talk about blockchain as a way to establish scarcity in digital space, we usually think about preventing double-spending within a single chain. You can't send the same Bitcoin twice because the network validates each transaction against a single ledger. But when chains split, you suddenly have two ledgers, two realities, and the same digital asset existing in both. Without replay protection, your actions in one reality automatically manifest in the other. You lose the ability to treat them as truly separate things.

Chain ID restores that separation. It says your intention is specific to a context, to a particular network with a particular history and particular rules. Your signature doesn't just prove you authorized an action in the abstract—it proves you authorized this action on this specific chain in this specific digital universe.

Most users will never think about replay attacks. They'll never know that every transaction they sign includes a number that ties it to one specific network. That's good design. The protection is invisible, automatic, built into the infrastructure. But when new chains fork, when projects split, when communities divide, this question comes up again. Did they implement replay protection? Are transactions safe to send on one chain without fear of losing assets on the other?

It's worth knowing this architecture exists, worth understanding that the signature you create isn't context-free. It's bound to a specific network by design, protecting you from the strange edge cases that emerge when blockchain realities multiply.

See you Thursday. Your signature doesn't live in the abstract—it belongs to exactly one chain.

← Transaction Graph Analysis: Following the Flow of FundsDust Attacks: Tracking Privacy Through Tiny Transactions →

AI generated. Not financial advice.