Definition
A replay attack exploits insufficient checks on the reuse or context of an authenticated message. The attacker does not necessarily need to discover the signing key: an existing valid signature can be enough if the receiving system accepts it again. In blockchain applications, replay can arise across chains, between contracts, or within an application that fails to track whether an authorization has already been used.
How It Works
A transaction or signed request should be bound to its intended context, such as a network, contract, operation, and sequence number. Chain identifiers help separate transaction signatures between networks, while nonces and used-message records help prevent repeated execution. Application-level signatures need their own suitable protections; a network’s transaction-level replay protection does not automatically secure every message an application asks a user to sign.
Key Considerations
After a chain split, compatible signing formats without adequate separation can create a risk that an action on one branch is accepted on another. The exact risk depends on the chains and transaction types involved. Developers should use established signature standards, clear domain separation, and correctly enforced freshness or one-time-use rules. Users should review the requested network and signing purpose and avoid assuming that a signature is harmless because it has no immediate fee. Replay protection prevents unauthorized reuse; it does not make the originally authorized operation safe or desirable.