NURGLE: Exacerbating Resource Consumption in Blockchain State Storage via MPT Manipulation
Zheyuan He, Zihao Li, Ao Qiao, Xiapu Luo, Xiaosong Zhang, Ting Chen
IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 6
Overview
This talk, titled "NURGLE: Exacerbating Resource Consumption in Blockchain State Storage via MPT Manipulation," introduces a novel and insidious Denial of Service (DoS) attack targeting the fundamental state storage mechanisms of popular blockchain platforms like Ethereum and Binance Smart Chain (BSC). Presented by Zheyuan He, a master's student from the University of Electronic Science and Technology of China, alongside collaborators from The Hong Kong Polytechnic University and S group, the research uncovers a critical vulnerability rooted in the widely adopted Merkle Patricia Trie (MPT) data structure. The core of the attack lies in strategically manipulating the MPT to inflate its structural complexity, thereby forcing blockchains to consume significantly more computational resources for essential state maintenance and verification.

Key moments
- 0:00 Introduction to Nurgle: A new DoS attack targeting MPT
- 1:18 Core attack idea: Introduce many intermediate MPT nodes
- 2:00 Persistent resource consumption is a key attack characteristic
- 4:10 How inserting nodes triggers MPT node splitting
- 5:05 Two key observations guiding the vulnerability discovery
- 6:00 Flaw in gas mechanism enabling the Nurgle attack
- 7:58 Evaluation results: Significant impact on Ethereum resources
- 9:20 Summary: Novel attack and new blockchain attack surface
NURGLE: Exacerbating Resource Consumption in Blockchain State Storage via MPT Manipulation
Speakers: Zheyuan He, Master Student, University of Electronic Science and Technology of China; Zihao Li; Ao Qiao; Xiapu Luo; Xiaosong Zhang; Ting Chen
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=m9_EyF39j6o
Overview
This talk, titled "NURGLE: Exacerbating Resource Consumption in Blockchain State Storage via MPT Manipulation," introduces a novel and insidious Denial of Service (DoS) attack targeting the fundamental state storage mechanisms of popular blockchain platforms like Ethereum and Binance Smart Chain (BSC). Presented by Zheyuan He, a master's student from the University of Electronic Science and Technology of China, alongside collaborators from The Hong Kong Polytechnic University and S group, the research uncovers a critical vulnerability rooted in the widely adopted Merkle Patricia Trie (MPT) data structure. The core of the attack lies in strategically manipulating the MPT to inflate its structural complexity, thereby forcing blockchains to consume significantly more computational resources for essential state maintenance and verification.
The significance of this work stems from its ability to inflict persistent and long-term damage, a stark contrast to many previous DoS attacks that are transient in nature. By inducing permanent changes to the MPT structure, the "NURGLE" attack ensures that the increased resource consumption endures indefinitely for all future transactions interacting with the manipulated state. This persistent aggravation of operational costs poses a substantial threat to the scalability, efficiency, and economic viability of MPT-based blockchain networks, demanding immediate attention from developers and researchers alike.
The researchers highlight two critical observations that underpin this vulnerability: the disproportionately heavy burden of state maintenance on overall blockchain performance, and a fundamental flaw in current gas mechanisms that fail to accurately reflect the actual resource consumption associated with MPT operations. These insights reveal a systemic weakness that attackers can exploit to degrade blockchain performance and increase operational overhead without incurring prohibitive costs themselves, making the NURGLE attack a potent new vector for resource exhaustion.
Background
▶ Watch: Introduction to Nurgle: A new DoS attack targeting MPT (0:00)
Blockchain networks rely on state storage to maintain critical information such as account balances, smart contract data, and nonces. This persistent state is constantly updated as transactions are processed and new blocks are added to the chain. For many prominent blockchains, including Ethereum, this state is managed using a specialized tree-like data structure known as the Merkle Patricia Trie (MPT). The MPT is a cryptographic accumulator that allows for efficient and secure verification of state changes, where each leaf node stores the actual value of a state data (e.g., an Ether balance), and the path from the root node to a leaf node corresponds to the key of that value (e.g., an account address).
The MPT structure is composed of three primary node types:
- Extension Nodes: These nodes contain a byte sequence that represents a common prefix shared by multiple keys, pointing to a subsequent node in the trie. They act as a compression mechanism.
- Branch Nodes: These are 17-entry arrays (16 for hex characters 0-F, and one for the value if the current node itself is a key). Each of the 16 pointers can point to another node, allowing for branching based on the next hexadecimal character in the key.
- Leaf Nodes: These nodes store the actual key-value pair of the state data, marking the end of a path in the trie.
The efficiency of MPT operations – such as inserting, updating, or deleting state data – is directly tied to the depth and complexity of the trie. When a new leaf node is inserted into an MPT, especially if its key shares a partial prefix with an existing key but then diverges, it can trigger a process known as node splitting. For instance, if an existing leaf node 12F is present, and a new node 123 is inserted, the original 12F node might be split, requiring the creation of new extension nodes, branch nodes, and additional leaf nodes to accommodate both 12F and 123. This splitting process increases the number of intermediate nodes that must be traversed and managed, thereby escalating the resources required for subsequent state maintenance and verification operations.
The problem, as identified by the researchers, stems from two critical observations regarding blockchain resource management:
Firstly, the heavy burden of state maintenance: A significant portion of a blockchain's execution time is dedicated to interacting with the MPT. Recent studies, cited by the researchers, indicate that over 80% of blockchain execution time is spent on these MPT-related operations. Furthermore, the time required for MPT interactions increases linearly with the number of involved MPT nodes. This highlights the MPT as a major performance bottleneck.
Secondly, a fundamental flaw in the gas mechanism: Current gas models, which are designed to meter computational resources, do not adequately account for the actual resources consumed during MPT operations, particularly those involving node splitting and structural changes. The talk provides an example: two transactions might transfer Ether from Account 1 to Account 3, and from Account 1 to Account 2, respectively. According to Ethereum's gas specification, these transactions might cost the same amount of gas. However, if the first transaction modifies six MPT nodes while the second modifies nine, the actual resource consumption differs significantly. This discrepancy arises because the gas mechanism often focuses on high-level operations (e.g., storage writes) rather than the granular, underlying MPT node manipulations. This flaw creates an economic arbitrage opportunity for attackers to induce disproportionately high resource costs on the network for a relatively low gas expenditure.
Key Findings
▶ Watch: Persistent resource consumption is a key attack characteristic (2:00)
The central discovery presented in this research is the identification and practical demonstration of a novel Denial of Service (DoS) attack, dubbed "NURGLE," that specifically targets the Merkle Patricia Trie (MPT), the foundational state storage structure in many blockchains. The core contribution is the realization that by strategically manipulating the insertion of new state data, an attacker can trigger excessive node splitting within the MPT. This process introduces a significantly larger number of intermediate nodes than would occur under normal operation, thereby inflating the trie's complexity.
Unlike many transient DoS attacks, the NURGLE attack introduces a persistent aggravation of resource consumption. Once the MPT structure is expanded through node splitting, these additional intermediate nodes remain a permanent part of the state. Consequently, all future transactions that interact with the affected portions of the state will inherently require more computational resources for traversal, lookup, and updates. This means the attack's impact is not limited to its duration of launch but continues to burden the blockchain indefinitely, leading to a sustained degradation of performance and increased operational costs for validators and full nodes.
The researchers base their attack design on two crucial observations:
- The Heavy Burden of State Maintenance: They found that MPT operations constitute a major performance bottleneck for blockchains. Empirical evidence suggests that over 80% of a blockchain's execution time is spent interacting with the MPT. Crucially, the time required for these interactions scales linearly with the number of MPT nodes involved. This makes any inflation of the MPT's size a direct and significant hit to performance.
- The Flaw of the Gas Mechanism: A critical enabler for the NURGLE attack is the inadequacy of current gas metering systems. The existing gas models do not accurately reflect the true resource cost associated with modifying the MPT's internal structure. As demonstrated by the example of two transactions costing the same gas but modifying different numbers of MPT nodes (six vs. nine), the gas price paid by an attacker does not correlate directly with the underlying computational effort required to process MPT changes. This allows an attacker to pay a relatively low fee to trigger expensive structural changes within the MPT, making the attack economically viable and disproportionately impactful.
In essence, the key finding is that the combination of MPT's structural properties, its central role in blockchain performance, and the current gas mechanism's blind spots creates a potent and persistent DoS vulnerability that can severely impair the long-term efficiency and cost-effectiveness of targeted blockchain platforms.
Technical Deep Dive
▶ Watch: Two key observations guiding the vulnerability discovery (5:05)
The NURGLE attack leverages a sophisticated understanding of the Merkle Patricia Trie (MPT) structure and its interaction with state modifications. The fundamental technical strategy is to induce maximal node splitting within the MPT through carefully crafted transaction sequences. When new key-value pairs are inserted into the MPT, the trie structure must adapt to accommodate them. If a new key shares a long prefix with an existing key but then diverges, the MPT algorithm dictates that the common prefix must be handled by an extension node, followed by a branch node at the point of divergence, leading to separate paths for the original and new keys. This process inherently increases the number of intermediate nodes.
Consider the example provided in the talk: an existing MPT contains two leaf nodes, Node 1 and Node 2. If an attacker then inserts a new Node 3, whose key is carefully chosen to create a conflict or partial overlap with existing keys, it can trigger a cascade of structural changes. Specifically, if an original leaf node, say represented by the path 12F, needs to accommodate new keys like 123 or 12E, the single 12F leaf node will be "split." This splitting involves the creation of a new extension node to represent the common prefix (12), followed by a branch node to handle the divergence (F, 3, E, etc.). From this branch node, new leaf nodes (e.g., for 12F, 123, 12E) or further extension/branch nodes will emerge. The result is a substantial increase in the total number of nodes in the MPT for the same amount of state data.
The attacker's goal is to maximize this intermediate node creation. This is achieved by generating a series of transactions that update or insert state entries with keys designed to:
- Share common, but not identical, prefixes: This forces the MPT to create extension nodes for the shared prefix.
- Diverge at specific, strategic points: This forces the creation of branch nodes, which then point to new sub-tries or leaf nodes.
- Create dense branches: By targeting specific hexadecimal nibbles (0-F) within a branch node, an attacker can ensure that a single branch node points to many different sub-branches, further increasing complexity.
The persistent nature of the attack is a critical technical aspect. Once these additional nodes are introduced into the MPT, they become an integral part of the blockchain's state. They are not temporary structures; they are committed to the ledger. This means that every subsequent operation that needs to traverse or update the affected parts of the MPT will incur the additional cost of navigating these inflated structures. This includes block verification, transaction processing, and state root computations. The researchers noted that for all future transactions involving the nodes introduced by their attack, "the time and resource cost of their state modifications is persistently read."
The fundamental technical enabler for this attack is the aforementioned flaw in the gas mechanism. Blockchain gas models, particularly in Ethereum, are designed to prevent network abuse by charging for computational steps. However, the current model assigns gas costs based on broad categories of operations (e.g., SSTORE for writing to storage, SLOAD for reading). It does not granularly account for the internal structural changes within the MPT that these operations might trigger. For example, an SSTORE operation that causes extensive node splitting might cost the same gas as an SSTORE that simply updates an existing leaf node without structural changes. This disconnect means an attacker can strategically construct transactions that are cheap in terms of gas but extremely expensive in terms of the underlying MPT node operations, leading to an effective resource exhaustion attack at minimal cost to the attacker. The example of two transactions consuming different numbers of MPT nodes (six versus nine) for the same gas cost perfectly illustrates this technical loophole. The attacker exploits this economic asymmetry to externalize significant resource costs onto the network's validators.
Demo / Proof of Concept
▶ Watch: Flaw in gas mechanism enabling the Nurgle attack (6:00)
The researchers conducted extensive experiments and evaluations to demonstrate the practical viability and impact of the NURGLE attack. While the presentation did not detail the specific step-by-step execution of a "demo" in a live environment, it presented compelling results from their proof-of-concept implementation and evaluation on real blockchain platforms.
The primary evaluation focused on the impact of the attack on the Ethereum network. By manipulating the MPT over a simulated period of 10,000 blocks, the attackers were able to introduce a substantial increase in the MPT's complexity. Specifically, their crafted transactions resulted in 1.11 times more intermediate nodes being introduced into the MPT than would have occurred under normal, non-adversarial conditions. This structural inflation directly translated into a significant resource overhead for the blockchain. The evaluation showed that Ethereum had to spend 11% more resources to handle these manipulated nodes within the MPT. This 11% increase represents a persistent and ongoing overhead for all MPT-related operations, highlighting the long-term performance degradation.
Beyond Ethereum, the researchers also successfully launched their attack on two public testnets—likely an Ethereum testnet (e.g., Sepolia or Goerli at the time of research) and the Binance Smart Chain (BSC) testnet. On both platforms, the evaluation clearly demonstrated that "the number of MPT nodes involved for updating a live node increases significantly after the launching of our [the] attack." This observation confirms that the attack's mechanism of inducing node splitting and expanding the MPT is effective across different blockchain implementations that rely on the Merkle Patricia Trie for state storage. The result was consistent: both blockchain platforms were forced to "spend more resources in handling those MPT nodes manipulated by our attack."
Crucially, the evaluation emphasized the persistent nature of the damage. The increased resource cost for state modifications is not temporary; it endures for all future transactions that interact with the parts of the MPT that were expanded by the attack. This demonstrates that the NURGLE attack is not merely a transient flood of transactions, but rather a structural modification that leaves a lasting footprint on the blockchain's operational efficiency. While the talk did not disclose specific tool names or the exact smart contract code used for the manipulation, the results provide concrete evidence of the attack's feasibility and its quantifiable impact on resource consumption.
Defensive Implications
▶ Watch: Summary: Novel attack and new blockchain attack surface (9:20)
The NURGLE attack exposes a critical architectural vulnerability in blockchains relying on Merkle Patricia Tries (MPT) for state storage, particularly when combined with an imperfect gas mechanism. Defending against such a persistent resource exhaustion attack requires a multi-faceted approach, addressing both the immediate symptoms and the underlying causes.
The most direct implication for defenders is the urgent need to re-evaluate and revise current gas models. The core of the economic vulnerability lies in the disconnect between the gas cost of an operation and its actual computational cost in terms of MPT node manipulations. Future gas mechanisms should be designed to account for the granular impact on the MPT structure. This could involve:
- Dynamic Gas Pricing for MPT Operations: Introducing gas charges that scale with the number of new MPT nodes created, existing nodes modified, or the depth of the trie traversed during an operation.
- Node Splitting Penalties: Implementing specific, higher gas costs for operations that trigger MPT node splitting, making it economically prohibitive for attackers to inflate the trie.
- State Size Considerations: Potentially incorporating a penalty for increasing the overall state size, though this is a more complex measure with broader implications.
Beyond gas mechanism adjustments, defenders should consider proactive monitoring of MPT growth and complexity. Full nodes and validators could implement heuristics or metrics to detect anomalous rates of MPT node creation or unusual increases in trie depth/breadth within specific sub-tries. Early detection of such patterns could trigger alerts or even temporary transaction throttling mechanisms for suspicious addresses.
From a long-term perspective, the NURGLE attack highlights the limitations of the current MPT structure under adversarial conditions. This necessitates further research into alternative state storage structures or resilient MPT variants. While the MPT offers strong cryptographic guarantees and efficient lookups, its susceptibility to structural inflation due to node splitting is a significant drawback. Future blockchain designs or upgrades might explore:
- Flat State Storage: Moving away from tree-based structures for certain types of state, if feasible without compromising cryptographic integrity.
- Optimized Trie Structures: Investigating MPT variants that are more resistant to adversarial key insertions, perhaps by employing different branching factors or node aggregation strategies.
- State Pruning and Archiving: While not directly preventing the attack, more aggressive state pruning or efficient archiving of historical state could help manage the overall size burden, though the persistent cost for active state remains.
Finally, the attack underscores the importance of comprehensive security audits that not only review smart contract logic but also delve into the underlying data structures and their interaction with the blockchain's economic model. Understanding how low-level operations translate into resource consumption is crucial for identifying and mitigating such sophisticated DoS vectors. The persistent nature of the NURGLE attack means that once the damage is done, it is extremely difficult to reverse, making proactive defense and robust economic metering paramount.
Key Takeaways
- Novel Persistent DoS Attack: The NURGLE attack introduces a new type of Denial of Service that persistently aggravates resource consumption in MPT-based blockchains by manipulating state storage.
- MPT Node Splitting Exploitation: The attack exploits the Merkle Patricia Trie (MPT)'s mechanism of node splitting, forcing the creation of numerous intermediate nodes through strategically crafted transactions.
- Flawed Gas Mechanism: A critical enabler for the attack is the current gas mechanism's failure to accurately account for the actual computational resources consumed by MPT structural changes, allowing attackers to cause significant damage for low cost.
- Significant Resource Overhead: Evaluations showed that the attack can introduce 1.11 times more intermediate MPT nodes, causing platforms like Ethereum to spend 11% more resources on state maintenance and verification.
- Persistent Impact: Unlike many transient DoS attacks, the structural changes induced by NURGLE are permanent, leading to a sustained and long-term degradation of blockchain performance and increased operational costs.
- Urgent Need for Gas Model Revision: Defenders must revise gas mechanisms to reflect granular MPT operations and consider penalties for node splitting to mitigate this persistent threat.
About the Speaker(s)
The talk was presented by Zheyuan He, identified as a master's student from the University of Electronic Science and Technology of China. The research behind "NURGLE" was a collaborative effort, involving researchers from the University of Electronic Science and Technology of China, The Hong Kong Polytechnic University, and the S group. The listed co-authors for this work include Zihao Li, Ao Qiao, Xiapu Luo, Xiaosong Zhang, and Ting Chen. Their collective expertise in blockchain security and systems research contributed to uncovering this novel attack vector.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research unveils NURGLE, a truly insidious and novel persistent DoS attack that exploits the Merkle Patricia Trie's structural properties and gas mechanism flaws in platforms like Ethereum. By strategically forcing node splitting, it inflates state storage complexity, leading to an enduring 11% resource overhead. This isn't theoretical; it's a critical, demonstrable vulnerability demanding immediate attention and gas model revisions.
Heather Calloway (CISO) — STRONG ACCEPT
This research uncovers a critical, persistent Denial of Service vulnerability in MPT-based blockchains, rooted in a fundamental flaw in gas metering that allows attackers to inflate state storage costs indefinitely. It presents a clear institutional failure in economic design, demanding immediate governance action.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024