So.... what are SR2 saying happened here? - Is it a double spend using SR2 escrow bitcoins? - How was the malleability introduced?
So.... what are SR2 saying happened here? - Is it a double spend using SR2 escrow bitcoins? - How was the malleability introduced?
The second issue is a bug that was discovered in the reference client where if you try to spend coins you sent to yourself before they are confirmed a bug in the wallet causes your balance to be off.
Neither problem inherently allows theft but if you aren't careful the first can open your to social engineering. The reason they are calling this a dos as far as I can tell is because they are preventing you from spending your money until the bug is fixed with the accounting in the reference wallet.
SR2 is probably full of crap but there is a small possibility that they some how automated re-sending of failed transactions w/o properly accounting for malleability in which case you might be able to steal a multiple of the actual amount of money in your account over a few days. The sheer size of this though would make me skeptical of that scenario.
This isn't really a malleability issue however. Lets say it wasn't successful: You send again. Opps, someone pulls the original out of a hat and both go through.
The only way to safely reissue is to double spend the original transaction. Then you get atomic exclusion, and it's completely safe: only one can possibly get into the longest chain. This safety still applies if there is mutation going on.