Critical Bug Impacting Litecoin, ZCash, Dogecoin and Other Networks Identified: Research

0

[ad_1]

Blockchain security firm, Halborn has detected several critical and exploitable vulnerabilities impacting more than 280 networks, including Litecoin (LTC) and Zcash (ZEC). Code-named “Rab13s,” this vulnerability has put over $25 billion of digital assets at risk.

This was first detected in the Dogecoin network a year ago, which was then fixed by the team behind the premier memecoin.

51% Attacks and Other Issues

According to the official blog post, Holborn researchers discovered the most critical vulnerability related to peer-to-peer (p2p) communications which, if exploited, can help attackers craft consensus messages and send them to individual nodes and take them offline. Eventually, such a threat could also expose networks to risks such as 51% attacks and other severe issues.

“An attacker can crawl the network peers using getaddr message and attack the unpatched nodes.”

The firm identified another zero-day which was uniquely related to Dogecoin, including an RPC (Remote Procedure Call) Remote code execution vulnerability impacting individual miners.

Variants of these zero-days were also discovered in similar blockchain networks, such as Litecoin and Zcash. While not all the bugs are exploitable in nature due to the differences in codebase between the networks, at least one of them could be exploited by attackers on each network.

In the case of vulnerable networks, Halborn said that successful exploitation of the relevant vulnerability could lead to denial of service or remote code execution.

The security platform believes that the simplicity of these Rab13s vulnerabilities increases the possibility of attack.

Upon further investigation, Halborn researchers found a second vulnerability in the RPC services that enabled an attacker to crash the node via RPC requests. But successful exploitation would require valid credentials. This reduces the possibility of the entire network being at risk because some nodes implement the stop command.

A third vulnerability, on the other hand, lets malicious entities execute code in the context of the user running the node through the public interface (RPC). The likelihood of this exploit is also low since even this requires a valid credential to carry out a successful attack.

Bug Exploits

Meanwhile, an exploit kit for Rab13s has been developed that includes a proof of concept with configurable parameters to demonstrate the attacks on various other networks.

Halborn has confirmed sharing all the necessary technical details with the identified stakeholders to help them remediate the bugs, as well as to release the relevant patches for the community and miners.

 

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
tron
TRON (TRX) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
monero
Monero (XMR) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
rain
Rain (RAIN) $ 0.000000
canton-network
Canton (CC) $ 0.000000
Shares