Critical vulnerability in Monero – original



➠ A bug was found in Monero P2Pool that allowed Monero miners to work not for themselves, but for a hacker’s wallet.

➠ On June 10, the developer warned about a critical consensus vulnerability in all P2Pool versions up to 4.16 and announced a patch for June 13.

➠ On June 13, P2Pool v4.16 was released with the fix. Miners needed to update and restart their nodes.

➠ June 15–16 — the vulnerability began to be actively exploited. First, the Mini and Nano chains were targeted, then Main.

➠ The essence of the attack: the attacker could take one miner’s share of participation in the pool, create thousands of fake copies, flood the payout window with them, and claim up to 80-100% of the block reward.

➠ Wallets and the XMR that had already been received are not hacked. But miners who didn’t update in time lost future payouts—their hash rate effectively worked for the attacker.
NANO-3.07%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned