About $20 mln worth of Ethereum have reportedly been stolen by a group of hackers, exploiting misconfigured Ethereum clients, according to a Bleeping Computer article published June 11.The hackers were able access applications using the Ethereum software which configured their interface to expose a Remote Procedure Call.
The RPC interface allows third parties to query, interact with, and retrieve data from the Ethereum-based service, meaning those with access could get private keys, see the owner's personal information, and even move funds.
While most apps disable this interface by default, and even when it is turned on, it is usually configured to only allow access to apps that are run locally.
Developers do not always keep this configuration and sometimes reconfigure their Ethereum clients without knowing the danger.
The Ethereum project has long known about the potential for exploiting this vulnerability and sent out an official security advisory as a warning to its users back in August 2015, indicating that the likelihood of an attack was low, but its potential severity was high.
According to Bleeping Computer, the Chinese cyber-security firm Qihoo 360 Netlab identified in March that at least one "Threat actor" was making mass-scans for exposed Ethereum software with RPC interfaces specifically on port 8545.
At the time, 360 Netlab said in a tweet that, "[so] far it has only got 3.96234 Ether on its account, but hey it is free money!".
On June 11, after reviewing the research again, the team from Netlab said that the scans for port 8545 never stopped, but actually increased as more "Threat actors" joined in.
At the time of posting, neither the Ethereum team, nor the co-founder Vitalik Buterin responded to a request for comment.
Report: Misconfigured Ethereum Clients Have Resulted in Hack of Around $20 Mln
에 게시 됨 Jun 13, 2018
by Cointele | 에 게시 됨 Coinage
Coinage
이 기사에서 언급
최근 뉴스
모두보기
First Mover: What's Next for Bitcoin as Wall Street Gets Vaccine Booster
Bitcoin was higher for a second day, staying in a range of between roughly $15,200 and $15,600, as news of progress in developing a coronavirus vaccine appeared to touch off a rally in U.S. stocks.
Market Wrap: Bitcoin Fails to Break $15.9K; Over 50K ETH Staked on Eth 2.0 Contract
Bitcoin gained Wednesday while Ethereum 2.0 staking has been ramping up.
Citibank Analyst Says Bitcoin Could Pass $300K by December 2021
A senior analyst at U.S.-based financial giant Citibank has penned a report drawing on similarities between the 1970s gold market and bitcoin.
Blockchain Bites: Data Unions. Hard Forks. And One Citi Analyst's Case for $300K BTC.
A Citibank managing director thinks bitcoin could hit $318,000.