New releases remediate reminiscence exhaustion vulnerability in Zcash

on

|

views

and

comments


Releases 5.3.3 and 5.4.2 harden zcashd code and remediate vulnerabilities inherited from Bitcoin Core that will have affected greater than 280 chains, in keeping with blockchain safety agency Halborn.

We now have no proof that an exploit has occurred on the Zcash community, and these bugs don’t compromise person privateness or affect Zcash provide. As at all times, in the event you discover any uncommon exercise in your node, please report it to [email protected]

All Zcash node operators on 5.3.1 or 5.3.2 ought to replace to 5.3.3 instantly, and all Zcash node operators on 5.4.0 or 5.4.1 ought to replace to 5.4.2 instantly. Prebuilt binaries and Debian packages might be obtainable within the subsequent few hours.

The vulnerabilities, found by Halborn in a 2022 audit of Dogecoin, have been first disclosed to ECC and contributors to different affected networks on Feb. 14, and extra particulars have been relayed in a Feb. 17 name. ECC initiated our safety course of instantly and started coordinating with ZecSec.com, the unbiased Zcash-community-funded safety group, and with Zcash Basis, who analyzed the affect on zebrad, its personal implementation of a Zcash node. We additionally reached out to Horizen, Komodo, and different groups with whom we’ve disclosure agreements.

Inside days, we had zcashd patches prepared for third-party testing, however the public releases have been delayed to permit different tasks time to finish their very own remediations and to permit for coordinated comms, given the delicate nature.

Halborn discovered that the bugs might permit an attacker to make the most of peer-to-peer community messages to fill the reminiscence of a node and crash it. By crashing different individuals’s mining nodes, an attacker might probably cut back, by round one half, the quantity of hashpower they would wish to mount a 51% assault on the Zcash community. A profitable 51% assault might probably be used to execute a double-spend assault, which might end in customers who acquired transactions from the attackers dropping their funds. We now have no purpose to consider that the Zcash community is at present susceptible to a 51% assault — with or with out the “one half low cost” on the assault price — however out of an abundance of warning, we’ve hardened the zcashd nodes in order that they can’t be crashed utilizing this bug.

ECC has a document of quick, coordinated responses to incidents like this and is well-known for delivering secure and safe know-how for Zcash customers and different privacy-minded tasks. For our newest information and product updates, please comply with @electriccoinco on Twitter.

Share this
Tags

Must-read

Nvidia CEO reveals new ‘reasoning’ AI tech for self-driving vehicles | Nvidia

The billionaire boss of the chipmaker Nvidia, Jensen Huang, has unveiled new AI know-how that he says will assist self-driving vehicles assume like...

Tesla publishes analyst forecasts suggesting gross sales set to fall | Tesla

Tesla has taken the weird step of publishing gross sales forecasts that recommend 2025 deliveries might be decrease than anticipated and future years’...

5 tech tendencies we’ll be watching in 2026 | Expertise

Hi there, and welcome to TechScape. I’m your host, Blake Montgomery, wishing you a cheerful New Yr’s Eve full of cheer, champagne and...

Recent articles

More like this

LEAVE A REPLY

Please enter your comment!
Please enter your name here