Parity Technologies Fixes Node Vulnerability, Urges All Ethereum Nodes to Update

Published at: Feb. 5, 2019

Ethereum blockchain infrastructure developer Parity Technologies experienced a security compromise that required nodes to perform an urgent update, the company stated in a blog post on Feb. 3.

Parity, which is a popular technology stack for Ethereum users, said it had received notification of a loophole which would allow an attacker to shut down nodes running its client.

“On February 3rd, we received several reports that an attacker can send a specially-crafted RPC request to a public Parity Ethereum node (any version pre 2.2.9-stable and pre 2.3.2-beta) and that node will crash,” officials summarized.

On social media, Parity confirmed it had issued a patch to fix the vulnerability within hours, with nodes running the affected versions nonetheless required to update their software.

“While the vulnerability only directly affects Parity Ethereum nodes that serve JSONRPC as a public service (e.g., Infura, [MyEtherWallet], MyCrypto, etc), we recommend everyone to update their nodes immediately,” a tweet read.

In late 2017, one user of Parity’s Ethereum (ETH) wallet accidentally quarantined 513,774.16 ETH (around $54 million). In April 2018, an Ethereum Improvement Proposal (EIP) that would restore a disabled contract to unfreeze the funds was voted down.

In June 2018, another vulnerability discovery led to a similar request to install node updates.

Last month, the organization received a grant from the nonprofit Ethereum Foundation worth $5 million to fund development on Casper, sharding and infrastructure.

Tags
Related Posts
The importance of decentralized oracles: Interview with Sergey Nazarov
Chainlink co-founder Sergey Nazarov believes that increasing the decentralization and scalability of oracle technologies are key to ensure trust in the DeFi ecosystem. Oracles play a key role in the correct functioning of DeFI protocols by connecting them to real-world data. However, the trustworthiness of oracles becomes compromised in instances where they rely on a single data source to retrieve information. For instance, according to Nazarov, excessively centralized oracles enabled five recent flash loan attacks, which resulted in DeFi protocols losing around $40 million. Flash loans, a form of loan that does not require any collateral, can be used to …
Decentralization / Dec. 19, 2020
Overview of Software Wallets, the Easy Way to Store Crypto
Similar to a bank account for fiat currency, a crypto wallet is a personal interface for a cryptocurrency network that provides reliable storage and enables transactions. Whether a cryptocurrency is securely stored or not, much depends on the wallet, which is only as secure as its private keys. Wallets are generally either hot or cold. The funds in a hot wallet can be spent at any time, online. A cold wallet functions in contrast: not intended for regular cryptocurrency transactions, but funds can be received at any time. Wallets can also be divided into three groups: software, hardware and paper. …
Blockchain / March 29, 2020
Japanese Cybersecurity Group Debuts Blockchain Scan Tool, Partners With ConsenSys Diligence
A cybersecurity subsidiary of Japan’s Nomura Research Institute (NRI) unveiled a new blockchain security alert tool in a press release Nov. 8, also confirming a partnership with U.S. blockchain software company ConsenSys. With the tool, dubbed the “Blockchain Security Monitoring Service,” NRI SecureTechnologies (NRI ST) said it aimed to increase security in blockchain implementations, informing operators about “vulnerabilities.” The solution’s first outing will target smart contract weaknesses, the release says, while at the same time NRI ST will work with ConsenSys’ Diligence team on expanding its security offering. Last week, a group of researchers from two American universities found that …
Blockchain / Nov. 8, 2018
Building multichain is a new necessity for DeFi products
At present, your DeFi product needs to be multichain to be competitive — this is the hard (and exciting) truth of 2021. Whether you’re building a wallet, a lending service or a DeFi game, your target audience knows that there is more to the crypto space than Ethereum. And they expect you to provide the best of all worlds. It seems there will always be a debate about which blockchain makes for the best foundation for projects. Enhanced security, low transaction costs and formidable speed — there will always be a chain that offers bigger advantages. As the speculators argue …
Technology / Nov. 20, 2021
How blockchain archives can change how we record history in wartime
Decentralized blockchain technology has been around for a relatively short period of time, in the grand scheme of things, but its decentralized nature has the power to keep data and information out of the hands of censors looking to create a “safe” and “faultless” version of history. Blockchain is permissionless and literally owned by no one. So, while we can’t save the Alexandria libraries of the past, we can make sure the future is well equipped with the tools necessary to preserve historical records. Here we’ll look at some of the ways nonfungible tokens (NFT) and blockchain technology have been …
Adoption / May 12, 2022