HomeSecurityUnupdated Ethereum Clients Put the Entire Network at Risk

Outdated Ethereum Clients Put the Entire Network at Risk

Ethereum According to a study by SRLabs, Ethereum clients that have not received security updates are putting the entire Ethereum network.

Researchers at SRLabs published a report based on data from ethernodes.org. According to the report, a large number of nodes using the popular Parity and Geth clients have not received updates. The researchers found that Ethereum clients and their users have been unprotected for a long time.

There are vulnerabilities in many clients that have not yet been patched and that put the blockchain ecosystem at risk. A hacker who could control 51% of the computing power on the Ethereum network could do a lot of damage to the ecosystem. A hacker who can attack many nodes will be able to control 51% of the network even more easily.

For this reason, vulnerabilities that allow denial-of-service attacks are very critical in cryptocurrency networks. Hackers could use these vulnerabilities to reduce the amount of computing power needed to carry out an attack that would give them control of 51% of the network.

A few months ago, SRLabs researchers identified a vulnerability in the Parity client.

“According to the data we collected, only two-thirds of the nodes have been patched so far. Shortly after this vulnerability was reported, Parity published a security advisory, urging users to update,” the report reads.

However, even after the update was released, 40% of nodes remained unprotected. Another update was released in March. 70% received the update, while the remaining 30% remained exposed.

The researchers reported that Parity Ethereum has an automated update process, but it is quite complex.

Things are worse for the Geth client, as it lacks this automatic update feature. Geth clients have not received security updates for a long time.

The lack of essential patches in Ethereum clients can cause great damage, as it puts the entire Ethereum network at risk.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS