Ethereum’s Constantinople Hard Fork Gets Delayed Due to Critical Bug

2019-1-16 13:04

CoinSpeaker
Ethereum’s Constantinople Hard Fork Gets Delayed Due to Critical Bug

It looks like Ethereum supporters and enthusiasts will have to wait some more time for the arrival of the much-awaited Constantinople hard fork. Citing the critical security vulnerability during the software upgrade by smart contract auditing firm ChainSecurity, the core developer team decided to postpone the launch.

[SECURITY ALERT] #Constantinople upgrade is temporarily postponed out of caution following a consensus decision by #Ethereum developers, security professionals and other community members. More information and instructions are below. https://t.co/p2znO8HGxf

— Ethereum (@ethereum) January 15, 2019

The official announcement on the Ethereum blog reads:

“Security researchers like ChainSecurity and TrailOfBits ran (and are still running) analysis across the entire blockchain. They did not find any cases of this vulnerability in the wild. However, there is still a non-zero risk that some contracts could be affected.”

It further adds:

“Because the risk is non-zero and the amount of time required to determine the risk with confidence is longer the amount of time available before the planned Constantinople upgrade, a decision was reached to postpone the fork out of an abundance of caution.”

Vulnerability Detected In Ethereum Improvement Proposal (EIP) 1283

ChainSecurity noted that if the Ethereum Improvement Proposal (EIP) 1283 is implemented, it would create a loophole for attackers to exploit the software code and steal users’ funds. Referring to it as the reentrancy attack, the vulnerability will allow attackers to “reenter” the same function multiple times without updating the user about the situation. this would allow the attackers to continuously withdraw the funds.

In its Medium blog post, ChianSecurity explained:

“The upcoming Constantinople Upgrade for the ethereum network introduces cheaper gas cost for certain SSTORE operations. As an unwanted side effect, this enables reentrancy attacks when using address.transfer(…) or address.send(…) in Solidity smart contracts. Previously these functions were considered reentrancy-safe, which they aren’t any longer”.

The post further explains that before the Constantinople hard fork, storage operations on the network would cost 5000 gas. This would considerably exceed the normally used 2300 gas while calling a contract through the “transfer” or “send” functions. But if the upgrade was implemented, “dirty” storage operations would have cost an additional 200 gas. ChainSecurity notes that an “attacker contract can use the 2300 gas stipend to manipulate the vulnerable contract’s variable successfully.”

This vulnerability is quite similar to the one found in the DAO attack in 2016.

Node Operators Should Upgrade to Emergency Software Clients

Now that the Constantinople hard fork is delayed further, node operators and miners are requested to upgrade to the emergency versions of the Ethereum software clients or else need to downgrade to the earlier pre-fork release. Failing to do so will cause you to become completely disconnected from the main network as the fork software is not compatible with the previous versions.

For Ethereum users who don’t run full nodes, need to take no action at the moment. Their wallets are secure in the current state. Currently, the developers have postponed the hard fork for an unspecified time. However, the Ethereum developers are likely to announce the date during the next conference meeting on Friday.

Following the delay in Constantinople, popular Ethereum clients like Go-Ethereum (Geth) and Parity have released the software updates. In the Ethereum Core developers chat platform, Kirill Pimenov – head of security at Parity Technologies – advised the upgrade to its new beta release 2.3.0 instead of downgrading the software. He wrote:

“I want to restate — downgrading Parity to pre-Constantinople versions is a bad idea, we don’t recommend that to anyone. Theoretically it should even work, but we don’t want to deal with that mess.”

Ethereum Price Drops

The announcement of delaying the Constantinople hard fork resulted in the Ethereum price drop. Ethereum (ETH) dropped by nearly 5% on Tuesday and is currently trading at $124 with a market cap just below $13 billion. However, in the anticipation of Constantinople launch, already 19 crypto exchanges worldwide have pledged their support to the hard fork.

Ethereum’s Constantinople Hard Fork Gets Delayed Due to Critical Bug

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Ethereum (ETH) на Currencies.ru

$ 3085.44 (-0.27%)
Объем 24H $10.928b
Изменеия 24h: 0.22 %, 7d: 4.10 %
Cегодня L: $3055.33 - H: $3131.6
Капитализация $370.643b Rank 2
Цена в час новости $ 122.22 (2424.5%)

ethereum fork bug hard constantinople critical due

ethereum fork → Результатов: 126


Фото:

Ethereum Classic Undergoes Thanos Hard Fork Upgrade for Improved GPU Miner Access

After crossing the 11. 7 million block height milestone, Ethereum Classic (ETC) has undergone a hard fork to bring about the anticipated Thanos upgrade. The Ethereum fork has suffered numerous security issues with multiple 51% attacks and proponents are hoping the new Thanos upgrade will provide much-needed network fidelity while allowing GPU-based mining to continue.

2020-11-30 18:01


Ethereum’s Hard Fork ‘Muir Glacier’ Launches In 2 Days, Will The ETH Community Be Prepared?

While the entire world is preparing for the New Year, Ethereum has scheduled Muir Glacier, its long-awaited hard fork, for January 1 of the year 2020. The Ethereum (ETH) Istanbul hard fork that happened just a few weeks ago didn’t make things easier when it comes to Ethereum’s so-called “difficulty bomb”, so many are expecting […]

2019-12-30 22:01


“Difficulty Bomb” Reconsidered by Ethereum Developers Ahead of Hard Fork

The “difficulty bomb” has been a planned part of the Ethereum blockchain for quite a while, but developers are seemingly reconsidering this protocol. According to reports from CoinDesk, the new hard fork could push back a necessary network feature by about two years, in an effort to eliminate the complications with Ethereum’s upgrade to proof-of-stake. […]

2019-12-4 03:14


Ethereum’s Istanbul hard fork scheduled for early December

As Ethereum 2. 0 approaches its expected deployment timeline, the community has been shedding focus on other developments within the ecosystem. While Ethereum co-founder Vitalik Buterin recently highlighted the recent change in Sharding protocol, Tim Beiko, Product Manager at PegaSys Protocol Engineering shared yet another update regarding the much expected Istanbul hard fork.

2019-10-26 20:30


Фото:

New Mining Manufacturer Linzhi Announces Ethereum ASIC Miner

Chen Min, the former chief chip maker at Bitcoin mining chip developer Canaan Creative, is turning her attention to Ethereum. Announcing her venture at the Ethereum Classic Summit in Seoul, South Korea, Chen’s new company, Linzhi, will focus on building cryptocurrency mining devices, and its first official products are a series of application-specific integrated circuit (ASIC) miners designed specifically for Ethereum and Ethereum Classic.

2018-9-15 01:22


Фото:

DevCon 4 Will Set the Stage for Ethereum’s Next Milestone: Constantinople

Ethereum is embracing the Constantinople milestone at the end of November 2018, after DevCon4 in Prague. Constantinople is the latest Ethereum release, introduced through a hard fork, that will include five Ethereum Improvement Proposals (EIPs):Bitwise shifting instructions (EIP 145) in the Ethereum Virtual Machine (EVM) allow for direct manipulation of bytes on the EVM layer.

2018-9-11 18:15


Ethereum Developers Reduce Ether Rewards to 2 ETH, Delay ‘Difficulty Bomb’

Ethereum developers have decided to delay the “Difficulty Bomb” by agreeing to include the code for such a change into Metropolis’ hard fork—Constantinople. The core developers decided on a video call, streamed live on YouTube on August 31, 2018, to accept the EIP-1234 scenario for the “Difficulty Bomb’s” impact on block rewards.

2018-9-4 16:32


Стресс-тест пройден: за сутки сеть Bitcoin Cash обработала 2 млн транзакций

1 сентября в сети Bitcoin Cash был проведён стресс-тест, в ходе которого за 24 часа майнеры обработали свыше 2 млн транзакций. В результате суточный объём BCH-транзакций превысил рекордные значения, достигнутые в сетях Ripple (1,7 млн) и Ethereum (1,2 млн).

2018-9-3 20:13


Сеть Bitcoin Cash была подвергнута стресс-тесту. Обработано 2 млн. транзакций

В субботу, 1 сентября, сеть Bitcoin Cash (BCH) была подвергнута стресс-тесту, в ходе которого майнерам удалось за сутки обработать более двух миллионов транзакций. Об этом сообщает Bitcoin. com. Таким образом, в течение последних суток объем BCH-транзакций превысил аналогичный показатель Ripple (XRP) и Ethereum (ETH).

2018-9-2 13:10


Стресс-тест: сеть Bitcoin Cash обработала за сутки 2 млн транзакций

В субботу, 1 сентября, сеть Bitcoin Cash (BCH) была подвергнута стресс-тесту, в ходе которого майнерам удалось за сутки обработать более двух миллионов транзакций. Об этом сообщает Bitcoin. com. Таким образом, в течение последних суток объем BCH-транзакций превысил аналогичный показатель Ripple (XRP) и Ethereum (ETH).

2018-9-2 11:16