Two Important Monero Bugs Have Come To Light

2019-3-6 19:55

Following a rather hectic disclosure process, an exchange-deposit bug found in the official Monero wallet has been patched and revealed to the public. Monero developers quickly fixed the vulnerability after one bugfinder went rogue and leaked the issue on Sunday. A patch has now been released, and the problem is under control—just in time for a second bug to arise.

First Bug Affects Exchanges

The first bug affects exchanges and other similar services, meaning that users do not need to worry. Lead developer Riccardo Spagni has also commented that the bug does not affect the Monero blockchain at all: “This is not a consensus bug, there is no double spend, it does not allow coins to be created out of thin air.”

Instead, the bug affects services that receive Monero deposits. Basically, transaction amounts are represented in two different ways, and prior to the patch, an attacker would have been able to misrepresent a deposit’s true value. The original bug concerned Coinbase, but other exchanges like Kraken have also responded by temporarily disabling Monero.

Disclosure Drama

It is important to keep security vulnerabilities secret until they are fixed so that potential attackers do not get a chance to exploit those bugs. Monero has tangled with the complexities of disclosure in the past—generally, the community deduces that a bug has been found whenever exchanges suddenly suspend Monero activity.

This bug was different: After it was disclosed privately on HackerOne, it was soon deliberately leaked on Medium. The leaker defended his actions by claiming that the Monero community has a “history of toxic behaviour” toward security researchers. Of course, that statement is unlikely to win over anyone who values Monero’s security.

Although there has been no fallout, there is one unsettling detail: According to some developers, it is suspicious that both the private disclosure and the public leak took place at about the same time. This has led some to believe that the leaker previously informed other individuals of the bug, which is obviously a major security problem.

Second Bug Affects Users

There is also a second, unrelated Monero bug that may pose a far greater risk to general users. An error in the Ledger Nano S could be causing users to lose their funds. This bug is particularly dangerous, since it does not involve an attack, but an all-around technical error. Ledger is currently warning users not to use the Nano S Monero app.

Warning: do not use Monero Ledger HW app with latest Monero client v0.14. Support issues have been reported on it, we are investigating. See more here https://t.co/yOV2b09QaG

— Ledger (@Ledger) March 4, 2019

These issues are arising at an inopportune time: Monero’s upcoming hard fork is set to be executed at the end of this week. The upgrade will primarily provide ASIC resistance, thereby ensuring that users with basic systems are able to continue mining Monero at a profit. Fortunately, the hard fork seems to be on track in spite of the above issues.

The post Two Important Monero Bugs Have Come To Light appeared first on UNHASHED.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Monero (XMR) на Currencies.ru

$ 134.81 (+0.69%)
Объем 24H $43.135m
Изменеия 24h: 1.16 %, 7d: 3.46 %
Cегодня L: $133.55 - H: $135.45
Капитализация $2.486b Rank 47
Цена в час новости $ 50.47 (167.11%)

monero two light come bugs important problem

monero two → Результатов: 53


Фото:

Study Finds 4 Percent of Monero Mined via. Malware over the Last 12 Years

Researchers at Universidad Carlos III de Madrid and King’s College London have found that from 2007 to 2018, around $57 Million of Monero was mined via. Malware, January 3, 2019. Background of the Study The joint study co-authored and compiled by two researchers was published January 3, 2019, and it states that four percent of the Monero mined over the.

2019-1-23 20:00


Фото:

Study Finds 4 Percent of Monero Mined with Malware over the Last 12 Years

Researchers at Universidad Carlos III de Madrid and King’s College London have found that from 2007 to 2018, around $57 Million of Monero was mined via. Malware, January 3, 2019. Background of the Study The joint study co-authored and compiled by two researchers was published January 3, 2019, and it states that four percent of the Monero mined over the.

2019-1-23 20:00


Kraken stirring the Ripple pot: Is it Ripple or XRP and why does it even matter?

One of the oldest cryptocurrency exchanges on the market, Kraken, announced that they’ll introduce XRP and Bitcoin Cash BCH margin trading on its platform. The addition will expand their margin offering to 8 assets, as these two will now be tradable alongside Bitcoin (XBT), Ethereum (ETH), Ethereum Classic (ETC), Augur (REP), Monero (XMR), and Tether […] The post Kraken stirring the Ripple pot: Is it Ripple or XRP and why does it even matter? appeared first on CaptainAltcoin.

2018-12-31 23:46


Monero [XMR]: Is a Bounce in Store or Are We Heading for the Bottom?

A look at the weekly chart of Monero (XMR), shows that we broke the $75 level of support which had been holding since the beginning of the summer and is now heading lower. The two support areas to watch are the $25-30 area formed by the lows of July 2017 (less likely to hold), and […] Monero [XMR]: Is a Bounce in Store or Are We Heading for the Bottom? was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-12-11 17:54


Фото:

How Monero Are Improving Human Rights With XMR

 Listen Here – https://soundcloud. com/cryptodaily/how-monero-are-improving-human-rights-with-xmr Monero is considered to be the privacy coin, the currency of choice for absolute privacy. Now, privacy doesn’t necessarily mean security and we should remember that 2018 has seen a tonne of ‘Monero mining’ hacks, calling into question some of the projects integrity.

2018-10-12 17:00


Фото:

Kraken Adds Cardano and Quantum to Its List of Supported Crypto Assets

Cryptocurrency exchange Kraken has announced the addition of two new assets to its platform: Cardano and Quantum, bringing the number of supported coins up to 19. Ninth-placed Cardano (ADA) and 29th-ranked Quantum (QTUM) join the likes of Bitcoin, Ether, EOS, Stellar Lumuns, Litecoin, Tether, Monero, Dash, Ether Classic, Dogecoin, Zcash, Augur, Iconomi, Gnosis, and Melon.

2018-10-2 13:07


Фото:

Monero The New Top 10 Cryptocurrency, Up 45%

If you’ve been watching the markets over the past month (which you probably have, otherwise what you doing here?) you may have seen that Monero has been flying up over the past few weeks. In a falling market that has spread over a number of months now, Monero XMR is up 45% over the past two weeks alone and, has now surpassed a number of rivals sitting in 10th place for market capitalisation according to Coinmarketcap.

2018-9-5 00:04


Фото:

‘Really Un-Tethered?’ Bitcoin Price Manipulation Returns With New Research

Days after Tether (USDT) gained a higher market cap than Monero and Dash, new research has reignited suspicions that the altcoin “manipulated” Bitcoin prices.   Cryptocurrency Highs Fuelled By Tether The product of two researchers at the University of Texas, the paper — titled Is Bitcoin Really Un-Tethered? — claims to have identified potential evidence of direct price manipulation since November 2017.

2018-6-13 20:00