Categories: CryptoNews

New Parity Update Addresses RPC Request Crashing Ethereum Network Nodes

In 2019, not a week goes by in the cryptocurrency industry without some sort of worrisome development. Parity, one of the more popular technology stacks in the Ethereum ecosystem, has issued a major security alert. It seems a new attack vector against network nodes has been uncovered which could ultimately force network nodes offline. Luckily, a fix is ready to be downloaded.

Parity Security bug is Worrisome

As has become the standard in the cryptocurrency industry, security warnings should not be taken lightly. Every potential bug, flaw, or exploit needs to be addressed as quickly as possible. It is also up to individual users and network participants to ensure they are up-to-date in terms of both software and information. For those users who run Parity Ethereum nodes, the latest security alert will be rather worrisome, all things considered.

To put this in perspective, a new actor vector was reported to the Parity team over the weekend. As part of this potential bug, it quickly became apparent malicious actors could effectively take network nodes offline by forcing it to crash. This is done through a very specific RPC request which can be sent to any public Parity Ethereum node on the network today. Anyone running a software version that is not 2.2.9-stable or 2.3.2-beta will remain susceptible to this attack, for the time being.

Although one always has to wonder if such an attack vector would be used, the fact it exists can pose many different problems. For network users, having their node kicked offline might not seem like a big problem, yet it can disrupt overall Ethereum network operations if enough nodes suffer from the same problem. It is good to see the Parity team address these problems in such a swift manner.

Related Post

What is rather remarkable is how this bug can affect commonly used public network service providers. The list includes MyEtherWallet, MyCrypto, Infura, and other pieces of the Ethereum infrastructure which are publicly accessible. For the time being, it seems unlikely any attack will be carried against these providers, although one cannot dismiss the possibility someone will at least try to wreak havoc sooner or later.

Updating one’s Parity software should not pose any significant problems as of right now. In fact, the updates are made available already and users can download the new client accordingly. Upgrading parity nodes shouldn’t take all that long either, although there will undoubtedly be some delays as to when all service providers are on board again. Some network nodes will be upgraded automatically, as explained in the original post.

The revelation of this new node bug is a great example of why bounty programs matter. They are invaluable in the ever-changing world of cryptocurrency,  Without a system in place to make accurate reports regarding potential discrepancies, a problem on this scale could have remained unnoticed for weeks on end. Due to the bug bounty program, the matter was addressed swiftly, which is the way things should work.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Velocity Ticket Debuts As The AI-Powered Invoicing Tool Every Service Business Needs in 2026

Velocity Ticket is trying to fix a major gap in businesses, and the approach it…

2 days ago

Axelar Confirms $4.67M Exploit on Secret Network Bridge, Core Protocol Remains Unaffected

Axelar is moving fast to contain damage after identifying a security incident that has resulted…

2 days ago

Sui Synthetic Dollar suiUSDe Gets Its Own Website

suiUSDe now has a dedicated landing page. The token, officially the eSui Dollar, comes out…

2 days ago

Ventuals Winds Down HIP-3 DEX, vHYPE Withdrawals Now Live For All Holders

Ventuals has fully wound down its HIP-3 DEX, and vHYPE withdrawals are now open. The…

2 days ago

Avalanche Launches Payments Collective With Franklin Templeton And 25 Others

Avalanche has launched the Avalanche Payments Collective, bringing together 28 organizations spanning nearly every layer…

3 days ago

ASTER Whale Reopens 5x Long Days After Getting Fully Liquidated On The Same Token

A wallet tracked as 0x5f91 just opened a fresh 5x leveraged long on ASTER, putting…

3 days ago