Categories: CryptoNews

QueenAnt Exploit Lets Hackers Change The Antminer Bitcoin Payout Address

Antminer is one of the most popular Bitcoin hardware manufacturers in the world. The company has built up a solid reputation through their line of Antminer devices, and customers have shown their support for the company throughout the years. But one Australian researcher notices how it is possible to hijack an Antminer through a software flaw in the open source mining software.

Is It Feasible To Hijack an Antminer?

The Antminer devices are primarily configured to be used with the CGminer open source software. Tim Noise, an Australian security researcher, mentions how there is a vulnerability in the configuration of this software that can be exploited. As a result, hackers could take control of any Antminer actively mining Bitcoin.

To be more precise, the device itself would continue its operations as it always has. However, the rewards from mining can be sluiced to a different Bitcoin address. QueenAnt, as this exploit is dubbed, can be found on GitHub. Although this may appear to be an issue with CGMiner itself, the cause lies much deeper.



Noise explains how the vulnerability can be exploited. CGMiner accepts incoming TCP connections through an RPC interface. Every Antminer runs the OpenWRT OS, which includes CGMiner for all of the mining procedures. On top of all this is an OpenWRT LuCi web interface, collecting statistics from the RPC interface without requiring a username or password.

Related Post

This would allow hackers to inject their Bitcoin address to receive funds, rather than the one belonging to the miner. Luckily, it is relatively easy to bypass this exploit, by updating the cgminer.conf and cgminer.sh, files. Antminer users can change the system password, adding an extra layer of protection.

Another course of action would be to take the Antminers offline entirely, a tactic deployed by bigger mining farms already. For the time being, it appears the Antminer S5 is rather vulnerable to these attacks. At the date of writing, it was unclear if these issues were fixed when the Antminer S7 was produced.

Image credit 1

If you liked this article follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin and altcoin price analysis and the latest cryptocurrency news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

$14M Worth of $MELANIA Tokens Sold in Ongoing Liquidity Strategy: What It Means for the Market

The $MELANIA token project has been making waves over the last month, not only for…

7 hours ago

Smart Money Pulls Back as Memecoin Market Sees Major Outflows

The memecoin market experienced a dramatic shift as it appeared that smart money investors had…

7 hours ago

$FUR Memecoin Explodes in Popularity as Exchanges Join the Hype with Furry Logos

In an astonishing manifestation of viral momentum, the Solana-based memecoin $FUR is making tremendous splashes…

7 hours ago

$OM Surges Over 24% as CEO Proposes Token Burn — Could This Be the Start of a Comeback?

Following a difficult stretch characterized by price oscillation and dwindling investor trust, Mantra ($OM) is…

7 hours ago

ZKsync Confirms Admin Account Hack in Airdrop Contract: ~$5M Worth of ZK Tokens Compromised

A breach of security at ZKsync, related to one of its airdrop distribution contracts, has…

7 hours ago

Smart Money Moves: Top Crypto Narratives Catching Whale Attention in the Last 24 Hours

In the previous day, a surge of intelligent monetary activity has washed over the cryptocurrency…

7 hours ago