The bug in an efirium-purse of Parity has led to blocking of funds for millions of dollars
The problem in a code of an ethereum-purse Parity led to the fact that precisely an unknown at the moment the quantity of means of users on the ethereum network was "frozen". On the available data, the amount in "air" exceeds $100 million at the rate at the time of the publication.
Vulnerability because of which "freezing" of means was activated was found in a code of the efirium-client, the second for popularity, on Monday November 6 by the developer under a nickname of "devopps199" who reported to the first about it on GitHub.
All purses on Parity created after July 20 and using function of the multisignature are subject to this vulnerability (when more than one key are necessary for the signature of transaction).
At the moment it is precisely unknown how many purses were created for this period and how many "air" stuck. According to EtherNodes.org, about 20% of addresses of a network are the share of Parity-purses, that is it is already possible to speak about at least $100 million, perhaps, forever stuck on purses.
And it is not the first big vulnerability of Parity. In July of this year the unknown hacker, having used a hole in a code, I stole "air" for $30 million. This bug was quickly closed, but as it was clarified, in a code there were additional defects because of which I worked an exploit.
The developer devopps199 admits that he is a beginner in smart contracts, he draws an analogy to banking storage on which door there is a button "lock forever", and he became that who "accidentally clicked it".
At present there is no clarity on the subject of how to return the stuck means. Some developers already say about a possible hardfork, however all understand that this, to put it mildly, contradictory decision, and especially in the context of an efirium, all of us remember a situation with The DAO and appearance of a coin of Ethereum Classic.
Some efirium-projects, for example, of Augur, already openly negatively spoke against a probable hardfork on social networks.
Warning that you should not use and create new purses with the multisignature until the situation clears up was published in the blog Parity.
Among frozen accounts there were purses of the project of the founder of Parity Gavin Wood of Polkadot who during ICO attracted cryptocurrency on the amount over $140 million.
Unfortunately, our multi-sig is among those frozen. @ParityTech is working on the situation and will provide updates when available.— Polkadot (@polkadotnetwork) November 7, 2017
If to trust the document published on Pastebin, the problem has mentioned purses on which in a total amount more than 600 thousand "air", their sum exceeds $180 million.
0 comments