o3n [ozone] blockchain layer

Blockchain source

Menu
  • Cybersecurity services
Menu

Zcash Bug Could Reveal Shielded Full Nodes’ IP Addresses

Posted on September 29, 2019 by nbelov

Komodo developer discloses a bug that can be used to expose IP addresses of Zcash’s shielded full nodes.

A bug in all Zcash (ZEC) implementations and most of its forks could leak metadata containing the full nodes’ with shielded addresses (zaddr) IPs.

Komodo (KMD) core developer Duke Leto disclosed the bug in a blog post published on his personal website. A Common Vulnerabilities and Exposures (CVE) code has already been assigned to track the issue on Sept. 27. Leto explained:

“A bug has existed for all shielded addresses since the inception of Zcash and Zcash Protocol. It is present in all Zcash source code forks. It is possible to find the IP address of full nodes who own a shielded address (zaddr). That is, Alice giving Bob a zaddr to be paid, could actually allow Bob to discover Alice’s IP address. This is drastically against the design of Zcash Protocol.”

Per the announcement, everyone who published their zaddr or provided it to a third party could be affected by the vulnerability. Leto claims that users should consider their “IP address and geo-location information associated with it as tied to […] zaddr.”

Multiple cryptocurrencies affected

According to Leto, users who never used a zaddr, only used it over the Tor Onion Routing network or only to send funds, are not affected. Furthermore, Leto also claims that Zcash is not the only cryptocurrency affected and provides a non-exhaustive list.

The cryptocurrencies included in the list are Zcash, Hush, Pirate, Komodo smart chains with zaddr enabled by default, Safecoin, Horizen, Zero, VoteCoin, Snowgem, BitcoinZ, LitecoinZ, Zelcash, Ycash, Arrow, Verus, Bitcoin Private, ZClassic and Anon. Leto also points out that Komodo has already disabled the shielded addresses feature and transitioned it to the Pirate chain, which means that KMD no longer contains the bug.

As Cointelegraph recently reported, Electric Coin Company, which launched and supports the development of privacy-coin Zcash, recently published a paper describing a trustless cryptographic system called Halo.

Source: Cointelegraph https://cointelegraph.com/

Recent Posts

  • JPMorgan Is Using Blockchain for Collateral Settlement – Crypto Briefing May 26, 2022
  • Falling wedge pattern points to eventual Ethereum price reversal, but traders expect more pain first May 26, 2022
  • DC Blockchain Summit: Booker, Gillibrand Praise Crypto – TIME May 26, 2022
  • Brainard tells House committee about potential role of CBDC, future of stablecoins May 26, 2022
  • ‘Other flavors of Tether’ will bridge users to USDT: Paolo Ardoino May 26, 2022
  • Ethereum could ‘take over everything’, and there won't be a multi-chain future, says EY's blockchain leader – MarketWatch May 26, 2022
  • Former Binance Executives Launch $100M Fund for Blockchain Startups – CryptoPotato May 26, 2022
  • Partisia Blockchain brings privacy-first zero-knowledge security to Polygon – Invezz May 26, 2022
  • Ethereum price dips below the $1.8K support as bears prepare for Friday’s $1B options expiry May 26, 2022
  • What is the future for blockchain technology with NFT’s in India? – Times of India May 26, 2022
  • Spooky Solana breakdown begins with SOL price facing a potential 45% drop — Here's why May 26, 2022
  • Bitcoin 'good to go up' after BTC price hits lowest since Terra crash May 26, 2022
  • Tether launches stablecoin pegged to pesos on Ethereum, Tron and Polygon May 26, 2022
  • Powers On… When will we learn from recent history to protect our crypto and ourselves? May 26, 2022
  • Blockchain tech offers multiple paths to financial inclusion for unbanked May 26, 2022
  • Cathie Wood’s Ark and 21Shares refile for spot Bitcoin ETF May 26, 2022
  • ECB president’s anti-crypto comments trigger community responses May 26, 2022
  • Global Hospitalization Insurance Market Forecast Report 2022-2027: Integration of Blockchain in Health Insurance is Growing in Popularity – ResearchAndMarkets.com – Business Wire May 26, 2022
  • Sports, Health, And Blockchain Integrate Through Walken | Mint – Mint May 26, 2022
  • Former Binance executives launch $100 million venture fund May 26, 2022
  • How Blockchain Is Transforming the Casino Industry? – STL.News May 26, 2022
  • The BSV Global Blockchain Convention: Blockchain investors focused on people, products and profits – CoinGeek May 26, 2022
  • Exchanges back 'Terra 2.0 revival plan' via airdrops, listing, buyback and burning May 26, 2022
  • WEF 2022: SWIFT probably won't exist in 5 years, says Mastercard CEO May 26, 2022
  • Blockchain-Powered Climate Tech Startup Raises $6 Million In Funding Led By Nomura – Forbes May 26, 2022
  • Outdated Node Clients Cause Blockchain Reorg on Eth2 Beacon Chain – The Defiant – DeFi News May 26, 2022
  • From Bitcoin to the metaverse: Dangers behind blockchain evolution – Khaleej Times May 26, 2022
  • Carbon credit standards body Verra suspends blockchain, crypto tokenization – Ledger Insights May 26, 2022
  • BTC price breakout due 'relatively soon' as Bitcoin volumes spook traders May 26, 2022
  • WEF 2022: Metaverse should be developed from children’s perspective, says LEGO VP May 26, 2022

Ad

Ad

©2022 o3n [ozone] blockchain layer | WordPress Theme by Superbthemes.com