ETC Social Engineering Attack: Fake Core-Geth 'Security Update' Misleads Some Mining Pools

iconKuCoinFlash
Share
AI summary iconSummary
Ethereum Classic (ETC) was targeted by a social engineering attack when a fake Core-Geth "security update" was falsely promoted. On September 14, an unreviewed ethereumclassic/core-geth v1.13.0 was distributed via @ETC_Network, CoinMarketCap, and email. Some mining node operators upgraded before reverting to etclabscore/core-geth v1.12.23. The incident did not disrupt the network or result in any fund losses. Classix warned that the unreviewed version altered chain selection and node discovery, raising concerns about contract security and potential risks of network fragmentation.

BlockBeats report: On September 17, according to an incident report released by Classix, a social engineering incident involving the Core-Geth client recently occurred on Ethereum Classic. An unreviewed version of ethereumclassic/core-geth v1.13.0 was released on September 14 and promoted as a "security update" via @ETC_Network, CoinMarketCap community updates, and email, misleading node operators into migrating.


The report states that a small number of mining pool nodes briefly switched to this version but have since reverted to the long-maintained etclabscore/core-geth v1.12.23; the incident caused no block loss, chain reorganization, fund loss, or service disruption. Classix warned that this unreviewed version modified critical logic such as chain selection and node discovery, posing a potential risk of network partitioning.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.