Anonymous person accuses Antminer of having an "Antbleed" backdoor, saying 70% of Bitcoin computing power is vulnerable

Anonymous person accuses Antminer of having an "Antbleed" backdoor, saying 70% of Bitcoin computing power is vulnerable

According to foreign media bitcoinmagazine, anonymous sources have accused Bitcoin mining hardware manufacturer Bitmain of having an "Antbleed" backdoor in its Antminer machines, which, if abused, could pose a threat to Bitcoin network security.

“Even if Bitmain has no bad intentions, this is a huge security vulnerability,” said the anonymous person, who claimed to have discovered the vulnerability and set up an Antbleed website to publicize it.

Explanation of the "Antbleed" vulnerability

The anonymous person said the Antbleed backdoor was extremely simple.

He explained that when an Antminer is online, it contacts the domain auth.minerlink.com (owned by Bitmain) on port 7000 every 1-11 minutes. This domain is not currently connected to any IP address.

However, this domain name may be connected to the corresponding IP address in the near future. If this happens, it will report the serial number, MAC address and IP address of the Antminer to Bitmain.

Bitmain can then connect to a specific user through this machine.

“Bitmain can use this data to cross-check customers’ sales and delivery records to make them personally identifiable,” the anonymous source said. “Bitcoin mining is a small industry, so it should be easy to link a mining machine to the corresponding mining pool or block.”

Once connected, Bitmain's servers connect to the Antminer and send a message back. If the message is "true," the machine continues mining, but if it's "false," the code generates a text message that says, "Stop mining."

The anonymous person said that this text will stop the miner from mining, and he said that he had tested it on an Antminer. In addition, the anonymous person said that anyone can test it with an Antminer by following the instructions on antbleed.com.

Bitcoin Core developer Peter Todd quickly commented on this on Twitter and Reddit:

“This backdoor has ‘no’ authentication, any man-in-the-middle attacker or DNS attacker can activate it, 70% of the hashrate is vulnerable.”

Bitmain’s response

In response to the backdoor accusation, Bitmain said:

“The code running on the machine is open source and available for everyone to view, so it does not contain secret functions. It is not a secret that the code points to functions that allow Antminer owners to remotely control their miners, and at the same time, Bitmain cannot remotely control Antminers that it does not own.”

What do you think?

<<:  Roger Ver plans to deploy cloud mining, is this BU's chance?

>>:  Bitcoin price rises to nearly $1,300, three positive factors drive Bitcoin market to continue to rise

Recommend

Husband is very rich woman's face

Husband is very rich woman's face Upturned ey...

What does a mole on a man's left ear mean?

In physiognomy, the ear represents a person's...

Grammy winner Imogen Heap supports blockchain technology

British singer and songwriter伊莫金·希普[1] recently e...

What does a big nose mean for a man?

If a man has a big nose, then in terms of destiny...

What kind of person is greedy for profit?

Do you often feel that you meet bad people and ar...

Face analysis: moles on the neck and back of the neck indicate good fortune

It is very common to have moles, but the location...

The hard fork upgrade is getting closer, what is the BCH community doing?

It has been more than half a month since the Bitc...

Coin Zone Trends: This Week’s Big Data on Ethereum Price Trends (2017-06-12)

ETH Weekly Report | Bullish break through the 2,0...

What causes my left eyelid to twitch?

What causes my left eyelid to twitch? In fact, fr...

"Deep pullback + regulatory storm", where should the crypto market go?

"2021 is a difficult year for retail investo...

How is the fortune of a person with Jianfengjin fate and Fuziyan on his hand?

Fuzi eyes refers to the mark on the first section...