Antminer has a vulnerability that can cause coins to be lost? Bitmain responds: It was a false alarm

Antminer has a vulnerability that can cause coins to be lost? Bitmain responds: It was a false alarm

Antminer is one of the world's most famous Bitcoin hardware manufacturers. Recently, a foreign community reported that an Australian researcher pointed out that Antminer could be hijacked through a flaw in an open source mining software.

The main configuration of the Antminer uses the CGminer open source software. The report said that Australian security researcher Tim Noise pointed out a vulnerability in the software configuration that hackers could exploit to control all Antminer mining activities.

“The vulnerability is called QueenAnt, and information about QueenAnt can be viewed on GitHub. Although on the surface it appears to come from CGMiner itself, the cause is much deeper.

Noise explained how the vulnerability could be exploited. CGMiner accepts incoming TCP connections via the RPC interface. Each Antminer runs the OpenWRT operating system, including CGMiner for all mining programs. This is an OpenWRT LuCi web interface that collects data from the RPC interface and does not require a username or password. This would allow the hacker to inject their Bitcoin address to receive mining rewards instead of the miner's Bitcoin address."

The article argues that the Antminer S5 is quite vulnerable to these attacks.

Pan Zhibiao, Director of Product and R&D at Bitmain, responded:

“This is not a vulnerability in the strict sense. Since CGminer has relatively large permissions, it is easy to manage and control, but it is also easy for hackers to modify it to some extent. However, most mining machines are behind routers and firewalls and are not exposed to the outside world, so the impact is small.”

In fact, there has been no coin loss incident caused by the Antminer "vulnerability" mentioned above, and only the S5 model is affected by the "vulnerability", while the S7 and the S9 that will be launched in batches have been fixed. The so-called "Antminer may be hijacked" is a false alarm.


<<:  What will happen to DAO token holders at this critical moment in the hard fork code development?

>>:  SolidX applies to list Bitcoin exchange-traded fund ETF on NYSE, additionally provides Bitcoin guarantee insurance

Recommend

What are the facial features of a scheming and cunning woman?

We all like to be friends with sincere and simple...

Li Bingbing's imposing appearance

Li Bingbing's imposing appearance In the rece...

How to analyze the facial features of women with prominent brow bones

Many people say that women with prominent brow bon...

What are the characteristics of a woman with a fox face?

Physiognomy refers to the features of the facial ...

Palmistry health line to see your own health status

Palmistry health line to see your own health stat...

China's version of Bitcoin is on the way

According to the official website of the People&#...

MIUI for mining machines? Interstellar Bit's IPFS OS architecture revealed

Judging from the current stage of IPFS mining mac...

Boys with this face should not be dated on Singles' Day

Singles' Day is here again. Are leftover wome...

Is it good to have a career with nasolabial lines?

Is it good to have a career with nasolabial lines...

What does it mean when there is no life line on the hand?

Many people believe that the lifeline is related ...

Will a woman with a raised chin be rich in the future?

Each of us is unique, everyone has our own charac...