Antminer has a vulnerability that can cause coins to be lost? Bitmain responds: It was a false alarm

Antminer has a vulnerability that can cause coins to be lost? Bitmain responds: It was a false alarm

Antminer is one of the world's most famous Bitcoin hardware manufacturers. Recently, a foreign community reported that an Australian researcher pointed out that Antminer could be hijacked through a flaw in an open source mining software.

The main configuration of the Antminer uses the CGminer open source software. The report said that Australian security researcher Tim Noise pointed out a vulnerability in the software configuration that hackers could exploit to control all Antminer mining activities.

“The vulnerability is called QueenAnt, and information about QueenAnt can be viewed on GitHub. Although on the surface it appears to come from CGMiner itself, the cause is much deeper.

Noise explained how the vulnerability could be exploited. CGMiner accepts incoming TCP connections via the RPC interface. Each Antminer runs the OpenWRT operating system, including CGMiner for all mining programs. This is an OpenWRT LuCi web interface that collects data from the RPC interface and does not require a username or password. This would allow the hacker to inject their Bitcoin address to receive mining rewards instead of the miner's Bitcoin address."

The article argues that the Antminer S5 is quite vulnerable to these attacks.

Pan Zhibiao, Director of Product and R&D at Bitmain, responded:

“This is not a vulnerability in the strict sense. Since CGminer has relatively large permissions, it is easy to manage and control, but it is also easy for hackers to modify it to some extent. However, most mining machines are behind routers and firewalls and are not exposed to the outside world, so the impact is small.”

In fact, there has been no coin loss incident caused by the Antminer "vulnerability" mentioned above, and only the S5 model is affected by the "vulnerability", while the S7 and the S9 that will be launched in batches have been fixed. The so-called "Antminer may be hijacked" is a false alarm.


<<:  What will happen to DAO token holders at this critical moment in the hard fork code development?

>>:  SolidX applies to list Bitcoin exchange-traded fund ETF on NYSE, additionally provides Bitcoin guarantee insurance

Recommend

The palmistry of Mai explains the length of life

Physiognomy has a long history in China, dating b...

PengolinCoin Mining Tutorial

Currency Introduction PangolinCoin (English name:...

The face of bankruptcy

The face of bankruptcy Many customers have consul...

What kind of man is afraid of his wife's appearance?

Fortune telling based on face reading: What kind ...

How is the love luck of people with big mouths?

Sometimes, we may dream of having good luck in lo...

What does a person who thinks he can't listen to criticism look like?

Nowadays, we all say "Pride brings harm, whi...

What does a mole on the right arm mean?

In fact, from the perspective of mole physiognomy...

What does three marriage lines mean?

People with clear marriage lines generally have g...

What will happen to CoinMarketCap after being acquired by Binance?

Three weeks after Binance announced its acquisiti...