A bug in all Zcash implementations and most of its forks could leak metadata containing the full nodes' with shielded addresses IPs.
Komodo core developer Duke Leto disclosed the bug in a blog post published on his personal website.
A Common Vulnerabilities and Exposures code has already been assigned to track the issue on Sept. 27.
"A bug has existed for all shielded addresses since the inception of Zcash and Zcash Protocol. It is present in all Zcash source code forks. It is possible to find the IP address of full nodes who own a shielded address. That is, Alice giving Bob a zaddr to be paid, could actually allow Bob to discover Alice's IP address. This is drastically against the design of Zcash Protocol."
Per the announcement, everyone who published their zaddr or provided it to a third party could be affected by the vulnerability.
Leto claims that users should consider their "IP address and geo-location information associated with it as tied to zaddr."
According to Leto, users who never used a zaddr, only used it over the Tor Onion Routing network or only to send funds, are not affected.
Leto also claims that Zcash is not the only cryptocurrency affected and provides a non-exhaustive list.
Leto also points out that Komodo has already disabled the shielded addresses feature and transitioned it to the Pirate chain, which means that KMD no longer contains the bug.
As Cointelegraph recently reported, Electric Coin Company, which launched and supports the development of privacy-coin Zcash, recently published a paper describing a trustless cryptographic system called Halo.
Zcash Bug Could Reveal Shielded Full Nodes' IP Addresses
Publicado en Sep 29, 2019
by Cointele | Publicado en Coinage
Coinage
Noticias recientes
Ver todo
First Mover: What's Next for Bitcoin as Wall Street Gets Vaccine Booster
Bitcoin was higher for a second day, staying in a range of between roughly $15,200 and $15,600, as news of progress in developing a coronavirus vaccine appeared to touch off a rally in U.S. stocks.
Market Wrap: Bitcoin Fails to Break $15.9K; Over 50K ETH Staked on Eth 2.0 Contract
Bitcoin gained Wednesday while Ethereum 2.0 staking has been ramping up.
Citibank Analyst Says Bitcoin Could Pass $300K by December 2021
A senior analyst at U.S.-based financial giant Citibank has penned a report drawing on similarities between the 1970s gold market and bitcoin.
Blockchain Bites: Data Unions. Hard Forks. And One Citi Analyst's Case for $300K BTC.
A Citibank managing director thinks bitcoin could hit $318,000.