Pentagon Report Outlines Blockchain Vulnerabilities

Share post:

A Pentagon-commissioned report has revealed some hard security truths about the blockchain, including the position that the blockchain is not decentralized, highly vulnerable to attack, and run on outdated software.

The Pentagon’s research arm, Defense Advanced Research Projects Agency (DARPA), hired Trail of Bits, a security research organization, to study the blockchain.

Trail of Bits focused on Bitcoin and Ethereum and discovered that it only takes four entities to disrupt Bitcoin and only two to disrupt Ethereum.

To analyze the challenges of Bitcoin security, the researchers from Trail of Bits registered multiple accounts with mining pool sites to study its code when available.

Security flaws discovered during the process include the fact that ViaBTC, a leading global mining company, assigns the password “123” to its account. Pooling, another mining company, does not even check the login credentials. Slushpool, a mining company that has mined more than 1.2 million Bitcoin since 2010, instructs users to ignore the password.

The three mining companies account for about 25% of the Bitcoin harsh rate, or total computer performance, and their security incompetence expose organizations and individuals to a high risk of cyberattacks. This is because the nodes used by crypto miners can easily be used to flood the network in a so-called Sybil attack using an inexpensive cloud server.

Another security problem in the blockchain is the use of older versions of software that cause software errors and bugs. Software bugs have already caused blockchain errors in Ethereum, and 21% of Bitcoin nodes run on older versions of the notoriously vulnerable Bitcoin Core client known to be vulnerable.

The sources for this piece include an article in TechRepublic.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Developer of “Unfollow Everything” sues Meta over control of social feeds

Ethan Zuckerman, an associate professor at the University of Massachusetts—Amherst, has filed a lawsuit against Meta, arguing that...

New York business leaders most optimistic about impact of AI: Accenture study

New York City's business elite are increasingly optimistic about the transformative potential of artificial intelligence, according to a...

Intel’s foundry business suffers $7 billion loss in 2023 amidst ambitious expansion

Intel's expansion into the foundry business as part of its IDM 2.0 strategy has resulted in a staggering...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways