You are viewing a single comment's thread from:

RE: under investigation: some tweets poped up about security issues in Gridcoin

in #gridcoin7 years ago (edited)

Read those reports:
https://web-in-security.blogspot.com.ee/2017/08/gridcoin-good.html
https://web-in-security.blogspot.com.ee/2017/08/gridcoin-bad.html

It's possible to:

  1. Steal the block creation reward from Gridcoin minters.
  2. Prevent Gridcoin minters from claiming their block creation reward.

not a big deal...

but what if to target pool's CPIDs (grcpool.com for example), then what?

Sort:  

Both of the above issues are no longer vulnerabilities in the production gridcoin client. There's the edge case of attempting to steal a cpid when a beacon expires but we can delete the beacon or the pool could force a cpid change.

You really aught to follow the developers responses to this on slack, you're behind on information.