Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The global economy is still paying for big banks’ laziness

    December 13, 2025

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » Security Advisory [Insecurely configured geth can make funds remotely accessible]

    Security Advisory [Insecurely configured geth can make funds remotely accessible]

    Michael JohnsonBy Michael JohnsonDecember 10, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Insecurely configured Ethereum clients with no firewall and unlocked accounts can lead to funds being accessed remotely by attackers.

    Affected configurations: Issue reported for Geth, though all implementations incl. C++ and Python can in principle display this behavior if used insecurely; only for nodes which leave the JSON-RPC port open to an attacker (this precludes most nodes on internal networks behind NAT), bind the interface to a public IP, and simultaneously leave accounts unlocked at startup.

    Likelihood: Low

    Severity: High

    Impact: Loss of funds related to wallets imported or generated in clients

    Details:

    It’s come to our attention that some individuals have been bypassing the built-in security that has been placed on the JSON-RPC interface. The RPC interface allows you to send transactions from any account which has been unlocked prior to sending a transaction and will stay unlocked for the entirety of the the session.

    By default, RPC is disabled, and by enabling it it is only accessible from the same host on which your Ethereum client is running. By opening the RPC to be accessed by anyone on the internet and not including a firewall rules, you open up your wallet to theft by anybody who knows your address in combination with your IP.

     

    Effects on expected chain reorganisation depth: none

    Remedial action taken by Ethereum: eth RC1 will be fully secure by requiring explicit user-authorisation for any potentially remote transaction. Later versions of Geth may support this functionality.

    Proposed temporary workaround: Only run the default settings for each client and when you do make changes understand how these changes impact your security.

     

    NOTE: This is not a bug, but a misuse of JSON-RPC.

     

    ADVISORY: Never enable JSON-RPC interface on an internet-accessible machine without a firewall policy in place to block the JSON-RPC port (default: 8545).

     

    eth: Use RC1 or later.

     

    geth: Use the safe defaults, and know security implications of the options.

    –rpcaddr  “127.0.0.1”. This is the default value to only allow connections originating on the local computer; remote RPC connections are disabled

    –unlock. This parameter is used to unlock accounts at startup to aid in automation. By default, all accounts are locked



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Michael Johnson

    Related Posts

    Announcement on planned withdrawal from exodus

    December 13, 2025

    Secret Sharing and Erasure Coding: A Guide for the Aspiring Dropbox Decentralizer

    December 13, 2025

    building the decentralized web 3.0

    December 13, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    The global economy is still paying for big banks’ laziness

    Crypto December 13, 2025

    Disclosure: The views and opinions expressed here belong solely to the author and do not…

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025

    why are Bitcoin and top altcoins tanking?

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 2025

    AGII Deploys Adaptive Integrity Core for Autonomous Contract-Level Verification

    December 10, 2025

    AGII Launches Predictive Threshold Engine to Strengthen Data-Driven Blockchain Intelligence

    December 8, 2025

    AGII Releases High-Gradient Decision Sequencer to Boost Next-Gen Blockchain Intelligence

    December 5, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    Crypto wrap: Bitcoin’s sharp fall drags Ethereum, XRP, Solana and BNB lower

    October 19, 2025

    Imagen Network to Support Kadena Chainweb EVM for Enhanced Interoperability

    October 23, 2025

    Bitcoin’s institutional surge widens trillion-dollar gap with altcoins

    October 25, 2025

    The global economy is still paying for big banks’ laziness

    December 13, 2025

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    AGII Launches Hybrid Logic Engine to Strengthen Predictive Web3 Infrastructure Control

    December 1, 20251 Views

    AGII Deploys Multi-Threaded Decision Layer to Advance High-Speed Blockchain Intelligence

    November 26, 20251 Views

    AGII Enhances Predictive Intelligence to Strengthen Smart Contract Reliability

    November 19, 20251 Views

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 20250 Views
    Don't Miss

    The global economy is still paying for big banks’ laziness

    Crypto December 13, 2025

    Disclosure: The views and opinions expressed here belong solely to the author and do not…

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025

    why are Bitcoin and top altcoins tanking?

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Apex Fusion expands to Base with bAP3X token deployment

    December 3, 20253 Views

    FOIA reveals US Marshals sitting on at least $1.6B in BTC

    December 3, 20253 Views

    Kraken buys Backed Finance, expands tokenized stock platform

    December 3, 20253 Views

    Former OpenSea manager’s insider trading conviction overturned

    December 1, 20253 Views
    Don't Miss

    The global economy is still paying for big banks’ laziness

    Crypto December 13, 2025

    Disclosure: The views and opinions expressed here belong solely to the author and do not…

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025

    why are Bitcoin and top altcoins tanking?

    December 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    The global economy is still paying for big banks’ laziness

    December 13, 2025

    How Tether-backed Twenty One plans to rival MicroStrategy

    December 13, 2025

    Announcement on planned withdrawal from exodus

    December 13, 2025
    Recent Posts
    • The global economy is still paying for big banks’ laziness
    • How Tether-backed Twenty One plans to rival MicroStrategy
    • Announcement on planned withdrawal from exodus
    • why are Bitcoin and top altcoins tanking?
    • Tether thinks Jack Mallers will keep focus on Twenty One’s BTC, not USDT
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.