Bitcoin
$ 29,394.00 3.34%
Ethereum
$ 1,986.72 2.95%
Solana
$ 50.03 5.17%
Dogecoin
$ 0.084660 1.94%
ApeCoin
$ 7.78 2.55%
STEPN
$ 1.41 1.03%
Terra
$ 0.000166 14.07%

Zcash bug threatens to reveal user IPs; no respite soon says community developer

Zcash bug threatens to reveal user IPs no respite soon says core developer

A Zcash bug threatens to reveal the metadata that contains the complete nodes along with shielded IPs. This bug, if materializes, threatens the Zcash forks as well.

Duke Leto, a community developer for Komodo (KMD), announced the bug in his blog. He goes on to add that to track the issue, a ‘Common Vulnerabilities and Exposures’ (CVE) code is already underway. As of September 29, no positive progress has been reported.

Zcash bug will ultimately reveal user identities

Leto explains that ever since Zcash and its protocol begin operations, the bug threatening the security of all the shielded addresses has always been there. Moreover, every Zcash source code forks, too, have the same glitch. It can reveal every IP address who owns a shielded address (zaddr) along with the associated nodes.

For example, if ‘A’ hands over a zaddr to ‘B’ to pay him, ‘B’ could very well discover the IP address of ‘A.’ This is frightening since the very foundation of a cryptocurrency transaction is shielded IP addresses. It goes against the Zcash design protocols and every known crypto security regulation.

In theory, anyone whose zaddr is published is under threat of identity revelation due to their IP address being in public. This vulnerability can expose the personal IP addresses of millions of Zcash and Zcash protocol users. Geo-location and IP address are associated with zaddr and hence vulnerable. Zcash problems will increase further as recently Coinbase in the United Kingdom removed Zcash for its local customers.

Multiple cryptocurrencies affected by Zcash bug

People who have not used a zaddr ever or employed a Tor Onion routing will not be victims. Moreover, there are many more cryptocurrencies that will face severe blow due to the same bug. Leto has provided a detailed list of cryptocurrencies facing a similar issue.

A non-exhaustive list includes many prominent names including Pirate, Snowgem, Ycash, ZClassic, Verus, Safecoin, VoteCoin, Arrow, Anon, Zelcash and many more. Out of these names, many have taken preventive steps as well. For example, Komodo no longer offers shielded address feature and now uses Pirate chain for this feature, making it secure against the said Zcash bug.

Gurpreet Thind

Gurpreet Thind

Gurpreet Thind is pursuing Masters in Electrical Engineering at University of Ottawa. His scholarly interests include IT, computer languages and cryptocurrencies. With a special interest in blockchain powered architectures, he seeks to explore the societal impact of digital currencies as finance of the future. He is passionate about learning new languages, cultures and social media.

Related News

Hot Stories

Michael Saylor says market crash will benefit Bitcoin
Ethereum wipes out $8.10B while eagerly awaiting 'The Merge'
Terra admits to facing technical issues in resuming LUNA and UST transfer 
RoboApe could be valued over Dogecoin and other crypto-memes.
Crypto exchanges are relisting LUNA after the crash

Follow Us

Industry News

eBay jumps into declining NFT business with Wayne Gretzky's help
Crypto crowd’s shocking prominence in Davos
Balenciaga U.S. stores to accept BTC and ETH starting June 2022
BTC Pizza Day is celebrated amid crypto crash
CV VC launches Africa-focused blockchain fund