Hackers Scoop $20 Million in ETH From Exposed Ethereum Nodes
The first half of June has seen a series of high profile attacks rock the cryptocurrency ecosystem, with the recent South Korean exchange Coinrail hacked to the tune of around $40 million and ZenCash targeted by a successful 51% attack.
One of the most successful hacks of 2018, however, didn’t occur with a bang, but with a whisper — the discrete siphoning of over $20 million in ETH from poorly-configured Ethereum nodes.
Hackers have succeeded in stealing over $20 million by hijacking insecure Ethereum nodes — an issue that was highlighted in March this year by Chinese security giant Qihoo 360, who notably raised concerns recently regarding the security of the soon-to-launch EOS blockchain.
Someone tries to make quick money by scanning port 8545, looking for geth clients and stealing their cryptocurrency, good thing geth by default only listens on local 8545 port. So far it has only got 3.96234 Ether on its account, but hey it is free money! pic.twitter.com/YVSWlMtYGa
— 360 Netlab (@360Netlab) March 15, 2018
Insecure Geth Clients Lose Out
Qihoo 360 attempted to alert the Ethereum community several months ago, warning users of the Geth Ethereum client that malicious parties were scanning port 8545 — the default listening port for the client. However, at the time of the report, hackers had only captured a little under 4 ETH for their effort, resulting in these warnings being largely ignored by the Ethereum community.
Fast forward a few months and a new tweet from Qihoo 360 reveals that the hackers never stopped, having currently captured a massive 38642.6 ETH haul — worth over $18 million at the time of this report.
Remember this old twitter we posted? Guess how much these guys have in their wallets? Check out this wallet address https://t.co/t4qB17r97J $20,526,348.76, yes, you read it right, more then 20 Million US dollars https://t.co/SXHrdTcb6e
— 360 Netlab (@360Netlab) June 11, 2018
The wallet associated with the hackers, to which all of the siphoned ETH has been sent, has received roughly 5,000 transactions to date, with an average transaction amount of around 7 ETH. This entire haul was accumulated simply by scanning the internet for Geth users that left their JSON-RPC port 8545 open to the world and hijacking their wallets.
Almost three years ago, the Ethereum project issued a security alert regarding the high risk associated with insecurely configured Ethereum clients with no firewall, specifically mentioning the built-in security placed on the JSON-RPC interface.
Despite the fact port security is a critical element of overall node security, many node operators have taken to social media over the last two years to announce the loss of their capital.
According to 360, scanning attempts on port 8545 have now increased dramatically as a result, with copycat hackers moving in on weak targets.
If you have honeypot running on port 8545, you should be able to see the requests in the payload. Which has the wallet addresses. And there are quite a few ips scanning heavily on this port now. https://t.co/xSB6tuGZ9u
— 360 Netlab (@360Netlab) June 11, 2018
Ethereum Market Data
At the time of press 2:54 am UTC on Mar. 27, 2022, Ethereum is ranked #2 by market cap and the price is up 1.35% over the past 24 hours. Ethereum has a market capitalization of $378.13 billion with a 24-hour trading volume of $8.9 billion. Learn more about Ethereum ›
Crypto Market Summary
At the time of press 2:54 am UTC on Mar. 27, 2022, the total crypto market is valued at at $2.02 trillion with a 24-hour volume of $60.92 billion. Bitcoin dominance is currently at 42.01%. Learn more about the crypto market ›