Close Menu
    X (Twitter)
    Blockchain Journal
    • News
      • Blockchain News
      • Bitcoin News
      • Ethereum News
      • NFT
      • DeFi News
      • Polkadot News
      • Chainlink News
      • Ripple News
      • Cardano News
      • EOS News
      • Litecoin News
      • Monero News
      • Stellar News
      • Tron News
      • Press Releases
      • Opinion
      • Sponsored
    • Price Analisys
    • Learn Crypto
    • Contact
    • bandera
    X (Twitter)
    Blockchain Journal
    Home » Critical vulnerability found in the NEO blockchain, comments from the NEO

    Critical vulnerability found in the NEO blockchain, comments from the NEO

    0
    By BlockchainJournal on December 3, 2018 News
    Share
    Facebook Twitter LinkedIn Pinterest Email

    chapter

    The Chinese technology corporation Tencent informed the developers of the blockchain protocol NEO and the node operators in their network about the presence of a vulnerability that could theoretically allow an attacker to remotely steal tokens or, as the researchers themselves call it, to engage in "remote piracy". About this he writes Blockmanity with reference to the publication posted by Tencent division in the social network Weibo.

    According to a statement by Tencent Security Lab, when a user launches a node on a network with a standard configuration, he is at risk. The company recommends all NEO node operators and GAS holders to pay attention to the security of their wallets and to update customers in a timely manner.

    Tencent proposes the following actions to protect itself from this vulnerability :

    • Upgrade to the latest version of the NEO-CLI client;
    • Try not to use remote procedure call (RPC) and manually change “BindAddress” to “127.0.0.1”;
    • If RPC is to be activated due to the need, try to change the port number of the RPC using the https port of JSON-PRC or install a firewall.

    The founder of the cryptocurrency NEO startup Eric Zhang commented on a vulnerability in the project protocol that allows attackers to steal users' tokens through the remote procedure call function.

    Zhang argues that the vulnerability does not threaten "regular users", since for its operation the RPC function must be activated in the NEO-CLI client, "the use of which is excluded by such users."

    Zhang Erik @neoerikzhang , founder and core developer of #NEO , denied the risk of theft for remote token normal users and explained the reasons from the technical point of view. See report below? pic.twitter.com/yKfXYbD8bs

    – NEO Smart Economy (@NEO_Blockchain) December 2, 2018

    He also draws attention to the fact that RPC is activated not by default, but only under certain conditions and through the command line. The same applies to the “BindAddress” option, which by default corresponds to the value “127.0.0.1”.

    "If the user does not attempt to change the configuration manually, the likelihood of associated risks may be excluded," the publication says.

    Accordingly, users who decide to change the configuration manually, Zhang can not guarantee anything. In mid-June, Chinese antivirus software developer Qihoo 360 reported that the incorrect configuration of certain applications and farms in the Ethereum network resulted in their users losing over $ 20 million at the exchange rate at that time.

    Late last week, NEO announced the opening of the Competence Center in St. Petersburg and the beginning of the development of a distributed file storage.


    blockchain Economy ethereum Featured GAS NEO Network Report Twitter
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    BlockchainJournal

    Related Posts

    North Korean hackers steal record $2 billion in crypto during 2025

    December 18, 20254 Mins Read

    Crypto losses from hacks hit 3.4 billion in 2025

    December 18, 20254 Mins Read

    xStocks launches tokenization of US stocks in Telegram’s TON Wallet

    December 18, 20254 Mins Read

    Zcash falls below 400 dollars but whales increase their holdings by 21%

    December 18, 20254 Mins Read

    ETHGas raises 12 million to revolutionize Ethereum with 50-millisecond transactions

    December 18, 20254 Mins Read

    ARK Invest spends 25.4 million dollars on Coinbase and other crypto stocks

    December 18, 20254 Mins Read

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blockchain Journal

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.