Back to news

Recent Social Engineering Incident Targeting Core-Geth Client on Ethereum Classic Network

According to an incident report released by Classix, a social engineering event targeting the Core-Geth client occurred recently on the Ethereum Classic network. Attackers impersonated identities to induce node operators to upgrade to an unofficially reviewed client version.

The report indicates that a version labeled ethereumclassic/core-geth v1.13.0 was released on September 14, but this version had not undergone the existing maintenance team's code review process, constituting an unauthorized release that deviated from normal version management and review mechanisms.

This unreviewed version was subsequently packaged as a "security update" and promoted widely, with dissemination channels including ETC's official social media accounts, community updates on CoinMarketCap, and direct email notifications, leveraging the credibility of official channels to induce node operators to upgrade voluntarily.

Classix's report noted that a few mining pool nodes had indeed switched to this unreviewed v1.13.0 version; however, after the incident was discovered, these mining pools gradually reverted their clients to the long-term maintenance version etclabscore/core-geth v1.12.23, which is recognized in the industry as a stable branch.

In terms of actual impact, the incident ultimately did not result in any block loss, did not trigger chain reorganization, did not incur financial losses, and did not lead to any service interruptions, with the overall network operation remaining substantially intact and most node operators unaffected.

From a market mechanism perspective, such incidents do not directly involve financial transactions or price drives, but their risk exposure falls on mining pools and node operators relying on the Core-Geth client. If the scope of the switch were to expand without timely detection, on-chain consensus division would directly harm the credibility of the ETC network, subsequently affecting market participants holding or trading ETC assets; timely warnings and version rollbacks were managed by the long-term maintenance team and node operators following the mainstream branch, whose network stability has been validated.

Classix specifically warned that the unreviewed version modified two key underlying functions: chain selection logic and node discovery mechanisms, both of which directly determine how nodes recognize the main chain and how they discover and connect to peer nodes. If widely adopted, there is a potential risk of network division.

Source: Public Information

ABAB AI Insight

Ethereum Classic, which forked from Ethereum in 2016 due to The DAO incident, has had its client ecosystem maintained by the community for a long time and has historically faced targeted attacks: in 2020, the ETC network suffered multiple 51% hash power attacks, leading to chain reorganizations and double-spending incidents, exposing the security vulnerabilities of small to medium-sized public chains when hash power concentration is insufficient. This recent social engineering attack targeting the Core-Geth client continues the trend of attackers shifting from "directly attacking on-chain consensus" to "polluting the underlying software supply chain."

From a resource mobilization perspective, the attackers did not invest hash power or funds for on-chain attacks this time but chose a lower-cost path—impersonating official social accounts, community platforms, and email channels to induce node operators to voluntarily complete client replacements. Essentially, this shifted the attack cost from "on-chain games" to "social engineering," using trust vulnerabilities in information channels instead of the high economic costs of hash power confrontation.

This model is similar to the recent surge in open-source software supply chain attacks, such as the malicious version injections in several popular npm packages in 2021 and the backdoor implanted in Log4j-related components in 2022, where attackers commonly disguise themselves as "official maintained versions" or "security patches" for dissemination. Blockchain client software, as the underlying infrastructure of decentralized networks, is gradually becoming a new target for such supply chain-level attacks, with the industry currently in a phase of expanding its focus from "on-chain security" to "software supply chain security."

Structurally, this is essentially a struggle over "trust distribution rights," representing an early signal of industrial chain reconstruction: traditionally, the trusted sources of client versions are endorsed by the core maintenance team's code repositories and review processes, while social media, community updates, and emails were originally just tools for information dissemination. When attackers can bypass the code review process and directly forge "official endorsements" from dissemination channels, it indicates a misalignment of responsibilities between the "review nodes" and "dissemination nodes" in the client distribution chain, forcing the industry to preemptively implement mechanisms like version signature verification and multi-party review confirmations at the dissemination stage, rather than relying solely on self-certification by the publisher.

ABAB News · Cognitive Laws

  1. Attack the channels of trust distribution before the chain.
  2. Security vulnerabilities often lie not in the code, but in human hearts.
  3. The more decentralized the system, the more it relies on each node to verify itself.

Source

·ABAB News
·
6 min read
·9 hrs ago
分享: