Lounge Started Jun 15, 2026 12:46 PM

P2Pool vulnerability is actively being exploited. Update to v4.16 ASAP

11 replies - 562 views - 0 thanks - 0 tippers - 4 watchers

Replies

Page 1 of 2 - 11 total
Jun 15, 2026 12:54 PM
#2

yeah like they thought a reddit post was enough for all the people to update lmao
is like CEX that doing the delisting and not allowing withdrawal after the date, like, people be having lives lmao, they not chronically online refreshing the reddit all day long LOL
like, they have their rigs mining, it's stable, they just do whatever u know

anyways, tail emission so the daily reward for the whole network is not even that much anyways
and P2Pool didnt even get that much adoption in the first place
in comparaison to Qubic, is really not that much

people gotta update tho
and like, in cases some be setting up the mining thing in the background on random computers, stealing CPU cycles but the ones that set those up dont even have access to these no more lol, so like, maybe some that will never even update, ever lol
shouldnt be that much of these tho, espcially for P2Pool which requires the whole blockchain i think? idk, only been doing solo-mining and when didnt was pool when P2Pool wasnt a thing yet but else just solo-mining so idk much about P2Pool anyways

tldr:
not as bad as Qubic, but people gotta update still:
https://github.com/SChernykh/p2pool/releases

0 thanks - 0 tippers
Jun 15, 2026 2:30 PM
#3

They didn't only post on Reddit. They also posted on the IRC/Matrix chatrooms, on GitHub/GitLab, and I believe @xenu or somebody here shared it on the forum. That pretty much covers it I think.

0 thanks - 0 tippers
Jun 15, 2026 2:38 PM
#4

@H1XMR I posted it on Twitter too and it is getting a lot of engagement

1 thanks - H1XMR - 0 tippers
Jun 15, 2026 4:12 PM Edited Jun 15, 2026 4:16 PM
#5

just sayin, 3 days notice kinda short, people have lives

like those cryptocoins doing the whole changing the whole blockchain or somethin and they need users to "swap their coins to the new chain", that shit literally never ever worked

but also, it would have been exploited sooner or later anyways, so i guess there was just no right way to do it and that's just how tech be

0 thanks - 0 tippers
Jun 15, 2026 5:01 PM
#6

It's a fairly big vulnerability, not exactly the smartest choice to hold on to it. Fixing it right away would lead to its discovery and exploitation. A 3 days notice then live rollout was the best way it could've been handled, given the circumstances.

0 thanks - 0 tippers
Jun 15, 2026 5:15 PM
#7

A 3 days notice then live rollout was the best way it could've been handled, given the circumstances.

i agree there yea

so like, kinda like a hardfork? if majority update then the whole chains moves to the new version, right?
interesting that it's the 2 smallest ones (nano/mini) that didnt upgrade in time tho

which combined they're at like 13Mh/s (while nethash is 5.56Gh/s)
so quick napkin math:
5,569Mh/s (nethash) divided by 13Mh/s = 427.69
so attacker has a 1 in 427.69 chance to find a block
there is 720 blocks per day, 1 block = 0.6 XMR
so attacker gets 1 monero per day

def getting that lambo

and attacker could just be the one that found the vulnerability in the first place too

so, really not that big of a deal right there

while for zcash for example, the inflation bug thing could have been exploited by the ones that found it
but inflation bug is an actual big deal

idk, no big deal for 1 monero per day honestly, what's next? sending the fbi and zachxbt after them? smh

0 thanks - 0 tippers
Jun 15, 2026 5:32 PM
#8

This speed is probably fast enough, given notifications across so many communities. But as mentioned above, there will always be some nodes that, for various reasons, take a very long time to update or never at all.

Judged by similar projects, Tor Project may be the best-built open-source infrastructure project, it provides separate repositories for almost every Linux distribution and requires all relay operators to enable automatic update scripts in the installation docs. Unfortunately, even when a project does everything it can, looking at the release of the final 0.4.8 version in the chart below shows that after several days the update rate reached only 50%; after nearly two months, a quarter still hadn’t updated; and even today about 10% of nodes remain outdated — the version number has moved from 0.4.9.0 to 0.4.9.9, ten micro-releases later.

It’s a fact that some existing nodes will not update for a long time; all we can say is that everyone who could be notified was notified, and we’re helpless about the rest that remain exposed to vulnerability.
Screenshot20260616004651

0 thanks - 0 tippers
Jun 15, 2026 5:45 PM
#9

@GlitchFrame

i mean, monero has had a bunch of hardforks and is a main critique from bitcoiners that monero just keeps having hardforks
but it hasnt been an issue for monero

and on that reddit thread it says the issue is with mini/nano (13Mh/s combined), not the main one (that is at 304Mh/s), so i guess it's really just a "not enough people using P2Pool in the first place"

like point is, monero has lots of users, it hasnt been an issue
main P2Pool has more users, they did update
mini/nano not many users, they're the minority of users but the majority for mini/nano, so if they just be doing other things like at the beach just chillin and having a fun time or somethin u know, maybe it's literally just 5 random dudes on nano/mini, and 3 are just at the beach not being chronically online right now lol

so idk, could it be fixed by like, adding more hashrate to mini/nano? like people that did update on the main P2Pool, can they just move their hashrate to mini/nano to force the update thing to happen? would be an easy fix there...

idk, maybe that's not even how it works, i just have no clue about P2Pool honestly

0 thanks - 0 tippers
Jun 16, 2026 5:25 AM
#11

@xenu
thanks on the update on that

idk i just fail to understand why it's even a big deal in the first place, not trying to downplay on purpose but from the link you just posted:
https://github.com/SChernykh/p2pool/security/advisories/GHSA-fm6j-gf38-p925

How long until everything is back to normal?
For you personally: the moment you upgrade and restart. For the network as a whole: as soon as the large majority of hashrate has upgraded, since updated nodes simply ignore the attack.

so from that explanation, to me it seems like it literally works the exact same way as a hardfork, if majority of the network upgrade then all nodes ignore the attack
so... could literally just move some of the hashrate from the main to mini/nano and problem solved, the 1 rogue attacker (that is getting even less than 1 monero per day cause not even getting the ones from the nodes that did update) would be getting nothing
and the ones that didnt update, well, same as when a centralized pool goes offline or a mining protocol change, they just missing on their own reward until they update but at least they wouldnt be stolen

so looking back, imo the 3 days notice was indeed enough, and now the fix is pretty much straight forward, just get mini/nano to update by bringing some additional hashrate on these and problem solved

should have been more clear from the reddit thread tho...

0 thanks - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.