Jump to content

Backdoor Code Discovered in Popular Bitcoin Mining Equipment

I came across the article. Anyone who mines with Bitmain Antminers should see this article. Hope this helps :D" Antbleed is a backdoor introduced by Bitmain into the firmware of their bitcoin mining hardware Antminer.

The firmware checks-in with a central service randomly every 1 to 11 minutes. Each check-in transmits the Antminer serial number, MAC address and IP address. Bitmain can use this check-in data to cross check against customer sales and delivery records making it personally identifiable. The remote service can then return "false" which will stop the miner from mining.

The patch was introduced here (pastebin) and can be seen in the source: here (github)

At worst, this firmware backdoor allows Bitmain to shut off a large section of the global hashrate (estimated to be at up to 70% of all mining equipment). It can also be used to directly target specific machines or customers. Standard inbound firewall rules will not protect against this because the Antminer makes outbound connections.

Even without Bitmain being malicious, the API is unauthenticated and would allow any MITM, DNS or domain hijack to shutdown Antminers globally. Additionally the domain in question DNS is hosted by Cloudflare making it trivially subjected to government orders and state control."

"Around 70% of Bitcoin hashrate affected

Bitcoin Core developer Peter Todd says "any MITM attacker or DNS attacker can activate it [Antbleed backdoor]" as there is no authentication mechanism included in the firmware."

 

https://www.bleepingcomputer.com/news/security/backdoor-code-discovered-in-popular-bitcoin-mining-equipment/

http://www.antbleed.com/

 

antbleed.PNG

Edited by MrBurnZZ
Link to comment
Share on other sites

Link to post
Share on other sites

Thanks for the fix, moved back to the new section ;)

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

Umm... the linked article also says this.

"UPDATE [April 28, 2016]: Bitmain has issued a firmware update that removes the backdoor code. The company explained in a blog post the reasons the code was included in the firmware in the first place, and apologized to customers."

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, DLex said:

Umm... the linked article also says this.

"UPDATE [April 28, 2016]: Bitmain has issued a firmware update that removes the backdoor code. The company explained in a blog post the reasons the code was included in the firmware in the first place, and apologized to customers."

it says what?

 

Blog Post?

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Prysin said:

it says what?

 

Blog Post?

It says backdoor already patch of last year.

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

36 minutes ago, DLex said:

Umm... the linked article also says this.

 

"UPDATE [April 28, 2016]: Bitmain has issued a firmware update that removes the backdoor code. The company explained in a blog post the reasons the code was included in the firmware in the first place, and apologized to customers."

Glad to see why they did it and that they fixed this issue quickly.

if you want to annoy me, then join my teamspeak server ts.benja.cc

Link to comment
Share on other sites

Link to post
Share on other sites

39 minutes ago, Prysin said:

it says what?

 

Blog Post?

The reason they say was that there were 3 incidents where a very large amount of miners was stolen or withheld by others from their customers. 

Folding stats

Vigilo Confido

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, NumLock21 said:

It says backdoor already patch of last year.

Doing a quick search shows this happened in April 2017, somehow they got the year wrong.

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×