Security Patch Announcement

in #steem4 years ago (edited)


Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain.

This threat did not create any risk to Steem accounts or token balances, however, our engineers quickly located the problem and fixed it. The patch was deployed to steemit's Steem nodes within 24 hours of discovering the bug. We have contacted witnesses to update their seed and witness nodes to preserve the stability of the P2P network and are in the process of informing exchanges to ensure their continuous operation. The patch doesn't require a replay; Node operators should simply update and restart steemd.

At this time, we do not believe the vulnerability is being actively exploited in any sort of attack, however, we recommend anyone running a steemd node upgrade to the newest version of stable. This can be done via docker pull steemit/steem using our provided Docker image.

steemit devs



How do I update my witness please?

If you are not running a witness server, then you don’t have to worry about it.

@Curie 's Witness/Seed has been updated, Cheers.

All my servers and services have been updated with the updated code.

Good work Steem Team!

Check, I update 3 hours ago my witness servers.

All my servers already updated.

Updated and running smoothly. Thank you for a quick turn around of fixing the issue.

All my witness servers are up to date.
Full STEEMING continue.


Good job dev, good to catch this issue before it is too late.

Way to go, guys!

How can we explore the next steemit updates? I would like to know what you guys working at in the near future...


good that you guys take care of it.

Already updated seed and witness nodes.
keep up the updates:P

All jacked up and good to go!


Both my main and back up witness nodes are updated and running. Thanks for the update!


It's been done for a while now. Thanks for the official post.

witness server update, up and running.

@steemitdev Got a 32.75% Vote via @klye

Send any amount of STEEM or SBD Over 1.000 & Recieve a RANDOM @KLYE VOTE
Make sure to include the link to your post in the memo field of the transfer!
( Any amounts < 1.000 STEEM or SBD will be considered donations )
Vote power is Generated via RNG (Random Number Generator)

wow great news.

It's reassuring to hear that there was such a quick and robust response before this vulnerability was exploited, good job to everyone involved!

My server has been updated, thank you.

I LOVE knowing that you guys are on it. Thank you.

That's a relief. Thanks for the info

Thats a great least we have wonderful engineers. Thanks for info

Thank you for looking after the community, the investments and the tech!

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain

Who informed?
Where informed ?
Could you refer to an issue or PR, please.

This isn't responsible for the network slowing down for about half the day each day, is it? Bandwidth seems to get crushed around the same hours all the time.

Bandwidth is unrelated.

could you explain how to do this o.O!!!!!!!!!!!!!

Suggestion, could it be added a check, verification, who of witnesses did update and give us voters this information on that witness web page, so we voters can ask 'our' witness to do their job or we can take votes away from the ones not doing update. Could this be done?

Kudos to the engineers for a timely intervention.
We are unstoppable.

A DoS is not so bad unless it lasts a lot. It is great to hear that it is fixed now, you are moving fast, guys, great job!

good job guys.

Cryptwo Witness node has been all updated

thanks for the info!
great help...
God bless!!!

Kudos to all the engineers working around the clock to keep the Steem/Steemit platform safe.

In these days of volatile digital vulnerabilities, your tasks are no easy jobs! You guys and ladies rock.

Thanks for sharing this information.

Good thing your on top of things guys. Good job

Congratulations @steemitdev, this post is the most rewarded post (based on pending payouts) in the last 12 hours written by a User account holder (accounts that hold between 0.1 and 1.0 Mega Vests). The total number of posts by User account holders during this period was 2609 and the total pending payments to posts in this category was $11820.44. To see the full list of highest paid posts across all accounts categories, click here.

If you do not wish to receive these messages in future, please reply stop to this comment.

Congratulations, your post received one of the top 10 most powerful upvotes in the last 12 hours. You received an upvote from @thejohalfiles valued at 281.70 SBD, based on the pending payout at the time the data was extracted.

If you do not wish to receive these messages in future, reply with the word "stop".

Any information that the system is safe in me is very encouraging.

I am glad to hear you in this case. Security is a constant battle and Steemit may be attacked as it gets more popular. Some of us remember the previous attacks. At least we have some other options to access the blockchain..

Thanks so much for keeping us informed as quickly as possible of threats to Steemd security. Much appreciated!

Ok. We totally understand that there will always be security risks. Now we can rest assured that your security team is actively in control. We shall keep steeming

My witness node is now compliant with the update as per @someguy123 revision he posted for steem-in-abox

Wow, i am glad the probem was identified on time and fixed. Thanks for the important update

Where are the release notes?
What has been changed?

is this the reason poloniex deposit is broken again?

Can you please provide URL to commit which fixes the issue? It that related to latest fc library changes?

Please visit this link
i am sure changing your mind

Thank you..👌

Coin Marketplace

STEEM 0.35
TRX 0.06
JST 0.046
BTC 38387.22
ETH 2779.17
USDT 1.00
SBD 4.35