The incident centers on the release of version 1.13.0 on September 14, which was pushed to the ethereumclassic/core-geth repository without input from established maintainers. According to an incident report by Classix, the update included 96 commits developed over just 56 hours, bypassing the typical pull request and peer-review process required for network stability. While the release claimed to patch critical vulnerabilities, investigators found that most cited security issues had already been addressed in previous versions or were inapplicable to the Ethereum Classic environment.
In section Cryptocurrency
Ethereum Classic operators roll back rogue Core Geth software update
Ethereum Classic mining pools have reverted to the stable Argos client after briefly adopting a disputed Core Geth v1.13.0 release. The unauthorized software, which was promoted as a critical security update, bypassed standard review protocols and altered consensus infrastructure, prompting urgent warnings from network maintainers to restore previous configurations.

Beyond the disputed security claims, the software introduced significant architectural changes, including the reactivation of Modified Exponential Subjective Scoring (MESS) and the replacement of existing node discovery infrastructure with hardcoded bootnodes. Although the migration reached several mining pool nodes, including four operated by 2Miners, operators successfully reverted to the maintained Argos v1.12.23 client before any consensus failures or economic losses occurred. Classix has since urged Ethereum Classic GitHub administrators to implement stricter repository controls to prevent further unauthorized releases and advised node operators to prioritize client diversity by considering alternatives like Besu or Nethermind.
Comments (0)
No comments yet. Be the first!