A serious security vulnerability has put the Dogecoin network at risk, with 69% of its nodes reportedly brought offline by a hacker exploiting the flaw.
On December 12, Andreas Kohl, co-founder of the Bitcoin sidechain Sequentia, claimed responsibility for disabling 69% of Dogecoin’s network using an old laptop from El Salvador. Kohl leveraged a vulnerability discovered by security researcher Tobias Ruck to carry out the attack.
A Flaw That Could Halt the Entire DOGE Network
According to data from Blockchair, Dogecoin previously had 647 active nodes. Following the attack, the number has dropped significantly to 315.
The Vulnerability
On December 4, an account on the X platform (formerly Twitter) named Department of DOGE Efficiency publicly disclosed a critical vulnerability called DogeReaper. This flaw allows attackers to remotely shut down Dogecoin nodes, potentially halting the entire network.
The vulnerability has been likened to the “Death Note” from the famous Japanese anime and manga series of the same name. By exploiting DogeReaper, an attacker can cause a segmentation fault error in a node simply by targeting its address. A segmentation fault occurs when a program attempts to access a restricted memory segment, prompting the operating system to stop the program for security reasons, thereby causing the node to go offline.
Since the addresses of Dogecoin nodes are publicly accessible, the flaw poses a severe risk to the network’s stability.
Expert Warnings
Security researchers have expressed concern over the potential impact of the flaw:
“If a malicious actor had discovered this vulnerability instead of us, they could have brought the entire Dogecoin network to a halt for several days, effectively freezing all transactions and block production.”
Coinbase’s Controversial Response
Despite the gravity of the issue, the Department of DOGE Efficiency revealed that Coinbase downplayed the vulnerability’s severity, awarding Tobias Ruck, the researcher who discovered it, a modest $200 bounty.
What’s Next for Dogecoin?
The attack has highlighted critical weaknesses in Dogecoin’s infrastructure. While the network remains operational, the incident raises questions about its resilience and the speed of its response to security threats.
As the Dogecoin community scrambles to address the flaw and restore network functionality, this episode serves as a stark reminder of the importance of robust cybersecurity in the blockchain ecosystem.