Share this article

Ethereum Client Bug Freezes User Funds as Fallout Remains Uncertain

An unknown amount of user funds on the ethereum network have been frozen due to a code issue with the Parity wallet software.

Updated Sep 13, 2021, 7:08 a.m. Published Nov 7, 2017, 4:55 p.m.
security, lock

An unknown amount of user funds on the ethereum network have been frozen due to a code issue with the Parity wallet software.

The security vulnerability which activated the freeze was found yesterday in ethereum's second most popular client by a developer going by the name "devopps199," who reported it on GitHub.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The vulnerability affects any Parity wallet deployed after July 20 that uses the company's "multi-signature" functionality. Under a multi-signature arrangement, more than one key is required to initiate and broadcast transactions.

So far, it's unclear how many of these wallets were deployed in that time frame and what amount of ether is currently stuck. According to data from EtherNodes.org, Parity constitutes roughly 20 percent of the network – and there's early indications that as much as $100 million worth of ether (if not more) may be inaccessible at this time.

This vulnerability follows another Parity issue from earlier this year, where wallets were hacked and $30 million in ether was stolen.

While the company patched that bug, another issue was still present in the code that allowed for today's exploit to happen. Speaking to CoinDesk, devopps said he is new to smart contracts and was following the logic of the former hack when he stumbled on the current problem.

What remains not as simple, however, is the process of figuring out how to retrieve the frozen funds.

Some developers have speculated that a hard fork is the only way to fix the problem. But as hard forks are a controversial upgrading mechanism – particularly in the context of ethereum - some in the community are already "refusing" to execute such an upgrade.

In the meantime, Parity has issued a statement warning users to avoid creating new multi-signature wallets, announcing:

"We​ ​are​ ​advising​ ​users​ ​not​ ​to​ ​deploy​ ​any​ ​further​ ​multi-sig​ ​wallets​ ​until the​ ​issue​ ​has​ ​been​ ​resolved​, ​and​ ​to​ ​not​ ​send​ ​any​ ​ether​ ​to​ ​wallets​ ​that have​ ​been​ ​deployed​ ​and​ ​are​ ​in​ ​use​ ​already.​"

"Parity Technologies would like to assure everyone that we are analyzing the situation, and we will release an update with further details shortly," the statement ends.

CoinDesk will continue monitoring this developing story.

Security lock image via Shutterstock

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Bitcoin and ether volatility trading gets easier with Polymarket's new contracts

Poker chips (AidanHowe/Pixabay)

Polymarket has launched new prediction markets tied to Volmex's bitcoin and ether 30-day implied volatility indices.

What to know:

  • Polymarket has launched new prediction markets tied to Volmex's bitcoin and ether 30-day implied volatility indices, allowing users to bet on how high volatility will get in 2026.
  • The contracts pay out if volatility indices reach or exceed a preset level by Dec. 31, 2026, letting traders wager on the intensity of price swings rather than market direction.
  • Early trading implies roughly a one-in-three chance that bitcoin and ether volatility will nearly double from current levels.