Share this article

Developers Debate Disclosure Protocols After ‘Accidental’ Ethereum Hard Fork

Ethereum’s largest client Geth hard-forked after a bug was tripped Wednesday. Developers are now weighing the merits of security disclosures methods.

Updated Sep 14, 2021, 10:30 a.m. Published Nov 13, 2020, 5:52 p.m.
birmingham-museums-trust-adudERb6uDM-unsplash

Ethereum developers are weighing changes to publicly disclosing critical bugs following the Nov. 11 "accidental hard fork."

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

According to a technical write-up published by Geth – the largest Ethereum client written in the Go language – a denial-of-service (DoS) attack vector was intentionally triggered by a downstream user as a test, resulting in a 30-block minority chain.

Geth had fixed the bug in early October following a disclosure, but it still existed in prior versions of Geth. The bug temporarily caused nodes that had not updated to the correct version of Geth to go down a different path than other clients.

Now, developers are reordering the disclosure process for security vulnerabilities in the aftermath of what some developers have called the biggest threat against Ethereum since 2016’s attack on The DAO.

Read more: ‘Unannounced Hard Fork’ Was Trying to Prevent the Very Disruption It Caused

That question comes with baggage. A common ethos in open-source software (OSS) such as Ethereum is that vendors are tasked “to notify those affected by vulnerabilities in a timely manner,” Summa founder James Prestwich told CoinDesk in a message. In other words, Geth has a responsibility to give dependent users a heads-up on possible complications, he said.

'Disclosure is a complex topic'

Yet, blockchains, at their very core, are financial settlement mechanisms. The traditional methods of disclosing bugs in OSS can lead to undesirable outcomes for other players with money on the line.

In Friday’s All Core Developers’ call, Ethereum developer Micah Zoltu and Geth team leader Peter Szilágyi both disagreed with the issuance of a notification list for critical vulnerabilities. Zoltu claimed such a list would create an uneven playing field for projects, while Szilágyi said that every bug disclosure creates a weak point in Ethereum’s infrastructure.

For example, disclosing the bug early to service provider Infura – which most of decentralized finance (DeFi) uses to connect to the Ethereum blockchain – would be an unfair advantage against its competitors. Moreover, the consequences for the larger ecosystem could be severe if privileged information from the list leaked to adversarial parties.

Given the option again, Szilágyi said he would go about the recent disclosure in the same manner – meaning, keeping the consensus bug under wraps (although he said at one point during the call they should have let users know a past version of Geth held a vulnerability). Geth has done so for other consensus vulnerabilities, he said.

“Disclosure is a complex topic and user safety is paramount,” Prestwich concluded.

Update (November 13 21:00 UTC): A prior version of this article incorrectly stated that 80% of the network went down the wrong chain. Only nodes that had not updated to the correct Geth version joined the minority chain.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

Pudgy Penguins NFT are on a holiday rally. (Screenshot)

The NFT brand’s animated segments will air on the Sphere across Christmas week, signaling the crypto company's move into real-world consumer markets.

What to know:

  • Pudgy Penguins will run an ad campaign at the Las Vegas Sphere during Christmas week, one of the few crypto brands to secure a spot at the high-profile venue.
  • The NFT project, which launched on Ethereum in 2021, has expanded into physical toys and digital gaming as part of a broader consumer push.
  • Pudgy Penguins briefly overtook Bored Apes in floor price earlier this year and recently launched its PENGU token on Solana, now trading on major exchanges.