Ethereum's Constantinople Upgrade Faces Delay Due to Security Vulnerability
Ethereum's major Constantinople upgrade was delayed after blockchain audit firm ChainSecurity discovered a security issue with one of the changes.

Ethereum’s long-anticipated Constantinople upgrade has just been delayed after a critical vulnerability was discovered in one of the planned changes.
Smart contract audit firm ChainSecurity flagged Tuesday that Ethereum Improvement Proposal (EIP) 1283, if implemented, could provide attackers a loophole in the code to steal user funds. Speaking on a call, ethereum developers, as well as developers of clients and other projects running the network, agreed to delay the hard fork – at least temporarily – while they assessed the issue.
Participants included ethereum creator Vitalik Buterin, developers Hudson Jameson, Nick Johnson and Evan Van Ness, and Parity release manager Afri Schoedon, among others. A new fork date will be decided during another ethereum dev call on Friday.
Discussing the vulnerability online, the project's core developers reached the conclusion that it would take too long to fix the bug prior to the hard fork, which was expected to execute at around 04:00 UTC on Jan. 17.
Called a reentrancy attack, the vulnerability essentially allows an attacker to "reenter" the same function multiple times without updating the user about the state of affairs. Under this scenario, an attacker could essentially be “withdrawing funds forever,” said Joanes Espanol, CTO of blockchain analytics firm Amberdata in a previous interview with CoinDesk.
He explained:
"Imagine that my contract has a function which makes a call to another contract… If I’m a hacker and I’m able to trigger function a while the previous function was still executing, I might be able to withdraw funds."
to one of the vulnerabilities found in the now-infamous DAO attack of 2016.
ChainSecurity's post explained that prior to Constantinople, storage operations on the network would cost 5,000 gas, exceeding the 2,300 gas usually sent when calling a contract using "transfer" or "send" functions.
However, if the upgrade was implemented, "dirty" storage operations would cost 200 gas. An "attacker contract can use the 2300 gas stipend to manipulate the vulnerable contract’s variable successfully."
Constantinople was previously expected to activate last year, but was delayed after issues were found while launching the upgrades on the Ropsten testnet.
Ethereum image via Shutterstock
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
What to know:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
XRP climbs to $1.90 but struggles to break out of tight range

Traders are watching $1.88 as support and $1.94–$2.00 as the levels XRP needs to clear to break consolidation.
What to know:
- XRP rose about 0.4 percent to trade near $1.90, but remained locked in a narrow consolidation range.
- Support around $1.88 has repeatedly attracted buyers, while rallies continue to stall below the $1.92 to $1.94 resistance band.
- Traders expect range-bound price action to persist unless XRP breaks above $1.94 toward $2.00 or falls below $1.88 toward the $1.80 area.











