Parity Team Publishes Postmortem on $160 Million Ether Freeze

Parity has released new details on how a critical code flaw resulted in the freezing of $160 million worth of ether.

AccessTimeIconNov 15, 2017 at 3:05 p.m. UTC
Updated Aug 18, 2021 at 7:28 p.m. UTC

Presented By Icon

Election 2024 coverage presented by

Stand with crypto

The team behind the Parity ethereum software client has released new details on how a critical code flaw resulted in the freezing of $160 million worth of ether.

As it stands, there remains no immediate solution to renewing access to those funds – a situation which Parity acknowledged has caused "distress and anxiety" within the community. According to the post, there is "no timeline" for the release of the locked-up ETH – a move which may require a platform-wide upgrade to restore functionality to the more than 500 affected wallets.

  • Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
    13:18
    Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
  • Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
    05:10
    Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
  • The first video of the year 2024
    04:07
    The first video of the year 2024
  • The last regression video of the year 3.67.0
    40:07
    The last regression video of the year 3.67.0
  • The hack, which saw the "accidental" deletion of the code library which supports Parity's multi-signature wallets (those that require multiple keys to issue transactions), was due to an oversight in the wallet code, the blog post states. While the risk was identified on Github back in August, it was misinterpreted by the Parity team, and no action was taken to further secure the wallets.

    As for the process of finding a solution, Parity said that it would work on ethereum improvement protocols that might offer a way to bring back access. Following the attack, discussion has been circulating as to whether updating the code to unwind the problem would constitute a "bail-out" akin to the DAO controversy from last year.

    Regarding the potential release of the locked millions, Parity says it intends to "follow the will of the community" in deploying the code fixes.

    The team explained:

    "Parity Technologies will handle much of the development work around these proposals and work constructively with the Ethereum Foundation team and the community towards further protocol layer development."

    Going forward, Parity argued that "more extensive and formal procedures" are necessary for contract security, which applies not only to Parity, but is relevant to the entire ethereum platform.

    Last week's developments impacted as many as 584 wallets, according to Parity's tracker website. Some of these belonged to high-profile startups, including Parity founder Gavin Wood's Polkadot, which had $98 million in ether frozen in the attack.

    To prevent any additional problems, Parity said it removed the ability for users to deploy multi-sig wallets "until we feel we have the correct security and operations procedures in place."

    Frozen branch image via Shutterstock

    Disclosure

    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information have been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.


    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.