{"id":22354,"date":"2026-08-06T07:18:05","date_gmt":"2026-08-06T07:18:05","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/08\/06\/security-advisory-insecurely-configured-geth-can-make-funds-remotely-accessible\/"},"modified":"2026-08-06T07:18:05","modified_gmt":"2026-08-06T07:18:05","slug":"security-advisory-insecurely-configured-geth-can-make-funds-remotely-accessible","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/08\/06\/security-advisory-insecurely-configured-geth-can-make-funds-remotely-accessible\/","title":{"rendered":"Security Advisory [Insecurely configured geth can make funds remotely accessible]"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<p class=\"chakra-text css-gi02ar\"><strong>Insecurely configured Ethereum clients with no firewall and unlocked accounts can lead to funds being accessed remotely by attackers. <\/strong><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Affected configurations: <\/b><span style=\"font-weight:400\">Issue reported for Geth, though all implementations incl. C++ and Python can in principle display this behavior if used insecurely; only for nodes which leave the JSON-RPC port open to an attacker (this precludes most nodes on internal networks behind NAT), bind the interface to a public IP, and simultaneously leave accounts unlocked at startup.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Likelihood: <\/b><span style=\"font-weight:400\">Low<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Severity: <\/b><span style=\"font-weight:400\">High<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Impact: <\/b><span style=\"font-weight:400\">Loss of funds related to wallets imported or generated in clients <\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Details:<\/b><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">It\u2019s come to our attention that some individuals have been bypassing the built-in security that has been placed on the JSON-RPC interface. The RPC interface allows you to send transactions from any account which has been unlocked prior to sending a transaction and will stay unlocked for the entirety of the the session. <\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">By default, RPC is disabled, and by enabling it it is only accessible from the same host on which your Ethereum client is running. By opening the RPC to be accessed by anyone on the internet and not including a firewall rules, you open up your wallet to theft by anybody who knows your address in combination with your IP.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Effects on expected chain reorganisation depth: <\/b><span style=\"font-weight:400\">none<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Remedial action taken by Ethereum<\/b><span style=\"font-weight:400\">: eth RC1 will be fully secure by requiring explicit user-authorisation for any potentially remote transaction. Later versions of Geth may support this functionality.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Proposed temporary workaround:<\/b><span style=\"font-weight:400\"> Only run the default settings for each client and when you do make changes understand how these changes impact your security.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<\/p>\n<p class=\"chakra-text css-gi02ar\"><b>NOTE: This is not a bug, but a misuse of JSON-RPC.<\/b><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<\/p>\n<p class=\"chakra-text css-gi02ar\"><b>ADVISORY: Never enable JSON-RPC interface on an internet-accessible machine without a firewall policy in place to block the JSON-RPC port (default: 8545).<\/b><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<\/p>\n<p class=\"chakra-text css-gi02ar\"><b>eth: <\/b><span style=\"font-weight:400\">Use RC1 or later.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<\/p>\n<p class=\"chakra-text css-gi02ar\"><b>geth:<\/b><span style=\"font-weight:400\"> Use the safe defaults, and know security implications of the options.<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">&#8211;rpcaddr \u00a0&#8220;127.0.0.1&#8221;. This is the default value to only allow connections originating on the local computer; remote RPC connections are disabled<\/span><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">&#8211;unlock. This parameter is used to unlock accounts at startup to aid in automation. By default, all accounts are locked<\/span><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/blog.ethereum.org\/en\/2015\/08\/29\/security-alert-insecurely-configured-geth-can-make-funds-remotely-accessible\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Insecurely configured Ethereum clients with no firewall and unlocked accounts can lead to funds being accessed remotely by attackers. Affected configurations: Issue reported for Geth, though all implementations incl. C++ and Python can in principle display this behavior if used insecurely; only for nodes which leave the JSON-RPC port open to an attacker (this precludes [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":20792,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[24],"tags":[],"kronos_expire_date":[],"class_list":["post-22354","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=22354"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22354\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/20792"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=22354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=22354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=22354"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=22354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}