Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Blockchain Can Suffer from the Same Vulnerabilities as Any Other Application current page
Link copied

Blockchain Can Suffer from the Same Vulnerabilities as Any Other Application

Aug 13, 2018
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Blockchain Can Suffer from the Same Vulnerabilities as Any Other Application
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

blog-blockchain-can-suffer-from-the-same-vulnerabilities.jpg

Earlier this year, The Hacker News reported on a wicked vulnerability within the EOS Blockchain Platform. While the vulnerability is considered critical, and the method of exploitation fairly basic (a maliciously crafted file), the ramifications are truly astounding. After the vulnerable parser reads the file, it forces an exploit on the node, which could then be leveraged against the supernode on the EOS platform. The supernode is responsible for collecting transaction information and packing it into blocks. Once the threat actor owns the supernode, they can modify or create malicious blocks that would control the entire EOS network. This includes everything the EOS Blockchain Platform has been implemented to perform – from cryptocurrency, supply chain management, to identity storage – whatever the EOS Platform has been implemented to support as a solution.

The uncrackable Blockchain (as it is advertised) can be owned by the fundamental technology designed to protect it; WASM files (smart contracts) and a simple file upload.

My point in this blog, however, is not to beat up the EOS Blockchain Platform, but rather to point out that every technology is vulnerable. Blockchain has been advertised as an ultra-secure database ledger technology, but the operating system, web service, and other components to make it a viable platform can suffer from the same risks as any other application or technology. People making coding mistakes and technology can have flaws, and thus every system is potentially vulnerable in some way. Blockchain is not different, and if you implement it for such things as cryptocurrency, a critical flaw could jeopardize all the data in the ledger; in this case, all the money being stored and processed via transactions.

Let that sink in for a minute. This one risk could have left all the cryptocurrency in the system vulnerable to theft. This perfectly “secure” technology is not perfectly secure after all. That alone should be a reminder to everyone that we cannot forgo cybersecurity basics just for the hype of a new technology.

So, what are cybersecurity basics?

  • Asset Inventory – The identification and lifecycle of all software, code, applications, nodes, and operating systems used in the Blockchain.
  • Change Control – Changes to the operating system, application, and resources are documented and go through a formal change control process.
  • Configuration Management – The hardening and removal of default settings that are a liability for the operating system, application, or network are mitigated.
  • Vulnerability Management – The operating system, application, web application, and source code are reviewed for vulnerabilities, and risks are prioritized accordingly.
  • Log Management – The centralized management and parsing of log files from all resources in the environment, including transaction logs.
  • Patch Management – The systematic and predictable methodology for deploying maintenance and security patches to all systems in the environment – from firmware to web applications and everything in between.
  • Identity and Access Management – The predictable workflow management of identities, roles, and entitlements for all users that have access to the resources of the system.
  • Privileged Access Management – The management of all privileged access into the Blockchain environment – from operating system to web applications, including password management, least privilege access, session management, keystroke logging, and application to application key and password management.

Theoretically, if the EOS Platform followed these cybersecurity basics correctly, even for an open source project and deployed solution, the file upload vulnerability may have been identified (I say “may” because there is always a chance commercial and open source tools could have missed it too). My point is that no system is perfect. All technologies – regardless of the hype, especially when they are new – need extra scrutiny before deployment. Blockchain technology is no different.

For more information on how BeyondTrust can help with cybersecurity basics, contact us today.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Don’t Be A Target: Protect and Secure Privileged Accounts with Bomgar
    Jun 29, 2017 Don’t Be A Target: Protect and Secure Privileged Accounts with Bomgar
    Blog
    1m
  • Multicloud Security & Permissions Management: Practical Tips
    Nov 22, 2021 Multicloud Security & Permissions Management: Practical Tips
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.