Decred patches critical flaw that could enable mixing deanonymization attack

Decred has released a mandatory software patch v2.1.6 to fix a critical consensus vulnerability, a potential periodic mixing deanonymization attack, and several network denial-of-service risks. Summary Decred has released mandatory v2.1.6 to fix a critical consensus security vulnerability. The patch prevents a potential periodic deanonymization attack involving Decred’s transaction mixing system. Several potential network denial of service attack routes and SPV validation issues have also been addressed. Users running older versions have been urged to upgrade to avoid operating on a different network fork. Decred said in an Aug. 19 post on X that users should upgrade to the new release as soon as possible because the patch contains security changes affecting consensus, transaction mixing, and network operations. The project also said the update improves how mixing sessions expire. A mandatory patch release for Decred is now available with the following changes: – Critical consensus-related security fix – Prevents a potential periodic deanonymization mixing attack – Several fixes for potential network-related denial-of-service (DoS) attacks – Improved… — Decred (DCR) (@decredproject) August 19, 2026 The release is mandatory because nodes remaining on older software risk being forked from the network. Decred’s release notes said the requirement is especially important for individual stakeholders, Voting Service Providers, proof-of-work miners, and cryptocurrency exchanges running network infrastructure. Decred v2.1.6 requires all users to upgrade Under the v2.1.6 release notes, Decred classified the consensus issue as a “critical” security vulnerability and warned that users who fail to update could end up operating on a different network fork. The patch applies to dcrd, Decred’s full-node software, while associated changes have also been released for dcrwallet. The software package contains 23 commits from three contributors, covering 20 files. According to the GitHub release, developers added 795 lines of code and removed 392 lines as part of the patch. Dave Collins, Jamie Holdstock and Josh Rickmar contributed to the dcrd release. You might also like: BitBox patches wallet flaws that could install malicious firmware Alongside the consensus fix, developers addressed several possible network-related denial-of-service attacks. Decred has not disclosed technical details that would provide a step-by-step route for exploiting the consensus vulnerability, while its release notice stresses the need for users across the network to move onto the patched version. At the time of Decred’s X announcement, the Windows build of Decrediton had not yet been made available, with the project saying it expected the release within the following day. The current v2.1.6 GitHub page now lists a Windows version of Decrediton alongside Linux and macOS packages. Users downloading the software can also verify the release files against SHA-256 hashes and associated signature files provided with the package, according to Decred’s installation instructions.
عنوان اصلی (انگلیسی): Decred patches critical flaw that could enable mixing deanonymization attack
مشاهدهی خبر کامل در منبع ↗ بازگشت به دیکرداین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.