Ethereum upgrade delayed over security vulnerability

Ethereum's big "Constantinople" upgrade has been delayed at the last minute.
By Stan Schroeder  on 
Ethereum upgrade delayed over security vulnerability
We're going to have to wait a little longer for Constantinople. Credit: GEOFFROY VAN DER HASSELT/AFP/Getty Images

Ethereum's Constantinople upgrade, which was supposed to kick in on Thursday, Jan 16, is getting delayed.

According to the official Ethereum blog, the delay is due to a potential security vulnerability identified by security audit company ChainSecurity on Jan. 15.

The security bug could potentially make some smart contracts on Ethereum vulnerable to a so-called "re-entrancy attack," enabling an attacker to steal other people's ether.

The bug is explained in detail in a blog post by ChainSecurity. The important bit is that, since Constantinople was delayed, no smart contracts are vulnerable at this point. In fact, a scan of Ethereum's blockchain by ChainSecurity did not find any contracts that would be vulnerable even if the upgrade went through, but Ethereum's developers still decided to mitigate the risk by delaying the upgrade.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

"Because the risk is non-zero and the amount of time required to determine the risk with confidence is longer the amount of time available before the planned Constantinople upgrade, a decision was reached to postpone the fork out of an abundance of caution," Ethereum developer Hudson Jameson wrote in a blog post Tuesday.

For most end-users -- i.e. owners of ether or users of dApps on the platform -- there is no need to do anything following this news. Users who run nodes or mining operations should follow the instructions here.

Constantinople was an important upgrade of Ethereum which was supposed to make the network a bit more efficient and pave the way for future upgrades, most importantly switching to a proof-of-stake consensus algorithm later this year. There's no new date set for the Constantinople upgrade at this point.

This is not the first time Constantinople has been delayed. The upgrade was originally scheduled to go live in November 2018, but was postponed due to bugs.

Disclosure: The author of this text owns, or has recently owned, a number of cryptocurrencies, including BTC and ETH.

Stan Schroeder
Stan Schroeder
Senior Editor

Stan is a Senior Editor at Mashable, where he has worked since 2007. He's got more battery-powered gadgets and band t-shirts than you. He writes about the next groundbreaking thing. Typically, this is a phone, a coin, or a car. His ultimate goal is to know something about everything.


Recommended For You
How to watch Borussia Dortmund vs. Real Madrid online for free
Players of Real Madrid celebrate

How to watch United States vs. Canada online for free
Detailed view of the match day stumps



How to cancel Peacock
In this photo illustration a Peacock logo of an US video streaming service is seen on a smartphone.

Trending on Mashable
In case you missed it: Bank info-stealing malware found in 90+ Android apps with 5.5M installs
unauthorized credit card alert on an android screen

NYT Connections today: See hints and answers for June 1
A phone displaying the New York Times game 'Connections.'

'Wordle' today: Here's the answer hints for June 1
a phone displaying Wordle

NYT Connections today: See hints and answers for May 31
A phone displaying the New York Times game 'Connections.'

Ticketmaster hacked. Breach affects more than half a billion users.
Ticketmaster website
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!