📈 Get daily crypto insights that make you smarter about your money

Ethereum Classic Miners Fled a Rogue Software Update Within Hours — Why No One Lost a Single Coin

Ethereum Classic node operators are being urged to shun a “rogue” software release after several mining pool nodes briefly adopted it — and then scrambled back — in an incident that exposed how thin the safeguards around the network’s code really are. No funds were lost and no transactions were affected, but the episode is a wake-up call for anyone holding ETC or mining it.

By Carlos Martinez | September 17, 2026

The Hook: A 96-Commit Sprint and a ‘Security Update’ Nobody Reviewed

In a Sept. 16 incident report, the Classix team laid out an unusual sequence of events. A repository called ethereumclassic/core-geth — a fork of the long-maintained etclabscore/core-geth repository, itself maintained since 2020 — released version 1.13.0 on Sept. 14 and labeled it stable at 15:06 UTC. The next morning, an account promoting itself as an Ethereum Classic network voice urged node operators to migrate, calling it a security update. Similar messaging appeared on CoinMarketCap, and mining pools received emails from an ethereumclassic.com address, according to the report.

The problem, per Classix: the release was never reviewed by the existing Core Geth maintainers, who described it as a rogue version. The pace of development itself was a red flag:

  • 96 commits in 56 hours — pushed directly to the fork’s main branch with no pull requests and no outside review.
  • 13,422 lines added, 3,977 lines deleted — a massive change set for two and a half days of work.
  • Seven release candidates in rapid succession before the “stable” label, with the first tagged on Sept. 12.

On-Chain Evidence: Miners Adopted It — Then Reversed

The software actually reached part of Ethereum Classic’s mining infrastructure. Node status data cited by Classix showed four 2Miners nodes running the disputed v1.13.0 at 12:09 UTC on Sept. 15. By 23:35 UTC that same day, all four had returned to Argos v1.12.23 — the current release from the repository that has maintained Core Geth since 2020. Other listed mining pools stayed on versions in the 1.12 series throughout.

Some individual nodes kept running it. Tracking site Etcnodes.org showed 11 nodes on v1.13.0 at 07:33 UTC on Sept. 15, falling to 10 by Sept. 16 — and three of those matched bootnode IP addresses that were hardcoded into the new client itself, the report noted.

The bottom line, according to Classix: no blocks were lost, no chain reorganizations occurred, no funds were affected, and no service interruption was recorded. The report classified the event as high severity but low impact — dangerous software design, fortunately benign outcome.

The Core Conflict: Were the Security Claims Even Real?

The v1.13.0 release told operators that every node running v1.12.x should upgrade, claiming unpatched security issues. Classix reviewed the seven cited issues and pushed back hard:

  • Five of the seven had already been fixed in maintained Core Geth releases between March and August — including CVE-2026-22862 and CVE-2026-26315, addressed in Aegis v1.12.21, with Argos v1.12.23 covering CVE-2026-26313.
  • One (CVE-2026-22868) concerned KZG proof verification, which is tied to blob transactions from Ethereum’s Cancun upgrade — a feature Ethereum Classic has never activated.
  • Another was a GraphQL query issue that requires GraphQL to be enabled manually and does not touch the peer-to-peer or consensus path.

Classix added that Core Geth maintainer Diego López León reviewed the remaining differences and found no exploitable flaw in Argos that v1.13.0 actually corrected. Beyond the disputed security claims, the release made two structural changes that alarmed maintainers: it reenabled MESS — Modified Exponential Subjective Scoring, a 2020-era chain-reorganization guard that was deliberately disabled at block 19,250,000 through ECIP-1110 — and it replaced the DNS tree signing key maintained since 2020 with hardcoded bootnodes, three of whose domains were hosted through a single Cloudflare account. Operators were never told who controlled the new signing key, the report said.

Market Implications: Why History Makes This Personal for ETC Holders

Ethereum Classic’s history makes any consensus-level tampering a serious matter. The network suffered three majority (51%) attacks in August 2020, including reorganizations involving thousands of blocks. MESS was originally created as protection against exactly that kind of attack — but if only some clients run it while Besu, Nethermind, and Getc do not implement the mechanism, different nodes could disagree about which chain is the real one. That fragmentation risk, not the security patch itself, is what elevated this incident’s severity rating.

For ordinary investors, the lesson is about trust in infrastructure. Most people never think about which software their exchange’s nodes or their favorite mining pool runs — until a disputed update changes how the network picks valid blocks. The incident also revives the recurring call for client diversity: concentrating hash power on a single implementation makes the whole network hostage to that codebase’s integrity.

The Verdict: Dodged Bullet, New Rules

Classix’s recommendations are blunt: avoid v1.13.0, run Argos v1.12.23, restore rotated node keys, check MESS configuration, and consider spreading across Nethermind, Besu, or Getc. It also asked GitHub administrators of the ethereumclassic organization to tighten repository controls — requiring proposals and reviews before new repositories are created, protecting default branches, and clearly identifying maintainers. For ETC holders, the network dodged a bullet this time; the price of that luck is closer attention to who, exactly, is shipping the code that runs the chain.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

9 thoughts on “Ethereum Classic Miners Fled a Rogue Software Update Within Hours — Why No One Lost a Single Coin”

      1. credit where due but hours is generous. the alarm came from community channels, not the pools. they still ran the binary first

  1. a 96 commit release labeled stable in a day and pools actually ran it. ETC security review is a group project nobody showed up to

    1. oldiron_validator

      group project nobody showed up to is right. core-geth had maintainers since 2020, reviewing 96 commits should take days not a label swap to stable

  2. etclabscore kept that repo clean for five years and a lookalike org nearly walked off with the network. signed releases would fix this overnight

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,810.00+1.5%ETH$2,474.38+3.5%SOL$101.57+4.7%BNB$727.33+2.3%XRP$1.31+3.3%ADA$0.2035+6.0%DOGE$0.0821+3.8%DOT$1.03+6.4%AVAX$7.62+5.1%LINK$11.38+6.6%UNI$7.33+21.0%ATOM$1.54+3.2%LTC$53.16+5.6%ARB$0.1632+1.9%NEAR$2.87+16.9%FIL$0.8221+5.1%SUI$0.7320+6.7%BTC$76,810.00+1.5%ETH$2,474.38+3.5%SOL$101.57+4.7%BNB$727.33+2.3%XRP$1.31+3.3%ADA$0.2035+6.0%DOGE$0.0821+3.8%DOT$1.03+6.4%AVAX$7.62+5.1%LINK$11.38+6.6%UNI$7.33+21.0%ATOM$1.54+3.2%LTC$53.16+5.6%ARB$0.1632+1.9%NEAR$2.87+16.9%FIL$0.8221+5.1%SUI$0.7320+6.7%
Scroll to Top