Intro
As many of you may have heard recently, there was recently a new vulnerability discovered and exploited. A user named supercomputer was able to fill up the miner queue all by there self. You can see evidence of this from here https://steemit.com/steem/@lantto/supercomputing-s-perfect-streak
Explanation
How did supercomputer do this? He was able to shortcut the requirements for mining steem. Namely, he skipped the hashing part and instead opted to user the power of a black magic called ECDSA. Soon the user @arhag will disclose exactly how the hack works, but I can give you a brief summary. The hacker was able to submit blocks without finding the appropriate
nonce by taking a previously mined block and changing the block-id of the work with-in the block, and changing his private key to be able to sign the newly created slightly modified POW and get the same signature of the previously mined POW. This results in very very quick and unfair mining. If you're interested in getting a little more in depth look at the bad code by looking here.
Fortunately the steem team has been hard at work to fix this and they have recently announced a new hard fork schedule. Starting on Mon, 15 Aug 2016 14:00:00 GMT, the supercomputer style of attack can no longer be exploited. You can find that release here.
https://github.com/steemit/steem/releases
Final Notes
In addition to fixing the POW bug, this hard fork will now be enforcing a voting rule. In order to vote you now need to have a minimum steem power. Thanks for reading
- Picokernel