以太坊客户端一个月前的漏洞被归咎于Prysm服务中断

cointelegraphОпубликовано 2025-12-15Обновлено 2025-12-15

Введение

12月4日,以太坊Prysm客户端因一个存在一个月的漏洞导致节点验证问题。该漏洞在Fusaka升级前的测试网中已存在但未被触发。问题表现为节点处理不同步认证时出现资源耗尽,导致重新计算历史状态转换,性能严重下降。网络出现42个epoch期间缺失18.5%的区块,参与率降至75%,验证者损失约382 ETH奖励。 开发者发布临时解决方案并更新补丁。事件显示客户端多样性避免了更严重问题——若主导客户端Lighthouse(当时占56%)出现类似漏洞,可能导致网络暂时失去最终性。目前Lighthouse占比降至52.6%,仍接近三分之二风险线。以太坊开发者正推动进一步分散客户端以提升网络韧性。

Prysm透露,在Fusaka升级前一个月测试网中引入的一个漏洞,是导致本月早些时候其客户端出现以太坊节点验证问题的原因。

以太坊开发者Terence Tsao周日发布了一份事故报告,详细说明了12月4日影响网络的Fusaka主网Prysm事件。

报告称,Prysm节点在处理不同步节点的认证时经历了“资源耗尽”。这导致Prysm重放过去的纪元区块并重新计算昂贵的状态转换,由于工作量过大,对性能产生了显著影响。

事故报告显示,该漏洞在事件发生前一个月就已存在于测试网中,但未被触发。

“该漏洞是在Prysm PR 15965中引入的,并在事件发生前一个月部署到测试网,但未触发。”

测试网旨在识别漏洞,但并非万无一失的方法。

2023年5月——上海硬分叉一个月后——以太坊开发者曾陷入恐慌,当时网络暂时失去交易最终性约25分钟,随后第二天又持续了一个多小时,之后区块链自行恢复。

Prysm已打补丁

Prysm没有使用当前的头部状态,而是从头重新生成先前的状态,造成了巨大的计算负担。

报告称,在超过42个纪元期间,网络出现了18.5%的区块缺失率,参与度降至75%,而验证者损失了约382枚以太币(ETH)的认证奖励。

相关:Vitalik Buterin表示以太坊可以处理暂时性最终性丢失

节点运营商被指示部署临时解决方案,同时开发人员为Prysm客户端开发更新补丁。

客户端多样性挽救了局面

开发者表示,如果事件影响到以太坊主导的共识客户端Lighthouse,情况可能会更糟。

根据ClientDiversity的数据,Offchain Labs的Prysm是以太坊第二大客户端,占有17.6%的份额。

“客户端多样性防止了对以太坊用户产生明显影响。如果某个客户端占据网络超过三分之一份额,将导致暂时性最终性丢失和更多区块缺失。”

然而,该事件凸显出Lighthouse危险地接近三分之二阈值,在这个阈值下,单个客户端漏洞可能最终化无效链。

Lighthouse目前的客户端份额为52.6%,低于事件发生时的约56%。

以太坊开发者正在推动更多的客户端多样性。来源:ClientDiversity


杂志:大问题:比特币能否在10年停电中存活?

Связанные с этим вопросы

QPrysm客户端出现的问题是由什么原因引起的?

APrysm客户端出现的问题是由于一个在测试网中已存在一个月的bug引起的。该bug在PR 15965中被引入,并在事件发生前一个月部署到测试网,但当时未被触发。

Q这个bug对以太坊网络造成了哪些具体影响?

A该bug导致Prysm节点在处理不同步节点的认证时出现资源耗尽,需要重放过去的epoch区块并重新计算昂贵的状态转换,造成性能显著影响。网络在超过42个epoch期间出现18.5%的错过区块率,参与率降至75%,验证者损失了约382 ETH的认证奖励。

Q开发者是如何解决这个问题的?

A开发者为节点运营商提供了临时解决方案,同时为Prysm客户端开发了补丁程序进行更新修复。

Q为什么这次事件没有对以太坊用户造成更严重的影响?

A客户端多样性避免了更严重的影响。由于Prysm仅占17.6%的网络份额,如果是一个拥有超过1/3网络份额的客户端出现此类bug,将会导致临时最终性丢失和更多错过区块。

Q当前以太坊客户端分布情况如何?主要存在什么风险?

A根据ClientDiversity数据,Lighthouse是目前最大的共识客户端,占52.6%的份额(事件发生时约为56%)。风险在于Lighthouse接近三分之二的阈值,如果单个客户端出现bug,可能最终化无效链。

Похожее

South Korea’s KB Financial Completes Stablecoin Pilot As Lawmakers Press For Regulatory Framework

South Korea's KB Financial Group has completed a Proof-of-Concept (PoC) for a won-denominated stablecoin in partnership with several companies. The pilot integrated the entire financial process—from stablecoin issuance to offline payments, merchant settlements, and international remittances—into a single blockchain-based workflow. A key test involved offline payments at a coffee shop via QR code without requiring a digital wallet. For international transfers, the model converted the won stablecoin to a dollar stablecoin, completing the process within three minutes and reducing fees by approximately 87% compared to traditional methods. KB aims to launch services once digital asset regulations are established. However, South Korea's Digital Asset Act, which would establish rules for such stablecoins, faces significant delays due to a disagreement between the Financial Services Commission (FSC) and the Bank of Korea (BOK). The central bank advocates for a consortium of banks to hold a majority stake in any issuer, while the FSC worries this could stifle innovation and tech firm participation. Lawmakers and experts have urged the National Assembly to prioritize the legislation, warning that South Korea is falling behind in the global digital asset market despite accounting for 10% of global transactions. Bank of Korea Deputy Governor Chang Cheong-soo acknowledged the potential of won-pegged stablecoins as a competitive future payment method.

bitcoinist15 мин. назад

South Korea’s KB Financial Completes Stablecoin Pilot As Lawmakers Press For Regulatory Framework

bitcoinist15 мин. назад

The Bond Market Deals a Blow to the AI Bull Market

The article "Bond Market Deals a Blow to the AI Bull Market" discusses how a recent global bond sell-off is threatening to end the AI-driven stock market rally that had been ongoing for about a month and a half. A sharp sell-off in global equity markets began last Friday, with significant declines in indices like South Korea's KOSPI and Japan's Nikkei 225. The primary suspect, according to Morgan Stanley, is the bond market. Key long-term bond yields, such as the U.S. 30-year Treasury and Japan's 10-year government bond, have surged to multi-decade highs. This breach of critical yield levels (like 5% for the 30-year U.S. Treasury) is seen as a dangerous signal that historically precedes risk asset corrections. The root cause is identified as resurgent inflation, fueled by rising oil prices due to renewed Middle East geopolitical tensions, specifically the breakdown of U.S.-Iran talks and the blockade of the Strait of Hormuz. This has led markets to drastically revise expectations for U.S. Federal Reserve policy, now pricing in a significant chance of future rate hikes instead of cuts. Higher bond yields negatively impact stocks, especially high-growth tech/AI stocks, through two main channels: 1. **Valuation Pressure:** Higher yields increase the discount rate used to value future earnings, making the present value of distant AI-related cash flows less attractive. 2. **Relative Attraction:** Safer government bonds offering ~5% yields reduce the appeal of riskier equity investments in emerging markets and tech sectors. Despite the pressure from bonds, the AI bull market has fundamental support from strong sector earnings (e.g., semiconductor companies). The current situation is described as a "tug-of-war" between bond market turbulence and AI prosperity. However, warnings exist that AI stock valuations have become excessive. For investors, the advice is to increase portfolio flexibility. Suggestions include focusing on specific AI supply chain segments (domestic computing, semiconductors, equipment) and being prepared for continued volatility. The article concludes by noting the market is at a precarious point, caught between geopolitical uncertainty and the AI revolution, requiring careful navigation.

marsbit21 мин. назад

The Bond Market Deals a Blow to the AI Bull Market

marsbit21 мин. назад

Circle: From Issuance to Infrastructure

Title: Circle: From Issuance to Infrastructure Circle, the issuer of the USDC stablecoin, is undergoing a strategic transformation to reduce its dependence on interest income from reserve holdings, which is declining due to falling interest rates. Historically, Circle's revenue came primarily from the yield on US Treasury reserves backing USDC. However, it also paid significant fees (approximately 60 cents of every dollar earned) to partners like Coinbase for distributing and settling USDC. To capture more value across the financial stack, Circle is vertically integrating into three new layers: 1. **Settlement Layer:** It is launching **Arc**, a native Layer-1 blockchain. Arc, which uses USDC as its gas token, aims to capture transaction fees currently paid to other blockchains (like Ethereum and Solana) and offers features like privacy for institutional payments. 2. **Distribution Layer:** The **Circle Payments Network (CPN)** connects financial institutions directly to Circle, reducing reliance on exchanges like Coinbase. While not yet monetized, CPN growth has improved Circle's margins. 3. **Application Layer:** Circle is building an **AI Agent Economy** infrastructure with products like Agent Wallets and Nanopayments. The goal is to capture fees from high-volume, automated transactions executed by AI agents, a market where USDC already dominates. These moves represent Circle's shift from a single-product company (USDC issuance) to a full-stack financial platform. The strategy faces challenges, including market competition from players like Stripe and Tether, and potential internal tension regarding how value created by the new Arc blockchain and token (ARC) will accrue to Circle's public shareholders (CRCL). Circle's long-term success depends on its ability to successfully execute this vertical integration and diversify its revenue streams away from interest income.

marsbit49 мин. назад

Circle: From Issuance to Infrastructure

marsbit49 мин. назад

Circle: From Issuance to Infrastructure

Title: Circle: From Issuance to Infrastructure Circle, the issuer of the USDC stablecoin, is undergoing a strategic transformation from a single-product company dependent on reserve interest income to a vertically integrated, full-stack financial platform. Its primary revenue source, earnings from US Treasury reserves backing USDC, is under pressure from declining Federal Reserve interest rates. Furthermore, Circle pays out a significant portion (~60 cents per dollar earned) to partners like Coinbase for distribution and settlement, leading to value leakage. To address these challenges and capture more value across the payment stack, Circle announced three key initiatives in Q1 2026: 1. **Settlement Layer**: Launching its own Layer-1 blockchain, **Arc**. Designed for institutional use with configurable privacy and quantum-resistant architecture, Arc uses USDC as its native gas token, allowing Circle to capture transaction fees currently paid to other blockchains like Ethereum. 2. **Distribution Layer**: Expanding the **Circle Payments Network (CPN)**, which connects financial institutions directly to Circle, reducing reliance on third-party exchanges for USDC distribution and on/off-ramps. 3. **Application Layer**: Building infrastructure for an **AI agent economy**, including tools for agent wallets, nanopayments, and a marketplace. Circle aims to monetize the high volume of AI-driven microtransactions predominantly settled in USDC. This vertical integration strategy aims to diversify Circle's revenue away from volatile interest income. However, a key challenge remains: aligning the value capture of the new ARC token with the interests of existing public market shareholders (CRCL) who invested primarily for reserve yields. The success of this stack-wide expansion hinges on Arc's adoption and Circle's ability to balance value distribution between its core corporate entity and its new blockchain ecosystem.

链捕手55 мин. назад

Circle: From Issuance to Infrastructure

链捕手55 мин. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Manyu: восходящая мем-звезда на Ethereum, готовая открыть новую эру культуры Shiba

Manyu - это мемтокен на Ethereum, который приносит децентрализованную культурную и развлекательную ценность через вирусное влияние в соцсетях и вовлечённость сообщества.

1.9k просмотров всегоОпубликовано 2025.11.27Обновлено 2025.11.27

Manyu: восходящая мем-звезда на Ethereum, готовая открыть новую эру культуры Shiba

Неделя обучения по популярным токенам 14: Glamsterdam — самое ожидаемое обновление Ethereum в 2026 году

Ordinals/Runes по-прежнему стимулируют доходы от комиссий за блоки и активность разработчиков, рассматриваются как отправная точка «нативной эмиссии активов» в сети.

1.3k просмотров всегоОпубликовано 2026.04.29Обновлено 2026.04.29

Неделя обучения по популярным токенам 14: Glamsterdam — самое ожидаемое обновление Ethereum в 2026 году

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на ETH (ETH) представлены ниже.

活动图片