BTC
$107,498.05
+
0.22%
ETH
$2,436.55
+
0.10%
USDT
$1.0001
-
0.01%
XRP
$2.1867
-
0.05%
BNB
$648.82
+
0.18%
SOL
$151.57
+
0.56%
USDC
$0.9998
+
0.00%
TRX
$0.2757
+
0.67%
DOGE
$0.1644
+
0.48%
ADA
$0.5591
-
0.87%
HYPE
$38.01
+
1.32%
WBT
$46.65
-
1.13%
BCH
$489.88
-
0.23%
SUI
$2.8147
+
1.77%
LINK
$13.37
+
0.43%
LEO
$8.9839
-
0.68%
AVAX
$18.05
+
0.49%
XLM
$0.2362
-
0.71%
TON
$2.8787
+
1.12%
SHIB
$0.0₄1154
-
0.01%
Logo
  • News
  • Prices
  • Data
  • Indices
  • Research
  • Events
  • Sponsored
  • Sign In
  • Sign Up
Markets
Share this article
X iconX (Twitter)LinkedInFacebookEmail

'Bash Bug' a Concern, But Little Threat to Bitcoin Services

Yesterday's discovery of the 'Bash Bug' affecting UNIX systems has security experts worried, but bitcoin developers are less concerned.

By Jon Southurst
Updated Sep 11, 2021, 11:12 a.m. Published Sep 26, 2014, 8:34 a.m.
software bug

There were widespread security concerns yesterday after the discovery of an old flaw that could affect web servers and Internet-connected devices – but many in the industry are claiming it presents no immediate threat to bitcoin services.

The vulnerability, dubbed either the 'Bash Bug' or the 'Shellshock Bug', would allow a malicious access to a UNIX-based device's operating system via the command line shell – the most widely used of which is bash.

jwp-player-placeholder
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
By signing up, you will receive emails about CoinDesk products and you agree to our terms of use and privacy policy.

UNIX-based systems include MacOS, Linux versions (desktop and server), popular mobile platforms and embedded systems on other devices that communicate online.

CNET reported that security expert Robert Graham, described it as "as big a deal as Heartbleed" – the OpenSSL flaw discovered in April – given the "enormous percentage of software that interacts with the shell".

'Over-hyped'

Jeff Garzik

, bitcoin core developer and now senior software engineer at BitPay, however, said there is no clear and present danger to bitcoin users.

"Prediction: bash bug NOT bigger threat than heartbleed," he posted on a Reddit thread.

Garzik told CoinDesk that, while the newly-discovered bug had the potential to be bad, "most online services using bitcoin are far more secure than your average home router".

He added that the Bash Bug would impact mostly non-bitcoin sites, and was being over-hyped.

"It requires special set of conditions to be exploitable, and home routers and ancient Apache web servers were already Swiss cheese security anyway. I think the practical impact will be much less than the mainstream media is making it out to be."

Bitcoin a target?

At this stage, there are no reports of any exploit of the Bash Bug affecting any bitcoin-related services. So why care at all?

Bitcoin services may potentially be a more attractive target for hackers and thieves than more established, fiat-based services like online banking and PayPal.

There are two historic reasons for this: poor security implementation at some early-stage online bitcoin services, and the reluctance of authorities to investigate or punish digital currency crimes, unless they suspect drugs or money laundering are involved.

Therefore it is best to at least be aware of potential problems developers and services may face.

One exchange's view

Yan Chuan or 'YC', CTO of exchange BitBays.com, said the bug was "relatively easy for hackers to use", and recommended all users patch, back up logs, and check systems to see if any attack had occurred.

Because the bug allowed malicious hackers full access to an operating system there was potential for any kind of attack, from stealing bitcoin wallets to installing keyloggers and backdoors.

YC said bitcoin itself would not be affected due to its decentralized structure.

"However, as a centralized provider of exchange or wallet services it is possible to be affected by the bash bug. Due to the presence of this vulnerability, open SSH, HTTP, FTP and other application servers are all at risk of being remotely accessed and controlled by a hacker."

Since Windows is not UNIX-based, its desktop users would not be affected themselves. BitBays' platform is prepared, YC continued, but concerned users of other platform might like to ask their exchange or wallet service about the situation if unsure.

Cracked shell

The Bash Bug vulnerability stems from a serious security flaw that exists in the bash (Bourne Again SHell) command 'env'. It affects the local shell, as well as SSH, FTP, HTTP, and other important services.

YC explained how the bug could be exploited, saying that many web servers send the user’s HTTP request information (REMOTE_HOST), REQUEST_METHOD, QUERY-STRING, etc) stored in an environment variable, to the backend Web framework or CGI scripts.

If this information includes malicious instructions, the next time the server executes bash it will execute the malicious instructions. Thus, the server is compromised.

At present, the popular Apache + PHP and Nginx + wsgi frameworks are vulnerable.

No quick fix

According to Red Hat, which issued its own security advisory, many programs access the bash shell in the background. Several Linux distributions have already made patches available, including Red Hat Enterprise Linux, Debian, Ubuntu and CentOS.

The bug, which has actually existed for more than 25 years before the release of today's news, could affect millions of devices and leave much older ones in need of patching. It is the sheer number of devices in need of patching, rather than the flaw's complexity or known exploits, that has some experts concerned.

Bug image via Shutterstock

SecurityJeff GarzikNews
Jon Southurst

Jon Southurst is a business-tech and economic development writer who discovered bitcoin in early 2012. His work has appeared in numerous blogs, UN development appeals, and Canadian & Australian newspapers. Based in Tokyo for a decade, Jon is a regular at bitcoin meetups in Japan and likes to write about any topic that straddles technology and world-altering economics.

Picture of CoinDesk author Jon Southurst
Latest Crypto News
Assets

Price Chip Testing

Jun 27, 2025
Article image

Digital Asset, Builder of Privacy-Focused Blockchain Canton, Raises $135M

Jun 24, 2025
Article image

Bankrupt Crypto Exchange FTX Slams Three Arrows Capital’s $1.51B Claim: “3AC Is Owed Nothing”

Jun 23, 2025
Article image

Ethereum Surges 4% on Massive Volume as Institutional Interest Grows

Jun 23, 2025
FastNews (CoinDesk)

[Test test ] translation without price widget

Jun 20, 2025
FastNews (CoinDesk)

[Test-C31-6047, FastNews] JPMorgan To Allow Clients To Buy Bitcoin, Says Jamie Dimon

Jun 20, 2025
Top Stories
Assets

Price Chip Testing

Jun 27, 2025
JPMorgan Chase CEO Jamie Dimon (Photo by Kevin Dietsch/Getty Images)

JPMorgan To Allow Clients To Buy Bitcoin, Says Jamie Dimon

May 19, 2025
Ethereum co-founder Vitalik Buterin (CoinDesk Archives)

Ethereum's Vitalik Buterin Proposes Design to Make Running Nodes Easier

May 19, 2025
A barman shakes a cocktail shaker with an array of drinks bottles behind him.

Crypto Daybook Americas: Bitcoin Whiplash Shakes Market as U.S. Yield Spike Threatens Bull Run

May 19, 2025
Mike Novogratz, Galaxy founder and CEO, speaks at Consensus 2024 (CoinDesk/Shutterstock/Suzanne Cordiero)

The Bull Case for Galaxy Digital Is AI Data Centers Not Bitcoin Mining, Research Firm Says

May 19, 2025
Tokyo, Japan (Jaison Lin/Unsplash)

Metaplanet Buys Another 1,004 Bitcoin, Lifts Holdings to Over $800M Worth of BTC

May 19, 2025

Only 1 article remaining this month.

Sign up for free

About

  • About Us
  • Masthead
  • Careers
  • CoinDesk News
  • Crypto API Documentation

Contact

  • Contact Us
  • Accessibility
  • Advertise
  • Sitemap
  • System Status
DISCLOSURE & POLICES
CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.
EthicsPrivacyTerms of UseCookie SettingsDo Not Sell My Info

© 2025 CoinDesk, Inc.
X icon
Sign Up
  • News
    Back to menu
    News
    • Markets
    • Finance
    • Tech
    • Policy
    • Focus
  • Prices
    Back to menu
    Prices
    • Data
      Back to menu
      Data
      • Trade Data
      • Derivatives
      • Order Book Data
      • On-Chain Data
      • API
      • Research & Insights
      • Data Catalogue
      • AI & Machine Learning
    • Indices
      Back to menu
      Indices
      • Multi-Asset Indices
      • Reference Rates
      • Strategies and Services
      • API
      • Insights & Announcements
      • Documentation & Governance
    • Research
      Back to menu
      Research
      • Events
        Back to menu
        Events
        • CoinDesk: Policy & Regulation
        • Consensus Hong Kong
        • Consensus Miami
      • Sponsored
        Back to menu
        Sponsored
        • Thought Leadership
        • Press Releases
        • CoinW
        • MEXC
        • Phemex
        • Advertise
      • Videos
        Back to menu
        Videos
        • CoinDesk Daily
        • Shorts
        • Editor's Picks
      • Podcasts
        Back to menu
        Podcasts
        • CoinDesk Podcast Network
        • Markets Daily
        • Gen C
        • Unchained with Laura Shin
        • The Mining Pod
      • Newsletters
        Back to menu
        Newsletters
        • The Node
        • Crypto Daybook Americas
        • State of Crypto
        • Crypto Long & Short
        • Crypto for Advisors
      • Webinars
        Back to menu
        Webinars
        Select Language
        English enEspañol esFilipino filFrançais frItaliano itPortuguês pt-brРусский ruУкраїнська ukDeutsch deNederlands nl