The new release, which includes updates for both the dcrd full-node software and the dcrwallet, was prompted by security concerns regarding how the network validates transactions and handles mixing sessions. By updating the mixclient protocol, developers have closed a loophole that could have allowed for the deanonymization of participants using the project’s CoinShuffle++ privacy feature. The update further refines blame assignment during mixing, ensuring that peers who trigger errors are correctly identified and excluded from sessions.
In section Cryptocurrency
Decred issues mandatory v2.1.6 patch to resolve critical security flaws
Decred has released a mandatory software update, v2.1.6, to address a critical consensus vulnerability and potential deanonymization risks within its transaction mixing system. The patch also implements essential network-level security measures to prevent denial-of-service attacks, forcing users to upgrade immediately to remain on the main network chain.

Beyond privacy enhancements, the v2.1.6 patch mitigates several network-related denial-of-service routes and strengthens Simplified Payment Verification (SPV) security. The updated wallet now mandates strict signature verification for spent outputs and includes missing Merkle-root validation for blocks processed in SPV mode. Because these changes alter core consensus rules, nodes running older software risk being forked from the network. Developers Dave Collins, Jamie Holdstock, and Josh Rickmar contributed to the release, which encompasses 23 commits and significant codebase adjustments. While the project has not confirmed any active exploitation of these vulnerabilities, it has urged all stakeholders, miners, and exchange infrastructure providers to migrate to the patched version as a precaution.
Comments (0)
No comments yet. Be the first!