AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 37 Cryptographic libraries

rpc: remove pay-to-use RPC on node side

Public commit record

What the developer wrote

Authored by jeffro256

60/100 · Adequate
rpc: remove pay-to-use RPC on node side

Co-authored-by: tobtoht <tob@featherwallet.org>
Co-authored-by: SNeedlewoods <sneedlewoods_1@protonmail.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
The short version

What changed, and why it matters

This commit removes the entire 'pay-to-use RPC' feature from the Monero node software. Previously, node operators could optionally require remote users to do small proof-of-work payments (or mining shares) before serving RPC requests. The patch deletes the payment logic, command-line options, RPC commands, tests, and shell completions. It is a feature-removal cleanup, not a fix for an active vulnerability, and it makes RPC access free again on nodes that had not separately restricted it.

Recommended action

Operators who previously relied on RPC payments for rate-limiting or anti-DoS protection must now enforce access control through other means, such as firewall rules, RPC login (--rpc-login), restricted RPC (--restricted-rpc), binding to loopback, or a reverse proxy. Review any public nodes for unintended open RPC access after upgrading. No immediate patch is required because this is an intentional feature removal, but monitor release notes for the rationale and any follow-up hardening.

Security signals we found

01

Removal of optional RPC payment subsystem

02

Deletion of proof-of-work share validation for RPC access

03

Deletion of client credit balance tracking and serialization

04

Removal of RPC endpoints used to submit mining nonces and pay for access

05

Change makes RPC access free by default on nodes that relied on payment gating

Risk score

Why this scored 37/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 5/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.