Erigon v3.6.1 Fixes Security Flaws and Data Risks
Erigon v3.6.1 is a recommended bugfix and security release for all users. The Erigon upgrade is a drop-in replacement for v3.6.0 and does not require a blockchain re-sync.
The release fixes a downloader regression that could silently replace a valid local snapshot, allowing the corrected file to remain available for seeding. It also closes a peer-ban bypass that enabled banned Caplin peers to reconnect through inbound connections. One Gnosis archive node recorded 13,827 failed handshakes from 1,638 banned peers in 90 minutes.
Additional fixes address recsplit index corruption after salt-collision retries, a data race during concurrent commits, inaccurate pending-transaction reporting, and incorrect 500 responses from syncing beacon nodes. Erigon also now publishes the correct PeerDAS custody-group count and requires a proven network bond before accepting PING endpoint statements.
For security, Erigon v3.6.1 upgrades google.golang.org/grpc to v1.83.2. The update addresses two high-severity CVEs involving potential HTTP/2 memory exhaustion and an xDS server panic, although the xDS issue is not reachable through Erigon’s current configuration. Data-column retention is now derived from chain configuration. Mainnet retention increases to 131,104 slots, while Gnosis and Chiado decrease to 65,552.
Neutral
The market impact is likely neutral because Erigon v3.6.1 is infrastructure software rather than a token-related catalyst. The release improves node security, snapshot integrity, peer management and indexing reliability, which can reduce operational risks for validators, archive nodes and infrastructure providers over the long term.
In the short term, traders are unlikely to receive a direct bullish or bearish signal. The upgrade requires no re-sync, limiting disruption to node operators and reducing the risk of temporary service interruptions. The fixes could marginally improve confidence in Erigon-based infrastructure, particularly on Gnosis, but this is unlikely to produce a measurable change in GNO or broader crypto prices by itself.
Historically, client security patches and consensus-infrastructure upgrades tend to have limited immediate price effects unless they address an active exploit, cause widespread downtime or coincide with a major network upgrade. Traders should monitor follow-up reports, validator participation, node outages and unusual GNO market volume. A confirmed exploitation of the patched vulnerabilities could become bearish, while broad adoption and improved network reliability would be a modest long-term positive, but neither outcome is established by this release alone.