S4E just found a high top 10 tcp port service scan
high·Misconfiguration·Updated Apr 7, 2026

Blockchain RPC Exposure Detection Scanner

This scanner detects the use of Blockchain RPC exposure in digital assets. The vulnerability relates to exposing the txpool_content method, enabling potential exploitations such as frontrunning attacks and MEV extraction.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Blockchain RPC exposure primarily affects decentralized applications and platforms utilizing blockchain technology for processing transactions. These applications are widely utilized by developers and businesses to facilitate transactions and interactions on the blockchain. The vulnerability impacts the txpool_content method, which returns all pending transactions, thus exposing sensitive information to unauthorized entities.

The vulnerability allows malicious actors to exploit exposed methods such as txpool_content for nefarious activities. These activities include frontrunning attacks, in which attackers execute trades immediately before another transaction after observing it in the mempool, and sandwich attacks, where buy and sell orders are placed around a victim's trade. Such actions can be used to exploit Maximal Extractable Value (MEV), which significantly affects the fair distribution of resources in blockchain networks.

Technical details reveal that the vulnerability involves the txpool_content method in blockchain RPC endpoints, which outputs all pending transactions, sender addresses, transaction data, gas prices, and values. This exposure occurs at JSON-RPC endpoints that haven't disabled txpool features, which are often unintendedly left open in misconfigured systems. The method's accessibility allows extraction of pending transactions from the mempool, thus providing real-time data about impending transaction executions.

Exploitation of this vulnerability leads to immediate effects such as financial losses due to manipulated transactions performed faster than the victim's original transaction. Other potential impacts include market manipulation through MEV exploitation, degrading user trust in blockchain networks, and enabling pervasive surveillance of user activity in the DeFi space. The exposure detrimentally influences the integrity and security ethos of blockchain platforms.

REFERENCES

Solution Advice
  • Disable the txpool_content, txpool_status, and txpool_inspect methods on public RPC endpoints.
  • Restrict access to these features to only internal validator or sequencer nodes.
  • If necessary for specific tooling, consider exposing these methods via separate authenticated endpoints.
  • Regularly audit and update configurations of RPC endpoints to prevent unauthorized access.
  • Implement rigorous network security measures to protect against external threats targeting blockchain infrastructures.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.