Friday, March 24, 2023
  • Login
  • Register
btclive365.com
  • Home
  • Cryptocurrency News Today
  • Bitcoin (BTC)
  • Altcoins
  • Blockchain
  • Crypto Mining
  • CryptoCurrency Predictions
  • Defi
  • Dogecoins
  • Earn Crypto
  • Ethereum (ETH)
  • Forex Trading
  • ICO
  • Litecoin ( LTC )
  • NFT
  • Ripple
  • Trend cryptocurrency
No Result
View All Result
  • Home
  • Cryptocurrency News Today
  • Bitcoin (BTC)
  • Altcoins
  • Blockchain
  • Crypto Mining
  • CryptoCurrency Predictions
  • Defi
  • Dogecoins
  • Earn Crypto
  • Ethereum (ETH)
  • Forex Trading
  • ICO
  • Litecoin ( LTC )
  • NFT
  • Ripple
  • Trend cryptocurrency
No Result
View All Result
btclive365.com
No Result
View All Result
Home CryptoCurrency Predictions

Fireblocks Saves Crypto Wallet Bitgo from Potential Exploit as It Patches Critical Vulnerability

btclive365 by btclive365
March 17, 2023
in CryptoCurrency Predictions
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


As the cryptocurrency industry continues to grow and evolve, so do the potential risks and vulnerabilities. In order to stay ahead of the curve, many crypto firms are taking proactive steps to avoid exploits on their platforms. From implementing robust security measures to conducting regular audits, these firms are committed to ensuring the safety and security of their users. Recently, BitGo, a popular cryptocurrency wallet, has recently fixed a crucial vulnerability that could have potentially exposed the private keys of both retail and institutional users.

Fireblocks Becomes a Messiah for Bitgo

In December 2022, the cryptography research team at Fireblocks discovered a significant vulnerability in BitGo’s Threshold Signature Scheme (TSS) wallets. This flaw had the potential to expose the private keys of exchanges, banks, businesses, and platform users, and Fireblocks named it the BitGo Zero Proof Vulnerability.

The vulnerability was found to be particularly alarming as attackers could extract a private key in under a minute using just a small amount of JavaScript code. As a result, BitGo took swift action and suspended the vulnerable service on December 10, 2022. A patch was released in February 2023, and BitGo required client-side updates to the latest version by March 17 to address the issue.

The Fireblocks team revealed how it discovered the exploit by using a free BitGo account on the mainnet. By identifying a missing component of mandatory zero-knowledge proofs in BitGo’s ECDSA TSS wallet protocol, the team was able to expose the private key through a straightforward attack.

To mitigate the possibility of a single point of attack, industry-standard enterprise-grade cryptocurrency asset platforms utilize either multi-party-computation (MPC/TSS) or multi-signature technology. This involves distributing a private key among multiple parties to ensure security controls in case one party is compromised. This approach minimizes the risks associated with holding cryptocurrency assets and helps to avoid potential exploits.

Crypto Market Could Have Witnessed Another Exploit 

Fireblocks demonstrated that both internal and external attackers could obtain full access to a private key through two methods.

First, a compromised client-side user could initiate a transaction to obtain a portion of the private key held in BitGo’s system. BitGo would then perform the signing computation and share information that leaks the BitGo key shard, potentially exposing the entire private key. The team said:

“The attacker can now reconstruct the full private key, load it in an external wallet and withdraw the funds immediately or at a later stage.”

The second scenario explores the possibility of an attack in case BitGo is compromised. In this scenario, the attacker would lie in wait for a customer to initiate a transaction and respond with a malicious value. This value would be used to sign the transaction using the customer’s key shard. By exploiting the response, the attacker would expose the user’s key shard and combine it with BitGo’s key shard to gain control of the wallet.

Fireblocks advises users to create new wallets and transfer funds from ECDSA TSS BitGo wallets before the patch, even though no attacks have been executed through this method.





Source link

Previous Post

CRO Price Prediction for 2040 and 2050: How High Can It Go?

Next Post

9 data science project ideas for beginners

btclive365

btclive365

Next Post

9 data science project ideas for beginners

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected test

  • 23.8k Followers
  • 99 Subscribers
  • Trending
  • Comments
  • Latest

How to sell Bitcoin – Bitcoin Magazine

November 9, 2022

Add a Tangible Asset to Your Portfolio: Buy Gold

January 7, 2023

Building Bitcoin Standard In Portugal – Bitcoin Magazine

November 9, 2022

USD/ZAR Rallies as SA President Ramaphosa Faces Potential Impeachment

December 1, 2022

Bitcoin price hits 2-week lows as FTX ‘bank run’ drains BTC reserves

1

Building Homesteader Lifestyle With Bitcoin – Bitcoin Magazine

1

Arbitrum dealings activity rockets 550% since August: Delphi Digital

0

Bitcoin․com Doubles Down on Self-Custody With Launch of Verse DEX – Press release Bitcoin News

0

US enforcement agencies are turning up the heat on crypto-related crime – Cointelegraph Magazine

March 24, 2023

NZD/USD eyes a recovery near 0.6250 as Fed’s tightening cycle looks set to terminate

March 23, 2023

Terraform Labs co-founder Do Kwon reportedly arrested in Montenegro

March 23, 2023

Top Crypto Gainers February 2023: Toncoin (TON), NEAR Protocol (NEAR) and Collateral Network (COLT)

March 23, 2023

Recent News

US enforcement agencies are turning up the heat on crypto-related crime – Cointelegraph Magazine

March 24, 2023

NZD/USD eyes a recovery near 0.6250 as Fed’s tightening cycle looks set to terminate

March 23, 2023

Terraform Labs co-founder Do Kwon reportedly arrested in Montenegro

March 23, 2023

Top Crypto Gainers February 2023: Toncoin (TON), NEAR Protocol (NEAR) and Collateral Network (COLT)

March 23, 2023

We deliver up-to-date, breaking crypto news about the latest Bitcoin, Ethereum, Blockchain, NFTs, and Altcoin trends and happenings

Follow Us

Browse by Category

  • Altcoins
  • Bitcoin (BTC)
  • Blockchain
  • Crypto Mining
  • Cryptocurrency News Today
  • CryptoCurrency Predictions
  • Defi
  • Dogecoins
  • Earn Crypto
  • Ethereum (ETH)
  • Forex Trading
  • ICO
  • Litecoin ( LTC )
  • NFT
  • Ripple
  • Trend cryptocurrency

Recent News

US enforcement agencies are turning up the heat on crypto-related crime – Cointelegraph Magazine

March 24, 2023

NZD/USD eyes a recovery near 0.6250 as Fed’s tightening cycle looks set to terminate

March 23, 2023
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2022 btclive365 All Right Rivered .

No Result
View All Result
  • Home
  • Cryptocurrency News Today
  • Bitcoin (BTC)
  • Altcoins
  • Blockchain
  • Crypto Mining
  • CryptoCurrency Predictions
  • Defi
  • Dogecoins
  • Earn Crypto
  • Ethereum (ETH)
  • Forex Trading
  • ICO
  • Litecoin ( LTC )
  • NFT
  • Ripple
  • Trend cryptocurrency

© 2022 btclive365 All Right Rivered .

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In