Monday, March 20, 2023
Bitcoin
Minersgarden
  • Home
  • Cryptos
    • Bitcoin news
    • Ethereum news
    • Bitcoin gold news
    • Bitcoin cash news
  • Blockchain
    • investors
    • Technical
    • Beginners
    • spam
  • Market analyse
    • stock
    • Price
    • Business
  • Scam
  • NFT
  • DEFI
  • ICO
  • Videos
No Result
View All Result
Bitcoin
  • Home
  • Cryptos
    • Bitcoin news
    • Ethereum news
    • Bitcoin gold news
    • Bitcoin cash news
  • Blockchain
    • investors
    • Technical
    • Beginners
    • spam
  • Market analyse
    • stock
    • Price
    • Business
  • Scam
  • NFT
  • DEFI
  • ICO
  • Videos
No Result
View All Result
Bitcoin
No Result
View All Result
Home Blockchain

BitGo patches critical vulnerability first discovered by Fireblocks

by Bitcoin Market
03/18/2023
Reading Time: 2 min
0
BitGo patches critical vulnerability first discovered by Fireblocks

BitGo patches critical vulnerability first discovered by Fireblocks

Share on FacebookShare on TwitterShare on Pinterest

Cryptocurrency wallet BitGo has patched a critical vulnerability that could have exposed the private keys of retail and institutional users.

Cryptography research team Fireblocks identified the flaw and notified the BitGo team in December 2022. The vulnerability was related to BitGo Threshold Signature Scheme (TSS) wallets and had the potential to expose the private keys of exchanges, banks, businesses and users of the platform.

The Fireblocks team named the vulnerability the BitGo Zero Proof Vulnerability, which would allow potential attackers to extract a private key in under a minute using a small amount of JavaScript code. BitGo suspended the vulnerable service on Dec. 10 and released a patch in February 2023 that required client-side updates to the latest version by March 17.

The Fireblocks team outlined how it identified the exploit using a free BitGo account on mainnet. A missing part of mandatory zero-knowledge proofs in BitGo’s ECDSA TSS wallet protocol allowed the team to expose the private key through a simple attack.

Related: Euler Finance hacked for over $195M in a flash loan attack

Industry-standard enterprise-grade cryptocurrency asset platforms make use of either multiparty-computation (MPC/TSS) or multisignature technology to remove the possibility of a single point of attack. This is done by distributing a private key between multiple parties, to ensure security controls if one party is compromised.

Fireblocks was able to prove that internal or external attackers could gain access to a full private key through two possible means.

A compromised client-side user could initiate a transaction to acquire a portion of the private key held in BitGo’s system. BitGo would then perform the signing computation before sharing information that leaks the BitGo key shard.

“The attacker can now reconstruct the full private key, load it in an external wallet and withdraw the funds immediately or at a later stage.”

The second scenario considered an attack if BitGo was compromised. An attacker would wait for a customer to initiate a transaction, before replying with a malicious value. This is then used to sign the transaction with the customer’s key shard. The attacker can use the response to reveal the user’s key shard, before combining that with BitGo’s key shard to take control of the wallet.

Fireblocks noted that no attacks have been carried out by the identified vector but warned users to consider creating new wallets and moving funds from ECDSA TSS BitGo wallets prior to the patch

Hacks of wallets have been commonplace across the cryptocurrency industry in recent years. In August 2022, over $8 million was drained from over 7,000 Solana-based Slope wallets. Algorand network wallet service MyAlgo was also targeted by a wallet hack that saw over $9 million drained from various high-profile wallets.

This article was originally published by: cointelegraph.com Read the original article here

You might also like

Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform

How do blockchain forensics and asset tracking work?

Bitcoin ATM maker shuts cloud service after user hot wallets compromised

Related Posts

Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform
Blockchain

Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform

by Bitcoin Market
03/20/2023
How do blockchain forensics and asset tracking work?
Blockchain

How do blockchain forensics and asset tracking work?

by Bitcoin Market
03/20/2023
Bitcoin ATM maker shuts cloud service after user hot wallets compromised
Blockchain

Bitcoin ATM maker shuts cloud service after user hot wallets compromised

by Bitcoin Market
03/20/2023
Polygon supernets vs. Avalanche subnets: Key differences
Blockchain

Polygon supernets vs. Avalanche subnets: Key differences

by Bitcoin Market
03/19/2023
Shiba Inu community divided over allegations of code, chain ID plagiarism
Blockchain

Shiba Inu community divided over allegations of code, chain ID plagiarism

by Bitcoin Market
03/19/2023
Coinmama

Recommended

DeFiLlama Launches Strategy Finder For Better DeFi Yield Farming

DeFiLlama Launches Strategy Finder For Better DeFi Yield Farming

10/24/2022
paypal scaled

Is It Possible to Buy Bitcoin with PayPal

02/12/2022

Categories

  • Bitcoin news
  • Blockchain
  • Bitcoin cash news
  • Ethereum news
  • Bitcoin gold news
  • Price
  • Scam
  • Videos

Don't miss it

Les Gros Bugs des films TRON et TRON L39Heritage
Videos

Les Gros Bugs des films TRON et TRON L'Héritage !

03/20/2023
Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform
Blockchain

Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform

03/20/2023
Cointelegraph 2023 Top 100 full list now mintable as digital collectibles
NFT

Cointelegraph 2023 Top 100 full list now mintable as digital collectibles

03/20/2023
Bank collapses are spurring interest in self-custody startups
DEFI

Bank collapses are spurring interest in self-custody startups

03/20/2023
Investors shelter in short-term Treasurys, reducing Bitcoin’s chance of rallying to $30K
Bitcoin news

Investors shelter in short-term Treasurys, reducing Bitcoin’s chance of rallying to $30K

03/20/2023
Alameda Research FTX Company is About to Crash Ethereum
Videos

Alameda Research (FTX Company) is About to Crash Ethereum…

03/20/2023

Categories

  • Beginners
  • Bitcoin cash news
  • Bitcoin gold news
  • Bitcoin news
  • Blockchain
  • Business
  • Cryptos
  • DEFI
  • Ethereum news
  • ICO
  • investors
  • Market analyse
  • NFT
  • Price
  • Private
  • Scam
  • spam
  • stock
  • Technical
  • Videos

Recent News

Les Gros Bugs des films TRON et TRON L39Heritage

Les Gros Bugs des films TRON et TRON L'Héritage !

03/20/2023
Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform

Manta Network seeks to bring privacy to non-fungible crypto assets with new NPO platform

03/20/2023

Information

  • Privacy and Antispam Policy
  • Terms of Use
  • Cookie Privacy Policy
  • DMCA
  • Site notice

Copyright © 2023 by Marketinbitcoin. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

No Result
View All Result
  • Home
  • Cryptos
  • Blockchain
  • Market analyse
  • Scam
  • NFT
  • DEFI
  • ICO
  • Videos

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT