fbpx
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
Monday, March 20, 2023
Online Crypto College
CREATE FREE ACCOUNT
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoin
    • Blockchain
    • Regulation
    • Trading
  • Learn Crypto For Free
  • Login
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoin
    • Blockchain
    • Regulation
    • Trading
  • Learn Crypto For Free
  • Login
No Result
View All Result
Online Crypto College
No Result
View All Result

Fireblocks Saves Crypto Wallet Bitgo from Potential Exploit as It Patches Critical Vulnerability

March 17, 2023
in Crypto News
Reading Time: 3 mins read
A A
Fireblocks Saves Crypto Wallet Bitgo from Potential Exploit as It Patches Critical Vulnerability
ShareShareShareShareShare

Related articles

Venezuelan Crypto Authority Removed and Arrested

Venezuelan Crypto Authority Removed and Arrested

March 20, 2023
HeartX Launches Web3 Marketplace and Community Aim to Revolutionize Digital Art Industry

HeartX Launches Web3 Marketplace and Community Aim to Revolutionize Digital Art Industry

March 20, 2023

As the cryptocurrency industry continues to grow and evolve, so do the potential risks and vulnerabilities. In order to stay ahead of the curve, many crypto firms are taking proactive steps to avoid exploits on their platforms. From implementing robust security measures to conducting regular audits, these firms are committed to ensuring the safety and security of their users. Recently, BitGo, a popular cryptocurrency wallet, has recently fixed a crucial vulnerability that could have potentially exposed the private keys of both retail and institutional users.

Fireblocks Becomes a Messiah for Bitgo

In December 2022, the cryptography research team at Fireblocks discovered a significant vulnerability in BitGo’s Threshold Signature Scheme (TSS) wallets. This flaw had the potential to expose the private keys of exchanges, banks, businesses, and platform users, and Fireblocks named it the BitGo Zero Proof Vulnerability.

The vulnerability was found to be particularly alarming as attackers could extract a private key in under a minute using just a small amount of JavaScript code. As a result, BitGo took swift action and suspended the vulnerable service on December 10, 2022. A patch was released in February 2023, and BitGo required client-side updates to the latest version by March 17 to address the issue.

The Fireblocks team revealed how it discovered the exploit by using a free BitGo account on the mainnet. By identifying a missing component of mandatory zero-knowledge proofs in BitGo’s ECDSA TSS wallet protocol, the team was able to expose the private key through a straightforward attack.

To mitigate the possibility of a single point of attack, industry-standard enterprise-grade cryptocurrency asset platforms utilize either multi-party-computation (MPC/TSS) or multi-signature technology. This involves distributing a private key among multiple parties to ensure security controls in case one party is compromised. This approach minimizes the risks associated with holding cryptocurrency assets and helps to avoid potential exploits.

Crypto Market Could Have Witnessed Another Exploit 

Fireblocks demonstrated that both internal and external attackers could obtain full access to a private key through two methods.

First, a compromised client-side user could initiate a transaction to obtain a portion of the private key held in BitGo’s system. BitGo would then perform the signing computation and share information that leaks the BitGo key shard, potentially exposing the entire private key. The team said:

“The attacker can now reconstruct the full private key, load it in an external wallet and withdraw the funds immediately or at a later stage.”

The second scenario explores the possibility of an attack in case BitGo is compromised. In this scenario, the attacker would lie in wait for a customer to initiate a transaction and respond with a malicious value. This value would be used to sign the transaction using the customer’s key shard. By exploiting the response, the attacker would expose the user’s key shard and combine it with BitGo’s key shard to gain control of the wallet.

Fireblocks advises users to create new wallets and transfer funds from ECDSA TSS BitGo wallets before the patch, even though no attacks have been executed through this method.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Euler Finance hackers begin laundering stolen tokens 

Next Post

US Banks borrow record-high $164.8B from Fed backstop facilities

Related Posts

Venezuelan Crypto Authority Removed and Arrested

Venezuelan Crypto Authority Removed and Arrested

March 20, 2023

Venezuela’s top authority on crypto policies, Joselit Ramirez, has been removed from his position and arrested for suspicion of participating...

HeartX Launches Web3 Marketplace and Community Aim to Revolutionize Digital Art Industry

HeartX Launches Web3 Marketplace and Community Aim to Revolutionize Digital Art Industry

March 20, 2023

Central, Singapore, 20th March, 2023, Chainwire HeartX, previously known as ArteX, a trailblazer in the digital art industry, has recently...

Complete Review On Crypto.com Exchange 2021

Complete Review On Crypto.com Exchange 2021

March 20, 2023

IntroductionIn a race to get the best out of the crypto world, everyone is in a search of safe, user-friendly...

Fidelity Expands its BTC, ETH Trading to Most Retail Accounts

Fidelity Expands its BTC, ETH Trading to Most Retail Accounts

March 19, 2023

Amid a severe banking crisis, Fidelity Investments has opened access to bitcoin and ether trading to all its retail traders....

CNF Brief: 5 of the biggest stories of the week

CNF Brief: 5 of the biggest stories of the week

March 19, 2023

FUD has engrossed Shiba Inu’s development after a lead developer revealed a significant blunder in the development of Shibarium. Bitcoin...

Load More
Next Post
US Banks borrow record-high $164.8B from Fed backstop facilities

US Banks borrow record-high $164.8B from Fed backstop facilities

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Former FTX CEO Sam Bankman-Fried seeks insurance coverage for legal expenses

Former FTX CEO Sam Bankman-Fried seeks insurance coverage for legal expenses

March 16, 2023
Dogecoin Price Prediction for Mid-March 2023

Dogecoin Price Prediction for Mid-March 2023

March 16, 2023
Without Democracy, Bitcoin Will Fail

Without Democracy, Bitcoin Will Fail

March 19, 2023
Crypto Entrepreneur Bail Package Revised

Crypto Entrepreneur Bail Package Revised

March 19, 2023
Playboy Accepted Ethereum As NFT Payments And Ended Up losing $5 Million

Playboy Accepted Ethereum As NFT Payments And Ended Up losing $5 Million

March 17, 2023

About Us

We provide the latest crypto news, trading tools, and up-to-date education to students and traders all over the world.

ENROLL FOR FREE

Latest Crypto Headlines

  • STX blasts over 250% higher in 30 days
  • Why “Ethereum to $2000” May Soon Become a Reality
  • Venezuelan Crypto Authority Removed and Arrested
  • Taiwan Securities Watchdog Will Regulate Crypto — But Not NFTs – Blockworks
  • FDIC Sells Signature Bank’s Deposits To Flagstar, Excludes $4 Billion In Crypto
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoin
    • Blockchain
    • Regulation
    • Trading
  • Learn Crypto For Free
  • Login
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2022 - OnlineCryptoCollege.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Altcoin
    • Blockchain
    • Regulation
    • Trading
  • Learn Crypto For Free
  • Login

© 2018 JNews by Jegtheme.

  • bitcoinBitcoin(BTC)$28,364.003.42%
  • ethereumEthereum(ETH)$1,789.23-0.35%
  • USDEXUSDEX(USDEX)$1.07-0.53%
  • tetherTether(USDT)$1.01-0.29%
  • binancecoinBNB(BNB)$340.39-0.24%
  • usd-coinUSD Coin(USDC)$1.00-0.05%
  • rippleXRP(XRP)$0.385392-2.95%
  • cardanoCardano(ADA)$0.345438-0.52%
  • matic-networkPolygon(MATIC)$1.16-3.60%
  • staked-etherLido Staked Ether(STETH)$1,787.15-0.27%
  • dogecoinDogecoin(DOGE)$0.074296-0.76%
  • solanaSolana(SOL)$23.527.62%
  • binance-usdBinance USD(BUSD)$1.00-0.19%
  • polkadotPolkadot(DOT)$6.47-0.22%
  • shiba-inuShiba Inu(SHIB)$0.000011-1.42%
  • tronTRON(TRX)$0.0669790.10%
  • litecoinLitecoin(LTC)$82.37-2.43%
  • avalanche-2Avalanche(AVAX)$17.51-1.28%
  • daiDai(DAI)$1.00-0.04%
  • uniswapUniswap(UNI)$6.43-1.52%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$28,439.004.02%
  • chainlinkChainlink(LINK)$7.404.07%
  • cosmosCosmos Hub(ATOM)$12.12-2.17%
  • ToncoinToncoin(TON)$2.38-0.54%
  • leo-tokenLEO Token(LEO)$3.37-0.31%
  • ethereum-classicEthereum Classic(ETC)$20.77-2.38%
  • okbOKB(OKB)$47.16-2.25%
  • moneroMonero(XMR)$154.74-1.33%
  • bitcoin-cashBitcoin Cash(BCH)$135.590.02%
  • filecoinFilecoin(FIL)$6.111.16%
  • Aerarium FiAerarium Fi(AERA)$7.15-13.10%
  • stellarStellar(XLM)$0.0893421.77%
  • AptosAptos(APT)$12.77-2.26%
  • lido-daoLido DAO(LDO)$2.41-4.32%
  • true-usdTrueUSD(TUSD)$1.010.03%
  • quant-networkQuant(QNT)$134.010.96%
  • hedera-hashgraphHedera(HBAR)$0.064224-0.22%
  • crypto-com-chainCronos(CRO)$0.0752495.17%
  • nearNEAR Protocol(NEAR)$2.08-2.80%
  • vechainVeChain(VET)$0.0243011.71%
  • blockstackStacks(STX)$1.247.78%
  • internet-computerInternet Computer(ICP)$5.37-0.95%
  • algorandAlgorand(ALGO)$0.216665-1.67%
  • apecoinApeCoin(APE)$4.19-3.46%
  • the-graphThe Graph(GRT)$0.156664-1.78%
  • fantomFantom(FTM)$0.491287-1.80%
  • eosEOS(EOS)$1.216.12%
  • the-sandboxThe Sandbox(SAND)$0.690.73%
  • immutable-xImmutableX(IMX)$1.42-4.12%
  • elrond-erd-2MultiversX(EGLD)$46.205.63%