• bitcoinBitcoin (BTC) $ 61,504.00
  • ethereumEthereum (ETH) $ 2,995.61
  • tetherTether (USDT) $ 0.999962
  • bnbBNB (BNB) $ 589.58
  • solanaSolana (SOL) $ 143.99
  • usd-coinUSDC (USDC) $ 0.999936
  • xrpXRP (XRP) $ 0.519593
  • staked-etherLido Staked Ether (STETH) $ 2,993.44
  • dogecoinDogecoin (DOGE) $ 0.146136
  • the-open-networkToncoin (TON) $ 5.93
  • cardanoCardano (ADA) $ 0.461827
  • shiba-inuShiba Inu (SHIB) $ 0.000023
  • avalanche-2Avalanche (AVAX) $ 34.31
  • tronTRON (TRX) $ 0.123466
  • polkadotPolkadot (DOT) $ 7.01
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,471.00
  • bitcoin-cashBitcoin Cash (BCH) $ 453.16
  • chainlinkChainlink (LINK) $ 14.05
  • nearNEAR Protocol (NEAR) $ 7.06
  • matic-networkPolygon (MATIC) $ 0.687434
  • litecoinLitecoin (LTC) $ 81.99
  • internet-computerInternet Computer (ICP) $ 12.10
  • uniswapUniswap (UNI) $ 7.34
  • leo-tokenLEO Token (LEO) $ 5.96
  • fetch-aiFetch.ai (FET) $ 2.19
  • daiDai (DAI) $ 0.998334
  • render-tokenRender (RNDR) $ 10.35
  • ethereum-classicEthereum Classic (ETC) $ 27.29
  • hedera-hashgraphHedera (HBAR) $ 0.107872
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • aptosAptos (APT) $ 8.62
  • cosmosCosmos Hub (ATOM) $ 9.20
  • pepePepe (PEPE) $ 0.000008
  • crypto-com-chainCronos (CRO) $ 0.126424
  • mantleMantle (MNT) $ 1.02
  • filecoinFilecoin (FIL) $ 5.73
  • wrapped-eethWrapped eETH (WEETH) $ 3,106.17
  • stellarStellar (XLM) $ 0.107459
  • blockstackStacks (STX) $ 2.09
  • okbOKB (OKB) $ 50.33
  • immutable-xImmutable (IMX) $ 2.05
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,944.60
  • kaspaKaspa (KAS) $ 0.122494
  • dogwifcoindogwifhat (WIF) $ 2.87
  • arbitrumArbitrum (ARB) $ 1.03
  • optimismOptimism (OP) $ 2.59
  • bittensorBittensor (TAO) $ 398.60
  • vechainVeChain (VET) $ 0.035193
  • arweaveArweave (AR) $ 38.89
  • the-graphThe Graph (GRT) $ 0.265494
  • makerMaker (MKR) $ 2,713.03
  • moneroMonero (XMR) $ 132.79
  • suiSui (SUI) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 0.999760
  • theta-tokenTheta Network (THETA) $ 2.17
  • injective-protocolInjective (INJ) $ 23.40
  • thorchainTHORChain (RUNE) $ 5.78
  • fantomFantom (FTM) $ 0.665347
  • celestiaCelestia (TIA) $ 9.50
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,310.70
  • flokiFLOKI (FLOKI) $ 0.000172
  • lido-daoLido DAO (LDO) $ 1.87
  • bonkBonk (BONK) $ 0.000024
  • bitget-tokenBitget Token (BGB) $ 1.12
  • algorandAlgorand (ALGO) $ 0.189033
  • galaGALA (GALA) $ 0.043121
  • coredaoorgCore (CORE) $ 1.70
  • sei-networkSei (SEI) $ 0.522164
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,083.46
  • whitebitWhiteBIT Coin (WBT) $ 9.88
  • jupiter-exchange-solanaJupiter (JUP) $ 1.05
  • quant-networkQuant (QNT) $ 97.25
  • flowFlow (FLOW) $ 0.878625
  • aaveAave (AAVE) $ 87.08
  • beam-2Beam (BEAM) $ 0.023808
  • ethenaEthena (ENA) $ 0.881740
  • bitcoin-svBitcoin SV (BSV) $ 62.82
  • dydx-chaindYdX (DYDX) $ 2.12
  • singularitynetSingularityNET (AGIX) $ 0.911382
  • bittorrentBitTorrent (BTT) $ 0.000001
  • worldcoin-wldWorldcoin (WLD) $ 5.49
  • ondo-financeOndo (ONDO) $ 0.782418
  • wormholeWormhole (W) $ 0.614203
  • flare-networksFlare (FLR) $ 0.028296
  • chilizChiliz (CHZ) $ 0.122970
  • neoNEO (NEO) $ 15.30
  • elrond-erd-2MultiversX (EGLD) $ 40.00
  • ribbon-financeRibbon Finance (RBN) $ 1.11
  • akash-networkAkash Network (AKT) $ 4.52
  • axie-infinityAxie Infinity (AXS) $ 7.26
  • zebec-protocolZebec Protocol (ZBC) $ 0.020588
  • gatechain-tokenGate (GT) $ 8.04
  • kucoin-sharesKuCoin (KCS) $ 10.39
  • the-sandboxThe Sandbox (SAND) $ 0.432477
  • ecasheCash (XEC) $ 0.000047
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.67
  • cheeleeCheelee (CHEEL) $ 16.24
  • eosEOS (EOS) $ 0.796852
  • starknetStarknet (STRK) $ 1.25
  • tezosTezos (XTZ) $ 0.926393
  • msolMarinade Staked SOL (MSOL) $ 170.59
  • roninRonin (RON) $ 2.75
  • mina-protocolMina Protocol (MINA) $ 0.799718
  • jasmycoinJasmyCoin (JASMY) $ 0.018156
  • aioz-networkAIOZ Network (AIOZ) $ 0.777071
  • havvenSynthetix Network (SNX) $ 2.57
  • conflux-tokenConflux (CFX) $ 0.212000
  • ordinalsORDI (ORDI) $ 38.36
  • decentralandDecentraland (MANA) $ 0.428105
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,011.26
  • gnosisGnosis (GNO) $ 304.17
  • nervos-networkNervos Network (CKB) $ 0.017614
  • apecoinApeCoin (APE) $ 1.23
  • dexeDeXe (DEXE) $ 13.10
  • book-of-memeBOOK OF MEME (BOME) $ 0.010636
  • usddUSDD (USDD) $ 0.996476
  • heliumHelium (HNT) $ 4.48
  • pyth-networkPyth Network (PYTH) $ 0.482111
  • axelarAxelar (AXL) $ 1.10
  • theta-fuelTheta Fuel (TFUEL) $ 0.109134
  • kavaKava (KAVA) $ 0.658107
  • safeSafe (SAFE) $ 1.67
  • iotaIOTA (IOTA) $ 0.219041
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,987.84
  • nexoNEXO (NEXO) $ 1.24
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.65
  • lido-staked-solLido Staked SOL (STSOL) $ 169.98
  • fraxFrax (FRAX) $ 0.998028
  • klay-tokenKlaytn (KLAY) $ 0.174397
  • swethSwell Ethereum (SWETH) $ 3,141.12
  • echelon-primeEchelon Prime (PRIME) $ 15.57
  • fasttokenFasttoken (FTN) $ 1.95
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000105
  • oasis-networkOasis Network (ROSE) $ 0.089593
  • frax-etherFrax Ether (FRXETH) $ 2,979.54
  • mantra-daoMANTRA (OM) $ 0.735227
  • ocean-protocolOcean Protocol (OCEAN) $ 0.917333
  • bitcoin-goldBitcoin Gold (BTG) $ 33.94
  • blurBlur (BLUR) $ 0.371912
  • dydxdYdX (ETHDYDX) $ 2.12
  • illuviumIlluvium (ILV) $ 88.48
  • tether-goldTether Gold (XAUT) $ 2,310.04
  • osmosisOsmosis (OSMO) $ 0.858338
  • golemGolem (GLM) $ 0.561283
  • wemix-tokenWEMIX (WEMIX) $ 1.57
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000027
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,200.95
  • curve-dao-tokenCurve DAO (CRV) $ 0.443814
  • arkhamArkham (ARKM) $ 2.46
  • woo-networkWOO (WOO) $ 0.285320
  • astarAstar (ASTR) $ 0.093619
  • xdce-crowd-saleXDC Network (XDC) $ 0.037431
  • true-usdTrueUSD (TUSD) $ 0.998974
  • venomVenom (VENOM) $ 0.302601
  • dymensionDymension (DYM) $ 2.95
  • mx-tokenMX (MX) $ 4.93
  • aerodrome-financeAerodrome Finance (AERO) $ 1.07
  • apenftAPENFT (NFT) $ 0.00000048
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,238.73
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.13
  • livepeerLivepeer (LPT) $ 14.64
  • jito-governance-tokenJito (JTO) $ 3.91
  • altlayerAltLayer (ALT) $ 0.334104
  • pendlePendle (PENDLE) $ 4.66
  • iotexIoTeX (IOTX) $ 0.047871
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.36
  • corgiaiCorgiAI (CORGIAI) $ 0.001307
  • ankrAnkr Network (ANKR) $ 0.044536
  • radixRadix (XRD) $ 0.042451
  • popcatPopcat (POPCAT) $ 0.448841
  • zilliqaZilliqa (ZIL) $ 0.023734
  • stepnGMT (GMT) $ 0.215330
  • celoCelo (CELO) $ 0.806026
  • raydiumRaydium (RAY) $ 1.64
  • superfarmSuperVerse (SUPER) $ 0.953693
  • memecoin-2Memecoin (MEME) $ 0.024713
  • 1inch1inch (1INCH) $ 0.369099
  • ether-fiEther.fi (ETHFI) $ 3.68
  • pax-goldPAX Gold (PAXG) $ 2,298.63
  • terra-luna-2Terra (LUNA) $ 0.616726
  • manta-networkManta Network (MANTA) $ 1.66
  • ravencoinRavencoin (RVN) $ 0.030114
  • holotokenHolo (HOT) $ 0.002321
  • enjincoinEnjin Coin (ENJ) $ 0.282186
  • rocket-poolRocket Pool (RPL) $ 20.16
  • amp-tokenAmp (AMP) $ 0.007177
  • 0x0x Protocol (ZRX) $ 0.476546
  • siacoinSiacoin (SC) $ 0.006992
  • aelfaelf (ELF) $ 0.541512
  • project-galaxyGalxe (GAL) $ 3.40
  • compound-governance-tokenCompound (COMP) $ 56.89
  • polymeshPolymesh (POLYX) $ 0.371397
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.51
  • stader-ethxStader ETHx (ETHX) $ 3,078.49
  • skaleSKALE (SKL) $ 0.072074
  • qtumQtum (QTUM) $ 3.53
  • celsius-degree-tokenCelsius Network (CEL) $ 0.879020
  • safepalSafePal (SFP) $ 0.796416
  • compound-wrapped-btccWBTC (CWBTC) $ 1,235.39
  • basic-attention-tokenBasic Attention (BAT) $ 0.243084

A Major Vulnerability Found in Early Crypto Wallet Software Risks Billions in Assets

0 130

A Major Vulnerability Found in Early Crypto Wallet Software Risks Billions in Assets

  news.bitcoin.com 48 m

A Major Vulnerability Found in Early Crypto Wallet Software Risks Billions in Assets

A critical vulnerability in early cryptocurrency wallets, identified by cybersecurity startup Unciphered, threatens billions of dollars in digital assets. Originating from a flaw in the BitcoinJS software used for wallet generation between 2011 and 2015, this issue exposes wallets to potential exploitation. Millions of users are being urged to transfer their assets to wallets generated with updated, secure software.

Report Shows Early Crypto Wallets Exposed to Billion-Dollar Vulnerability

Unciphered‘s exhaustive 22-month investigation has unearthed a significant flaw in BitcoinJS, a widely used browser-based cryptocurrency wallet generation tool. This flaw stems from the SecureRandom function in the JSBN javascript library, compounded by weaknesses in major browsers’ Math.random implementations. This vulnerability, affecting wallets created from 2011 to 2015, makes them susceptible to attacks, with earlier wallets being more vulnerable.

Unciphered disclosed that it has coordinated with various entities to alert millions of users about this vulnerability. For individuals with assets in affected wallets, immediate action is recommended: transferring assets to newly generated wallets using reliable software. This proactive step is crucial for safeguarding digital assets against potential exploitation.

The vulnerability first surfaced for the team during a project for a client locked out of a Blockchain.com bitcoin wallet. This led to the rediscovery of a potential issue in BitcoinJS-generated wallets from 2011-2015. The implication is staggering, potentially affecting millions of cryptocurrency wallets generated during this period, with a significant value of assets at risk.

The vulnerability arises from the way BitcoinJS, a Javascript implementation of Bitcoin, used the JSBN library’s SecureRandom function. This function’s deficiency, particularly in its entropy collection and PRNG (pseudo-random number generator), creates a situation where key material could potentially be recovered by an attacker. The SecureRandom function’s failure to effectively utilize browser cryptographic functions compounded this issue, relying instead on weaker RNG methods.

This situation is critical because bitcoin private keys, requiring 256 bits of entropy, were generated with less entropy than needed. The varied impact of this vulnerability makes some wallets more susceptible to attacks than others. However, certain mitigation measures, like incorporating additional entropy sources, have been implemented over time, reducing the risk for newer wallets.

The vulnerability extends beyond bitcoin, potentially affecting dogecoin, litecoin, and zcash-based wallets. Various wallet services and projects that derived their code from BitcoinJS, including popular ones like Dogechain.info and Blockchain.info, might also be impacted. This highlights the widespread implications of the vulnerability across multiple cryptocurrencies.

Unciphered’s researchers detail that historically, third-party library dependencies have often led to vulnerabilities in software development. Similar issues have been seen in other projects, such as OpenSSL on Debian platforms. The current situation with BitcoinJS and its ecosystem exemplifies this ongoing risk in software development, especially when it comes to securing financial assets and sensitive information.

What do you think about the bug Unciphered discovered? Share your thoughts and opinions about this subject in the comments section below.

Source

Leave A Reply

Your email address will not be published.