• bitcoinBitcoin (BTC) $ 95,438.00
  • ethereumEthereum (ETH) $ 3,611.06
  • xrpXRP (XRP) $ 2.58
  • tetherTether (USDT) $ 0.999963
  • solanaSolana (SOL) $ 226.08
  • bnbBNB (BNB) $ 646.85
  • dogecoinDogecoin (DOGE) $ 0.414811
  • cardanoCardano (ADA) $ 1.26
  • usd-coinUSDC (USDC) $ 0.999864
  • staked-etherLido Staked Ether (STETH) $ 3,606.15
  • avalanche-2Avalanche (AVAX) $ 50.76
  • tronTRON (TRX) $ 0.227328
  • shiba-inuShiba Inu (SHIB) $ 0.000029
  • the-open-networkToncoin (TON) $ 6.62
  • stellarStellar (XLM) $ 0.531291
  • chainlinkChainlink (LINK) $ 24.79
  • wrapped-stethWrapped stETH (WSTETH) $ 4,289.68
  • polkadotPolkadot (DOT) $ 9.86
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 95,294.00
  • hedera-hashgraphHedera (HBAR) $ 0.341801
  • bitcoin-cashBitcoin Cash (BCH) $ 531.30
  • suiSui (SUI) $ 3.49
  • wethWETH (WETH) $ 3,608.72
  • litecoinLitecoin (LTC) $ 128.81
  • nearNEAR Protocol (NEAR) $ 7.24
  • pepePepe (PEPE) $ 0.000020
  • uniswapUniswap (UNI) $ 14.02
  • leo-tokenLEO Token (LEO) $ 8.78
  • aptosAptos (APT) $ 14.10
  • wrapped-eethWrapped eETH (WEETH) $ 3,803.49
  • internet-computerInternet Computer (ICP) $ 13.67
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.698482
  • usdsUSDS (USDS) $ 0.998843
  • crypto-com-chainCronos (CRO) $ 0.200662
  • vechainVeChain (VET) $ 0.063586
  • ethereum-classicEthereum Classic (ETC) $ 33.18
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.86
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • render-tokenRender (RENDER) $ 9.01
  • algorandAlgorand (ALGO) $ 0.546073
  • bittensorBittensor (TAO) $ 615.03
  • filecoinFilecoin (FIL) $ 7.25
  • arbitrumArbitrum (ARB) $ 1.05
  • kaspaKaspa (KAS) $ 0.156865
  • cosmosCosmos Hub (ATOM) $ 9.68
  • daiDai (DAI) $ 1.00
  • blockstackStacks (STX) $ 2.38
  • aaveAave (AAVE) $ 232.77
  • fantomFantom (FTM) $ 1.24
  • immutable-xImmutable (IMX) $ 2.04
  • celestiaCelestia (TIA) $ 7.75
  • whitebitWhiteBIT Coin (WBT) $ 23.27
  • okbOKB (OKB) $ 54.26
  • mantra-daoMANTRA (OM) $ 3.56
  • bonkBonk (BONK) $ 0.000042
  • dogwifcoindogwifhat (WIF) $ 3.19
  • optimismOptimism (OP) $ 2.53
  • injective-protocolInjective (INJ) $ 32.37
  • moneroMonero (XMR) $ 170.90
  • mantleMantle (MNT) $ 0.898035
  • hyperliquidHyperliquid (HYPE) $ 8.91
  • the-graphThe Graph (GRT) $ 0.299989
  • theta-tokenTheta Network (THETA) $ 2.81
  • sei-networkSei (SEI) $ 0.659783
  • ethenaEthena (ENA) $ 0.819658
  • worldcoin-wldWorldcoin (WLD) $ 3.32
  • ondo-financeOndo (ONDO) $ 1.65
  • thorchainTHORChain (RUNE) $ 6.55
  • bitget-tokenBitget Token (BGB) $ 1.58
  • flokiFLOKI (FLOKI) $ 0.000227
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,619.16
  • galaGALA (GALA) $ 0.051660
  • kaiaKaia (KAIA) $ 0.361315
  • based-brettBrett (BRETT) $ 0.193599
  • pyth-networkPyth Network (PYTH) $ 0.531750
  • makerMaker (MKR) $ 2,150.48
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.995888
  • the-sandboxThe Sandbox (SAND) $ 0.774354
  • flare-networksFlare (FLR) $ 0.035322
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,045.12
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 95,389.00
  • jasmycoinJasmyCoin (JASMY) $ 0.037036
  • arweaveArweave (AR) $ 26.72
  • flowFlow (FLOW) $ 1.11
  • iotaIOTA (IOTA) $ 0.478880
  • eosEOS (EOS) $ 1.12
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,790.96
  • lido-daoLido DAO (LDO) $ 1.86
  • tezosTezos (XTZ) $ 1.60
  • starknetStarknet (STRK) $ 0.715090
  • jupiter-exchange-solanaJupiter (JUP) $ 1.18
  • matic-networkPolygon (MATIC) $ 0.698792
  • beam-2Beam (BEAM) $ 0.029173
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,712.28
  • kucoin-sharesKuCoin (KCS) $ 12.44
  • heliumHelium (HNT) $ 8.61
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 95,309.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.46
  • raydiumRaydium (RAY) $ 5.00
  • axie-infinityAxie Infinity (AXS) $ 9.31
  • bitcoin-svBitcoin SV (BSV) $ 73.29
  • gatechain-tokenGate (GT) $ 11.48
  • coredaoorgCore (CORE) $ 1.51
  • bittorrentBitTorrent (BTT) $ 0.000001
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,720.17
  • ethereum-name-serviceEthereum Name Service (ENS) $ 40.82
  • neoNEO (NEO) $ 19.09
  • elrond-erd-2MultiversX (EGLD) $ 48.08
  • decentralandDecentraland (MANA) $ 0.696017
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 1.28
  • dydx-chaindYdX (DYDX) $ 1.80
  • aioz-networkAIOZ Network (AIOZ) $ 1.12
  • popcatPopcat (POPCAT) $ 1.29
  • apecoinApeCoin (APE) $ 1.66
  • msolMarinade Staked SOL (MSOL) $ 280.11
  • xdce-crowd-saleXDC Network (XDC) $ 0.077332
  • aerodrome-financeAerodrome Finance (AERO) $ 1.63
  • tokenize-xchangeTokenize Xchange (TKX) $ 13.71
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,613.50
  • zcashZcash (ZEC) $ 71.16
  • chilizChiliz (CHZ) $ 0.116813
  • conflux-tokenConflux (CFX) $ 0.232428
  • fasttokenFasttoken (FTN) $ 3.17
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 95,406.00
  • mina-protocolMina Protocol (MINA) $ 0.874263
  • binance-staked-solBinance Staked SOL (BNSOL) $ 229.88
  • akash-networkAkash Network (AKT) $ 4.11
  • ecasheCash (XEC) $ 0.000051
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,791.72
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 94,548.00
  • pendlePendle (PENDLE) $ 5.92
  • curve-dao-tokenCurve DAO (CRV) $ 0.764691
  • wormholeWormhole (W) $ 0.346944
  • nexoNEXO (NEXO) $ 1.45
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 239.49
  • axelarAxelar (AXL) $ 1.08
  • notcoinNotcoin (NOT) $ 0.009062
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.18
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 95,011.00
  • ordinalsORDI (ORDI) $ 42.76
  • havvenSynthetix Network (SNX) $ 2.70
  • mog-coinMog Coin (MOG) $ 0.000002
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.415608
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.009312
  • oasis-networkOasis (ROSE) $ 0.121676
  • dydxdYdX (ETHDYDX) $ 1.81
  • zksyncZKsync (ZK) $ 0.222263
  • roninRonin (RON) $ 2.18
  • blurBlur (BLUR) $ 0.386167
  • grassGrass (GRASS) $ 3.21
  • nervos-networkNervos Network (CKB) $ 0.017195
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,607.95
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000141
  • compound-governance-tokenCompound (COMP) $ 85.48
  • usddUSDD (USDD) $ 0.998302
  • neiro-3Neiro (NEIRO) $ 0.001796
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,609.26
  • arkhamArkham (ARKM) $ 2.33
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.721730
  • kavaKava (KAVA) $ 0.666411
  • eigenlayerEigenlayer (EIGEN) $ 3.81
  • gnosisGnosis (GNO) $ 272.85
  • reserve-rights-tokenReserve Rights (RSR) $ 0.013053
  • layerzeroLayerZero (ZRO) $ 6.18
  • kusamaKusama (KSM) $ 43.09
  • safeSafe (SAFE) $ 1.32
  • echelon-primeEchelon Prime (PRIME) $ 13.06
  • 1inch1inch (1INCH) $ 0.496640
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,913.74
  • tether-goldTether Gold (XAUT) $ 2,648.05
  • superfarmSuperVerse (SUPER) $ 1.45
  • zilliqaZilliqa (ZIL) $ 0.033943
  • dashDash (DASH) $ 53.51
  • book-of-memeBOOK OF MEME (BOME) $ 0.009371
  • fraxFrax (FRAX) $ 0.993609
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.006433
  • moo-dengMoo Deng (MOODENG) $ 0.638113
  • holotokenHolo (HOT) $ 0.003522
  • astarAstar (ASTR) $ 0.083818
  • bitcoin-goldBitcoin Gold (BTG) $ 35.10
  • super-oethSuper OETH (SUPEROETHB) $ 3,609.07
  • amp-tokenAmp (AMP) $ 0.007450
  • bazaarsBazaars (BZR) $ 9.75
  • woo-networkWOO (WOO) $ 0.321107
  • enjincoinEnjin Coin (ENJ) $ 0.334655
  • theta-fuelTheta Fuel (TFUEL) $ 0.087660
  • stepnGMT (GMT) $ 0.232099
  • snekSnek (SNEK) $ 0.008004
  • creditcoin-2Creditcoin (CTC) $ 1.44
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000028
  • livepeerLivepeer (LPT) $ 16.08
  • qubic-networkQubic (QUBIC) $ 0.000005
  • iotexIoTeX (IOTX) $ 0.060467
  • apenftAPENFT (NFT) $ 0.00000057
  • dexeDeXe (DEXE) $ 9.86
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 95,197.00
  • celoCelo (CELO) $ 1.00
  • beldexBeldex (BDX) $ 0.079819
  • 0x0x Protocol (ZRX) $ 0.646291
  • frax-etherFrax Ether (FRXETH) $ 3,605.30

Trust Wallet Fixed Vulnerability But Warns $88,000 of User Funds Are Still at Risk

0 292

Trust Wallet Fixed Vulnerability But Warns $88,000 of User Funds Are Still at Risk

It took a few days for the team at Trust Wallet to patch a vulnerability that put users’ funds at risk and release the necessary fix. But the popular crypto wallet didn’t publicly acknowledge the issue for months, and says even now that affected users will need to move to a new wallet address to protect their funds.

On Saturday, Trust Wallet announced that it fixed a vulnerability that impacts users who created a digital wallet using the project’s browser extension between Nov. 13 and Nov. 23 of last year. The fix only benefits browser wallets created after Nov. 23.

“To be free from the vulnerability, users must migrate their assets from the affected wallet addresses to new, non-affected wallet addresses,” Trust Wallet said in a blog post. “Under these circumstances, we undertook every possible measure to inform users and assist them in mitigating the risk of potential attacks.”

The Binance-backed wallet project said it had been initially alerted to the problem by a security researcher last fall, who flagged an issue in its open-source library that exposed private keys to a security risk.

Though most of the users’ vulnerable funds have been secured, Trust Wallet says that $88,300 of funds are still exposed. Trust Wallet acknowledged that a few users had fallen victim to the vulnerability, pledging on Twitter to offer them a refund.

“Despite our best efforts to minimize loss, we proactively identified 2 likely exploits with a total loss of $170K,” the project said on Twitter. “To do right to users, we created a reimbursement process for affected users to make them whole.”

7/10 Despite our best efforts to minimize loss, we proactively identified 2 likely exploits with a total loss of $170K. To do right to users, we created a reimbursement process for affected users to make them whole.

See the claim process here: https://t.co/a7qLwJQuop

— Trust Wallet (@TrustWallet) April 22, 2023

Once the vulnerability had been fixed—preventing new wallets from being impacted—the project team says it debated whether to disclose the vulnerability publicly.

“Our primary objective was to help users preserve as much of their assets as possible and prevent potential losses,” it said. “We believed that confidential, one-on-one communication with users would enable users to take the necessary actions without sacrificing their assets’ sole ownership.”

The project said it reached out to impacted users through multiple rounds of mobile push notifications and in-app warnings that appeared every minute. The messages were accompanied by clear instructions on how users could transfer their assets, it said.

Not only did Trust Wallet offer users customer support, but the project also offered to reimburse gas fees for users transferring their funds to uncompromised wallets. In total, Trust Wallet reimbursed around 23.6 BNB of gas fees, or around $7,700.

Additionally, Trust Wallet reached out to Binance and secured the exchange’s help in reaching out to users who had funds that could be traced back to the exchange. The project emphasized that it did not share “personally identifiable information” with the exchange.

The project thanked Binance’s security team for “triaging the issue, conducting risk assessments, escalating the matter, conducting impact analysis, and communicating with the security researcher.”

Trust Wallet said it had prepared a public statement regarding the vulnerability last November, but decided to wait, weighing the value of informing the public against the possibility of highlighting a security hole that could still be used.

The public warning’s date would ultimately be pushed back in February to April.

“We considered that once the disclosure was made, a bad actor could exploit the remaining wallets and take ownership of the funds left,” it said. “Therefore, we gave affected users more time to secure their fund[s] instead of making a[…] premature disclosure.”

Source

Leave A Reply

Your email address will not be published.