• bitcoinBitcoin (BTC) $ 91,655.00
  • ethereumEthereum (ETH) $ 3,318.13
  • tetherTether (USDT) $ 0.996897
  • xrpXRP (XRP) $ 2.01
  • bnbBNB (BNB) $ 692.57
  • solanaSolana (SOL) $ 186.88
  • dogecoinDogecoin (DOGE) $ 0.308771
  • usd-coinUSDC (USDC) $ 0.998455
  • staked-etherLido Staked Ether (STETH) $ 3,317.08
  • cardanoCardano (ADA) $ 0.835716
  • tronTRON (TRX) $ 0.249978
  • avalanche-2Avalanche (AVAX) $ 35.07
  • the-open-networkToncoin (TON) $ 5.48
  • wrapped-stethWrapped stETH (WSTETH) $ 3,939.71
  • chainlinkChainlink (LINK) $ 20.25
  • shiba-inuShiba Inu (SHIB) $ 0.000021
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,646.00
  • suiSui (SUI) $ 4.02
  • hedera-hashgraphHedera (HBAR) $ 0.268410
  • polkadotPolkadot (DOT) $ 6.57
  • wethWETH (WETH) $ 3,322.35
  • stellarStellar (XLM) $ 0.322737
  • hyperliquidHyperliquid (HYPE) $ 26.52
  • bitget-tokenBitget Token (BGB) $ 6.37
  • bitcoin-cashBitcoin Cash (BCH) $ 432.12
  • leo-tokenLEO Token (LEO) $ 9.06
  • uniswapUniswap (UNI) $ 12.91
  • pepePepe (PEPE) $ 0.000018
  • litecoinLitecoin (LTC) $ 97.89
  • wrapped-eethWrapped eETH (WEETH) $ 3,507.57
  • ethena-usdeEthena USDe (USDE) $ 0.995477
  • nearNEAR Protocol (NEAR) $ 4.98
  • usdsUSDS (USDS) $ 0.999752
  • aaveAave (AAVE) $ 328.84
  • aptosAptos (APT) $ 8.73
  • internet-computerInternet Computer (ICP) $ 9.81
  • mantleMantle (MNT) $ 1.18
  • crypto-com-chainCronos (CRO) $ 0.139951
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.452462
  • ethereum-classicEthereum Classic (ETC) $ 25.02
  • whitebitWhiteBIT Coin (WBT) $ 24.44
  • vechainVeChain (VET) $ 0.042810
  • render-tokenRender (RENDER) $ 6.65
  • moneroMonero (XMR) $ 185.38
  • daiDai (DAI) $ 0.999220
  • mantra-daoMANTRA (OM) $ 3.51
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 3.33
  • bittensorBittensor (TAO) $ 444.64
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.25
  • arbitrumArbitrum (ARB) $ 0.726111
  • okbOKB (OKB) $ 49.60
  • filecoinFilecoin (FIL) $ 4.79
  • kaspaKaspa (KAS) $ 0.113945
  • ethenaEthena (ENA) $ 0.948216
  • algorandAlgorand (ALGO) $ 0.313499
  • optimismOptimism (OP) $ 1.77
  • cosmosCosmos Hub (ATOM) $ 6.14
  • tokenize-xchangeTokenize Xchange (TKX) $ 29.72
  • bonkBonk (BONK) $ 0.000030
  • immutable-xImmutable (IMX) $ 1.32
  • theta-tokenTheta Network (THETA) $ 2.23
  • blockstackStacks (STX) $ 1.48
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998591
  • celestiaCelestia (TIA) $ 4.66
  • movementMovement (MOVE) $ 0.942975
  • fantomFantom (FTM) $ 0.735369
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,314.57
  • gatechain-tokenGate (GT) $ 15.70
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030964
  • ondo-financeOndo (ONDO) $ 1.34
  • injective-protocolInjective (INJ) $ 19.69
  • the-graphThe Graph (GRT) $ 0.199934
  • usual-usdUsual USD (USD0) $ 0.999213
  • dogwifcoindogwifhat (WIF) $ 1.80
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,726.16
  • worldcoin-wldWorldcoin (WLD) $ 2.04
  • sei-networkSei (SEI) $ 0.395525
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,423.86
  • flokiFLOKI (FLOKI) $ 0.000171
  • lido-daoLido DAO (LDO) $ 1.83
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,882.00
  • quant-networkQuant (QNT) $ 106.52
  • jasmycoinJasmyCoin (JASMY) $ 0.031621
  • thorchainTHORChain (RUNE) $ 4.42
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,500.61
  • ai16zai16z (AI16Z) $ 1.35
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 92,219.00
  • fasttokenFasttoken (FTN) $ 3.36
  • galaGALA (GALA) $ 0.033462
  • raydiumRaydium (RAY) $ 4.84
  • flare-networksFlare (FLR) $ 0.024537
  • beam-2Beam (BEAM) $ 0.025325
  • kucoin-sharesKuCoin (KCS) $ 10.96
  • makerMaker (MKR) $ 1,471.43
  • tezosTezos (XTZ) $ 1.28
  • pyth-networkPyth Network (PYTH) $ 0.358996
  • the-sandboxThe Sandbox (SAND) $ 0.527880
  • nexoNEXO (NEXO) $ 1.27
  • binance-staked-solBinance Staked SOL (BNSOL) $ 191.06
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 91,522.00
  • based-brettBrett (BRETT) $ 0.117939
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,418.04
  • eosEOS (EOS) $ 0.753425
  • curve-dao-tokenCurve DAO (CRV) $ 0.904305
  • kaiaKaia (KAIA) $ 0.192743
  • ethereum-name-serviceEthereum Name Service (ENS) $ 32.63
  • jupiter-exchange-solanaJupiter (JUP) $ 0.792186
  • flowFlow (FLOW) $ 0.687669
  • starknetStarknet (STRK) $ 0.462594
  • heliumHelium (HNT) $ 5.93
  • dydx-chaindYdX (DYDX) $ 1.45
  • xdce-crowd-saleXDC Network (XDC) $ 0.069103
  • msolMarinade Staked SOL (MSOL) $ 233.87
  • aerodrome-financeAerodrome Finance (AERO) $ 1.41
  • arweaveArweave (AR) $ 15.68
  • bittorrentBitTorrent (BTT) $ 0.000001
  • bitcoin-svBitcoin SV (BSV) $ 50.70
  • iotaIOTA (IOTA) $ 0.279767
  • coredaoorgCore (CORE) $ 1.06
  • neoNEO (NEO) $ 13.59
  • axie-infinityAxie Infinity (AXS) $ 6.04
  • zcashZcash (ZEC) $ 58.56
  • elrond-erd-2MultiversX (EGLD) $ 33.23
  • jito-governance-tokenJito (JTO) $ 3.33
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,317.74
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 91,363.00
  • aioz-networkAIOZ Network (AIOZ) $ 0.774808
  • matic-networkPolygon (MATIC) $ 0.451970
  • decentralandDecentraland (MANA) $ 0.462017
  • apecoinApeCoin (APE) $ 1.17
  • wbnbWrapped BNB (WBNB) $ 692.58
  • pendlePendle (PENDLE) $ 5.08
  • wormholeWormhole (W) $ 0.293280
  • spx6900SPX6900 (SPX) $ 0.867444
  • mog-coinMog Coin (MOG) $ 0.000002
  • fartcoinFartcoin (FARTCOIN) $ 0.792329
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,614.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,314.38
  • usddUSDD (USDD) $ 0.994812
  • chilizChiliz (CHZ) $ 0.081812
  • popcatPopcat (POPCAT) $ 0.773062
  • eigenlayerEigenlayer (EIGEN) $ 3.52
  • dexeDeXe (DEXE) $ 12.82
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,320.75
  • conflux-tokenConflux (CFX) $ 0.153876
  • reserve-rights-tokenReserve Rights (RSR) $ 0.013390
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.45
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 199.74
  • gnosisGnosis (GNO) $ 272.04
  • zksyncZKsync (ZK) $ 0.188702
  • akash-networkAkash Network (AKT) $ 2.80
  • mina-protocolMina Protocol (MINA) $ 0.572513
  • roninRonin (RON) $ 1.84
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.308062
  • compound-governance-tokenCompound (COMP) $ 74.99
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.663585
  • ecasheCash (XEC) $ 0.000033
  • echelon-primeEchelon Prime (PRIME) $ 12.92
  • havvenSynthetix Network (SNX) $ 1.93
  • dydxdYdX (ETHDYDX) $ 1.45
  • fraxFrax (FRAX) $ 0.992674
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,503.79
  • tether-goldTether Gold (XAUT) $ 2,591.91
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 91,865.00
  • amp-tokenAmp (AMP) $ 0.007508
  • turboTurbo (TURBO) $ 0.009103
  • notcoinNotcoin (NOT) $ 0.006101
  • superfarmSuperVerse (SUPER) $ 1.37
  • gigachad-2Gigachad (GIGA) $ 0.064408
  • axelarAxelar (AXL) $ 0.674771
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000106
  • susdssUSDS (SUSDS) $ 1.02
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006470
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,601.01
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.005641
  • layerzeroLayerZero (ZRO) $ 5.08
  • oasis-networkOasis (ROSE) $ 0.083749
  • grassGrass (GRASS) $ 2.29
  • livepeerLivepeer (LPT) $ 14.98
  • ordinalsORDI (ORDI) $ 26.17
  • beldexBeldex (BDX) $ 0.079341
  • paypal-usdPayPal USD (PYUSD) $ 0.999123
  • 1inch1inch (1INCH) $ 0.382669
  • kusamaKusama (KSM) $ 32.81
  • vanaVana (VANA) $ 16.94
  • pax-goldPAX Gold (PAXG) $ 2,613.67
  • apenftAPENFT (NFT) $ 0.00000052
  • chex-tokenCHEX Token (CHEX) $ 0.516358
  • blurBlur (BLUR) $ 0.241480
  • safeSafe (SAFE) $ 0.982000
  • usdx-money-usdxusdx.money USDX (USDX) $ 0.993811
  • aixbtaixbt by Virtuals (AIXBT) $ 0.506665
  • nervos-networkNervos Network (CKB) $ 0.011063
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • true-usdTrueUSD (TUSD) $ 0.997390
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,730.00
  • kavaKava (KAVA) $ 0.450809
  • frax-etherFrax Ether (FRXETH) $ 3,306.82
  • pumpbtcpumpBTC (PUMPBTC) $ 90,737.00
  • usualUsual (USUAL) $ 0.998171

Trust Wallet Fixed Vulnerability But Warns $88,000 of User Funds Are Still at Risk

0 309

Trust Wallet Fixed Vulnerability But Warns $88,000 of User Funds Are Still at Risk

It took a few days for the team at Trust Wallet to patch a vulnerability that put users’ funds at risk and release the necessary fix. But the popular crypto wallet didn’t publicly acknowledge the issue for months, and says even now that affected users will need to move to a new wallet address to protect their funds.

On Saturday, Trust Wallet announced that it fixed a vulnerability that impacts users who created a digital wallet using the project’s browser extension between Nov. 13 and Nov. 23 of last year. The fix only benefits browser wallets created after Nov. 23.

“To be free from the vulnerability, users must migrate their assets from the affected wallet addresses to new, non-affected wallet addresses,” Trust Wallet said in a blog post. “Under these circumstances, we undertook every possible measure to inform users and assist them in mitigating the risk of potential attacks.”

The Binance-backed wallet project said it had been initially alerted to the problem by a security researcher last fall, who flagged an issue in its open-source library that exposed private keys to a security risk.

Though most of the users’ vulnerable funds have been secured, Trust Wallet says that $88,300 of funds are still exposed. Trust Wallet acknowledged that a few users had fallen victim to the vulnerability, pledging on Twitter to offer them a refund.

“Despite our best efforts to minimize loss, we proactively identified 2 likely exploits with a total loss of $170K,” the project said on Twitter. “To do right to users, we created a reimbursement process for affected users to make them whole.”

7/10 Despite our best efforts to minimize loss, we proactively identified 2 likely exploits with a total loss of $170K. To do right to users, we created a reimbursement process for affected users to make them whole.

See the claim process here: https://t.co/a7qLwJQuop

— Trust Wallet (@TrustWallet) April 22, 2023

Once the vulnerability had been fixed—preventing new wallets from being impacted—the project team says it debated whether to disclose the vulnerability publicly.

“Our primary objective was to help users preserve as much of their assets as possible and prevent potential losses,” it said. “We believed that confidential, one-on-one communication with users would enable users to take the necessary actions without sacrificing their assets’ sole ownership.”

The project said it reached out to impacted users through multiple rounds of mobile push notifications and in-app warnings that appeared every minute. The messages were accompanied by clear instructions on how users could transfer their assets, it said.

Not only did Trust Wallet offer users customer support, but the project also offered to reimburse gas fees for users transferring their funds to uncompromised wallets. In total, Trust Wallet reimbursed around 23.6 BNB of gas fees, or around $7,700.

Additionally, Trust Wallet reached out to Binance and secured the exchange’s help in reaching out to users who had funds that could be traced back to the exchange. The project emphasized that it did not share “personally identifiable information” with the exchange.

The project thanked Binance’s security team for “triaging the issue, conducting risk assessments, escalating the matter, conducting impact analysis, and communicating with the security researcher.”

Trust Wallet said it had prepared a public statement regarding the vulnerability last November, but decided to wait, weighing the value of informing the public against the possibility of highlighting a security hole that could still be used.

The public warning’s date would ultimately be pushed back in February to April.

“We considered that once the disclosure was made, a bad actor could exploit the remaining wallets and take ownership of the funds left,” it said. “Therefore, we gave affected users more time to secure their fund[s] instead of making a[…] premature disclosure.”

Source

Leave A Reply

Your email address will not be published.