Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Fireblocks Discloses Critical Vulnerability in BitGo Ethereum Wallets

Altszn.com by Altszn.com
March 17, 2023
in Blockchain
0
Fireblocks Discloses Critical Vulnerability in BitGo Ethereum Wallets
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



The cryptography research team at blockchain infrastructure provider Fireblocks today released the details of a vulnerability in BitGo’s Ethereum wallets that use the firm’s Threshold Signature Scheme (TSS).

BitGo users whose private keys were potentially exposed include exchanges, banks, and notable Web3 brands with hundreds of thousands of users between them. Fireblocks refused to disclose the names of specific brands affected, citing a non-disclosure agreement (NDA).

Fireblocks was able to catch the vulnerability in early December, just over a month after the service was made public.

After confirming the technical details of the vulnerability, BitGo suspended the service on December 10, releasing a patch update in February. The Palo Alto-based firm also required its clients to update to the latest version by March 17.

Today’s announcement comes at the end of a “coordinated disclosure” process that the firm’s research team has followed with BitGo’s security team. According to Fireblocks, the vulnerability could have enabled an attacker to extract a full private key using a single signature and a few seconds of computation, bypassing all of BitGo’s security features.

Digital asset custodian and security company BitGo, whose customers include some of the crypto industry’s big names, such as Bitstamp, Pantera Capital, and eToro, among others, first introduced TSS wallets in June 2022, with support for Ethereum wallets added in October.

Concerns remain over potential prior exploits

The vulnerability—dubbed BitGo Zero Proof Vulnerability—stemmed from a missing implementation of mandatory Zero-Knowledge Proofs in the BitGo TSS wallet protocol, which uses the Elliptic Curve Digital Signature Algorithm (ECDSA).

The Zero Proof vulnerability was initially discovered in BitGoJS, the SDK that BitGo clients use to interact with the BitGo API. BitGoJS is used for performing signatures on the client side.

Exploiting the vulnerability on the SDK allows an attacker to steal the private key share used by the client, regardless of their key storage methods and security measures.

Despite the measures taken by BitGo to address the vulnerability, the team at Fireblocks is still concerned that prior exploitation could have left affected brands’ NFT wallets vulnerable.

“Any patch introduced into the library should protect wallets that implement it,” Fireblocks head of technology, research and innovation Arik Galansky told Decrypt. “However, it still leaves the concern if anyone has already exploited the vulnerability in the past and extracted the key while it was using a vulnerable library.”

“As attacks on the crypto industry continue to accelerate, licensed custodians are entrusted with securing billions of dollars in user funds,” Fireblocks co-founder and CTO Idan Ofrat said in a statement shared with Decrypt. “The vulnerability is a result of the wallet provider failing to follow a well-reviewed cryptographic standard.”

Although wallets generated following the patch should be safe, according to Fireblocks, the keys of any BitGo Ethereum TSS wallet generated prior to the update should be considered potentially exposed. Any funds in those wallets should therefore be considered at risk and immediately moved to a secure wallet.

Stay on top of crypto news, get daily updates in your inbox.



Read More: decrypt.co

Tags: BitGoBlockchainCriticaldisclosesEthereumFireblocksvulnerabilityWallets
ADVERTISEMENT

Recent

Bitcoin’s (BTC) $2T Market Cap Could Be Drained As Altcoin Season Heats Up in June: Analyst

Bitcoin’s (BTC) $2T Market Cap Could Be Drained As Altcoin Season Heats Up in June: Analyst

May 15, 2025
Yat Siu argues that ownership of the intangible drives innovation.

Yat Siu argues that ownership of the intangible drives innovation.

May 15, 2025
NFT founder stole millions from Bitcoin project, investors allege

NFT founder stole millions from Bitcoin project, investors allege

May 15, 2025

Categories

  • Bitcoin (4,858)
  • Blockchain (11,412)
  • Crypto (9,352)
  • Dark Web (549)
  • DeFi (8,397)
  • Ethereum (4,905)
  • Metaverse (7,531)
  • Monero (290)
  • NFT (1,481)
  • Solana (5,047)
  • Web3 (20,706)
  • Zcash (509)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Bitcoin’s (BTC) $2T Market Cap Could Be Drained As Altcoin Season Heats Up in June: Analyst

    Bitcoin’s (BTC) $2T Market Cap Could Be Drained As Altcoin Season Heats Up in June: Analyst

    May 15, 2025
    Yat Siu argues that ownership of the intangible drives innovation.

    Yat Siu argues that ownership of the intangible drives innovation.

    May 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 102,233.00
    • ethereumEthereum (ETH) $ 2,553.68
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.48
    • bnbBNB (BNB) $ 652.20
    • solanaSolana (SOL) $ 170.95
    • usd-coinUSDC (USDC) $ 0.999905
    • dogecoinDogecoin (DOGE) $ 0.226522
    • cardanoCardano (ADA) $ 0.770047
    • tronTRON (TRX) $ 0.269316
    • staked-etherLido Staked Ether (STETH) $ 2,551.47
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,051.00
    • suiSui (SUI) $ 3.72
    • chainlinkChainlink (LINK) $ 16.28
    • wrapped-stethWrapped stETH (WSTETH) $ 3,077.81
    • avalanche-2Avalanche (AVAX) $ 23.87
    • stellarStellar (XLM) $ 0.297591
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hedera-hashgraphHedera (HBAR) $ 0.199502
    • hyperliquidHyperliquid (HYPE) $ 24.77
    • leo-tokenLEO Token (LEO) $ 8.90
    • bitcoin-cashBitcoin Cash (BCH) $ 391.63
    • the-open-networkToncoin (TON) $ 3.08
    • litecoinLitecoin (LTC) $ 97.98
    • polkadotPolkadot (DOT) $ 4.78
    • usdsUSDS (USDS) $ 0.999866
    • wethWETH (WETH) $ 2,550.09
    • moneroMonero (XMR) $ 347.85
    • pi-networkPi Network (PI) $ 0.882978
    • wrapped-eethWrapped eETH (WEETH) $ 2,730.99
    • pepePepe (PEPE) $ 0.000014
    • bitget-tokenBitget Token (BGB) $ 4.88
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,164.00
    • whitebitWhiteBIT Coin (WBT) $ 30.27
    • uniswapUniswap (UNI) $ 6.38
    • bittensorBittensor (TAO) $ 425.96
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.89
    • aptosAptos (APT) $ 5.51
    • aaveAave (AAVE) $ 226.62
    • okbOKB (OKB) $ 53.94
    • ondo-financeOndo (ONDO) $ 0.967833
    • jito-staked-solJito Staked SOL (JITOSOL) $ 204.98
    • kaspaKaspa (KAS) $ 0.115203
    • internet-computerInternet Computer (ICP) $ 5.47
    • ethereum-classicEthereum Classic (ETC) $ 19.12
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.23
    • bitcoinBitcoin (BTC) $ 102,233.00
    • ethereumEthereum (ETH) $ 2,553.68
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.48
    • bnbBNB (BNB) $ 652.20
    • solanaSolana (SOL) $ 170.95
    • usd-coinUSDC (USDC) $ 0.999905
    • dogecoinDogecoin (DOGE) $ 0.226522
    • cardanoCardano (ADA) $ 0.770047
    • tronTRON (TRX) $ 0.269316
    • staked-etherLido Staked Ether (STETH) $ 2,551.47
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 102,051.00
    • suiSui (SUI) $ 3.72
    • chainlinkChainlink (LINK) $ 16.28
    • wrapped-stethWrapped stETH (WSTETH) $ 3,077.81
    • avalanche-2Avalanche (AVAX) $ 23.87
    • stellarStellar (XLM) $ 0.297591
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hedera-hashgraphHedera (HBAR) $ 0.199502
    • hyperliquidHyperliquid (HYPE) $ 24.77
    • leo-tokenLEO Token (LEO) $ 8.90
    • bitcoin-cashBitcoin Cash (BCH) $ 391.63
    • the-open-networkToncoin (TON) $ 3.08
    • litecoinLitecoin (LTC) $ 97.98
    • polkadotPolkadot (DOT) $ 4.78
    • usdsUSDS (USDS) $ 0.999866
    • wethWETH (WETH) $ 2,550.09
    • moneroMonero (XMR) $ 347.85
    • pi-networkPi Network (PI) $ 0.882978
    • wrapped-eethWrapped eETH (WEETH) $ 2,730.99
    • pepePepe (PEPE) $ 0.000014
    • bitget-tokenBitget Token (BGB) $ 4.88
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,164.00
    • whitebitWhiteBIT Coin (WBT) $ 30.27
    • uniswapUniswap (UNI) $ 6.38
    • bittensorBittensor (TAO) $ 425.96
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.89
    • aptosAptos (APT) $ 5.51
    • aaveAave (AAVE) $ 226.62
    • okbOKB (OKB) $ 53.94
    • ondo-financeOndo (ONDO) $ 0.967833
    • jito-staked-solJito Staked SOL (JITOSOL) $ 204.98
    • kaspaKaspa (KAS) $ 0.115203
    • internet-computerInternet Computer (ICP) $ 5.47
    • ethereum-classicEthereum Classic (ETC) $ 19.12
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.23