Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Fireblocks Discloses Critical Vulnerability in BitGo Ethereum Wallets

Altszn.com by Altszn.com
March 17, 2023
in Blockchain
0
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



The cryptography research team at blockchain infrastructure provider Fireblocks today released the details of a vulnerability in BitGo’s Ethereum wallets that use the firm’s Threshold Signature Scheme (TSS).

BitGo users whose private keys were potentially exposed include exchanges, banks, and notable Web3 brands with hundreds of thousands of users between them. Fireblocks refused to disclose the names of specific brands affected, citing a non-disclosure agreement (NDA).

Fireblocks was able to catch the vulnerability in early December, just over a month after the service was made public.

After confirming the technical details of the vulnerability, BitGo suspended the service on December 10, releasing a patch update in February. The Palo Alto-based firm also required its clients to update to the latest version by March 17.

Today’s announcement comes at the end of a “coordinated disclosure” process that the firm’s research team has followed with BitGo’s security team. According to Fireblocks, the vulnerability could have enabled an attacker to extract a full private key using a single signature and a few seconds of computation, bypassing all of BitGo’s security features.

Digital asset custodian and security company BitGo, whose customers include some of the crypto industry’s big names, such as Bitstamp, Pantera Capital, and eToro, among others, first introduced TSS wallets in June 2022, with support for Ethereum wallets added in October.

Concerns remain over potential prior exploits

The vulnerability—dubbed BitGo Zero Proof Vulnerability—stemmed from a missing implementation of mandatory Zero-Knowledge Proofs in the BitGo TSS wallet protocol, which uses the Elliptic Curve Digital Signature Algorithm (ECDSA).

The Zero Proof vulnerability was initially discovered in BitGoJS, the SDK that BitGo clients use to interact with the BitGo API. BitGoJS is used for performing signatures on the client side.

Exploiting the vulnerability on the SDK allows an attacker to steal the private key share used by the client, regardless of their key storage methods and security measures.

Despite the measures taken by BitGo to address the vulnerability, the team at Fireblocks is still concerned that prior exploitation could have left affected brands’ NFT wallets vulnerable.

“Any patch introduced into the library should protect wallets that implement it,” Fireblocks head of technology, research and innovation Arik Galansky told Decrypt. “However, it still leaves the concern if anyone has already exploited the vulnerability in the past and extracted the key while it was using a vulnerable library.”

“As attacks on the crypto industry continue to accelerate, licensed custodians are entrusted with securing billions of dollars in user funds,” Fireblocks co-founder and CTO Idan Ofrat said in a statement shared with Decrypt. “The vulnerability is a result of the wallet provider failing to follow a well-reviewed cryptographic standard.”

Although wallets generated following the patch should be safe, according to Fireblocks, the keys of any BitGo Ethereum TSS wallet generated prior to the update should be considered potentially exposed. Any funds in those wallets should therefore be considered at risk and immediately moved to a secure wallet.

Stay on top of crypto news, get daily updates in your inbox.



Read More: decrypt.co

Tags: BitGoBlockchainCriticaldisclosesEthereumFireblocksvulnerabilityWallets
ADVERTISEMENT

Recent

Animoca Brands Yet Again Reduces Its Metaverse Fund Expectations

March 27, 2023

Minecraft, GTA may change their tune on blockchain yet: GameFi execs

March 27, 2023

Titanium Blockchain CEO behind BARs ICO fraud, put behind bars for 4 years

March 27, 2023

Categories

  • Altcoins (267)
  • Bitcoin (7,263)
  • Blockchain (7,393)
  • Crypto (12,356)
  • Dark Web (815)
  • DeFi (4,494)
  • Ethereum (3,778)
  • Exchanges (472)
  • Metaverse (5,528)
  • Monero (494)
  • NFT (4,305)
  • Psychedelic Stocks (800)
  • Solana (1,384)
  • Web3 (9,343)
  • XRP (16)
  • Zcash (313)

Category

Advertise

Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

Useful Links

Advertise
DMCA
Contact Us
Privacy Policy
Shipping & Returns
Terms of Use

Resources

Exchanges
Changelly
Web3 Jobs

Recent News

Animoca Brands Yet Again Reduces Its Metaverse Fund Expectations

March 27, 2023

Minecraft, GTA may change their tune on blockchain yet: GameFi execs

March 27, 2023

© 2022 Altszn.com. All Rights Reserved.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3

© Altszn.com. All Rights Reserved.

  • bitcoinBitcoin (BTC) $ 27,932.00
  • ethereumEthereum (ETH) $ 1,768.16
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 328.50
  • usd-coinUSD Coin (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.456815
  • cardanoCardano (ADA) $ 0.353270
  • staked-etherLido Staked Ether (STETH) $ 1,767.19
  • dogecoinDogecoin (DOGE) $ 0.073948
  • matic-networkPolygon (MATIC) $ 1.10
  • binance-usdBinance USD (BUSD) $ 1.00
  • solanaSolana (SOL) $ 20.73
  • polkadotPolkadot (DOT) $ 6.01
  • litecoinLitecoin (LTC) $ 92.58
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • tronTRON (TRX) $ 0.064400
  • avalanche-2Avalanche (AVAX) $ 16.92
  • daiDai (DAI) $ 1.00
  • uniswapUniswap (UNI) $ 5.77
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 27,963.00
  • chainlinkChainlink (LINK) $ 7.19
  • cosmosCosmos Hub (ATOM) $ 11.21
  • leo-tokenLEO Token (LEO) $ 3.46
  • the-open-networkToncoin (TON) $ 2.10
  • moneroMonero (XMR) $ 160.05
  • ethereum-classicEthereum Classic (ETC) $ 20.10
  • okbOKB (OKB) $ 41.99
  • stellarStellar (XLM) $ 0.092427
  • bitcoin-cashBitcoin Cash (BCH) $ 124.19
  • filecoinFilecoin (FIL) $ 5.60
  • aptosAptos (APT) $ 11.84
  • true-usdTrueUSD (TUSD) $ 1.00
  • lido-daoLido DAO (LDO) $ 2.16
  • hedera-hashgraphHedera (HBAR) $ 0.061439
  • quant-networkQuant (QNT) $ 122.71
  • crypto-com-chainCronos (CRO) $ 0.068340
  • nearNEAR Protocol (NEAR) $ 1.93
  • vechainVeChain (VET) $ 0.022822
  • arbitrumArbitrum (ARB) $ 1.29
  • algorandAlgorand (ALGO) $ 0.209640
  • apecoinApeCoin (APE) $ 4.03
  • internet-computerInternet Computer (ICP) $ 4.94
  • blockstackStacks (STX) $ 0.987827
  • the-graphThe Graph (GRT) $ 0.140456
  • eosEOS (EOS) $ 1.13
  • fantomFantom (FTM) $ 0.438676
  • the-sandboxThe Sandbox (SAND) $ 0.628433
  • elrond-erd-2MultiversX (EGLD) $ 42.51
  • decentralandDecentraland (MANA) $ 0.585949
  • tezosTezos (XTZ) $ 1.15