Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets

Altszn.com by Altszn.com
August 11, 2023
in Zcash
0
Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



Share





A vulnerability in the Libbitcoin Explorer 3.x library has led to the theft of over $900,000 from Bitcoin users.

Blockchain security firm SlowMist reported the issue.

🚨SlowMist Security Alert🚨

Recently, #Distrust discovered a severe vulnerability affecting cryptocurrency wallets using the #Libbitcoin Explorer 3.x versions. This vulnerability allows attackers to access wallet private keys by exploiting the Mersenne Twister pseudo-random…

— SlowMist (@SlowMist_Team) August 10, 2023

It could also affect users of other digital currencies like Ethereum (ETH), Ripple (XRP), Dogecoin (DOGE), Solana (SOL), Litecoin (LTC), Bitcoin Cash (BCH), and Zcash that employ Libbitcoin to create accounts.

Libbitcoin is a Bitcoin wallet implementation used by various applications, including Airbitz, Bitprim, Blockchain Commons, and Cancoin. SlowMist did not specify which applications are affected by the vulnerability.

The vulnerability, known as the “Milk Sad,” was first discovered by the cybersecurity team “Distrust” and reported to the CEV cybersecurity vulnerability database on Aug. 7. It involves a faulty key generation mechanism in the Libbitcoin Explorer, which allows attackers to guess private keys.

The attackers exploited this vulnerability to steal over $900,000 worth of crypto, including a single attack that siphoned away over $278,318

SlowMist claims to have “blocked” the address, implying that they have contacted exchanges to prevent the attacker from cashing out the funds. They will also be monitoring the address in case funds are moved elsewhere.

The Distrust team and eight freelance security consultants have set up an informational website explaining the vulnerability. They have found that the vulnerability occurs when users generate a wallet seed using the “bx seed” command, which lacks sufficient randomness and can produce the same seed for multiple users.

The vulnerability was discovered when a Libbitcoin user reported missing BTC on July 21. More digging showed that other users were having their Bitcoin stolen similarly.

Eric Voskuil, a member of the Libbitcoin Institute, stated that the “bx seed” command is not intended for production wallets, and changes may be made to strengthen the warning against its use or remove the command altogether.

Wallet vulnerabilities remain a problem for crypto users in 2023, with over $100 million lost in a hack of the Atomic Wallet in June. According to the wallet security rankings released by CER in July, nly six out of 45 wallet brands employ penetration testing to discover vulnerabilities.


Follow Us on Google News





Read More: crypto.news

Tags: 900KBitcoinleadsLibbitcoinTheftvulnerabilityWalletsZcash
ADVERTISEMENT

Recent

Top L2 Arbitrum’s Scaling Roadmap Seeks to Avoid ‘Trade-offs’

Top L2 Arbitrum’s Scaling Roadmap Seeks to Avoid ‘Trade-offs’

May 16, 2025
Pixelmon Announces Strategic Partnership with Ava Labs to Launch Two Mobile Games Including ‘Warden’s Ascent’ on Avalanche with Dedicated Layer-1

Pixelmon Announces Strategic Partnership with Ava Labs to Launch Two Mobile Games Including ‘Warden’s Ascent’ on Avalanche with Dedicated Layer-1

May 16, 2025
Gamers Hate Crypto, but a New High-Profile Partnership Marks a Shift

Gamers Hate Crypto, but a New High-Profile Partnership Marks a Shift

May 16, 2025

Categories

  • Bitcoin (4,812)
  • Blockchain (11,331)
  • Crypto (9,270)
  • Dark Web (540)
  • DeFi (8,355)
  • Ethereum (4,866)
  • Metaverse (7,449)
  • Monero (287)
  • NFT (1,436)
  • Solana (5,028)
  • Web3 (20,606)
  • Zcash (501)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Top L2 Arbitrum’s Scaling Roadmap Seeks to Avoid ‘Trade-offs’

    Top L2 Arbitrum’s Scaling Roadmap Seeks to Avoid ‘Trade-offs’

    May 16, 2025
    Pixelmon Announces Strategic Partnership with Ava Labs to Launch Two Mobile Games Including ‘Warden’s Ascent’ on Avalanche with Dedicated Layer-1

    Pixelmon Announces Strategic Partnership with Ava Labs to Launch Two Mobile Games Including ‘Warden’s Ascent’ on Avalanche with Dedicated Layer-1

    May 16, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 103,460.00
    • ethereumEthereum (ETH) $ 2,494.80
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.36
    • bnbBNB (BNB) $ 643.01
    • solanaSolana (SOL) $ 167.46
    • usd-coinUSDC (USDC) $ 0.999898
    • dogecoinDogecoin (DOGE) $ 0.217962
    • cardanoCardano (ADA) $ 0.753382
    • tronTRON (TRX) $ 0.269109
    • staked-etherLido Staked Ether (STETH) $ 2,487.78
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,305.00
    • suiSui (SUI) $ 3.77
    • wrapped-stethWrapped stETH (WSTETH) $ 2,988.49
    • chainlinkChainlink (LINK) $ 15.49
    • avalanche-2Avalanche (AVAX) $ 22.72
    • hyperliquidHyperliquid (HYPE) $ 27.01
    • stellarStellar (XLM) $ 0.289622
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.95
    • hedera-hashgraphHedera (HBAR) $ 0.193793
    • bitcoin-cashBitcoin Cash (BCH) $ 397.03
    • the-open-networkToncoin (TON) $ 3.05
    • litecoinLitecoin (LTC) $ 99.14
    • polkadotPolkadot (DOT) $ 4.68
    • usdsUSDS (USDS) $ 0.999913
    • wethWETH (WETH) $ 2,490.38
    • moneroMonero (XMR) $ 338.85
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • wrapped-eethWrapped eETH (WEETH) $ 2,651.79
    • bitget-tokenBitget Token (BGB) $ 4.95
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.723848
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 103,424.00
    • whitebitWhiteBIT Coin (WBT) $ 30.13
    • bittensorBittensor (TAO) $ 423.89
    • daiDai (DAI) $ 0.999946
    • uniswapUniswap (UNI) $ 5.94
    • aaveAave (AAVE) $ 226.58
    • nearNEAR Protocol (NEAR) $ 2.76
    • aptosAptos (APT) $ 5.17
    • okbOKB (OKB) $ 53.05
    • kaspaKaspa (KAS) $ 0.115971
    • jito-staked-solJito Staked SOL (JITOSOL) $ 202.45
    • ondo-financeOndo (ONDO) $ 0.922834
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.099155
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.32
    • ethereum-classicEthereum Classic (ETC) $ 18.41
    • bitcoinBitcoin (BTC) $ 103,460.00
    • ethereumEthereum (ETH) $ 2,494.80
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.36
    • bnbBNB (BNB) $ 643.01
    • solanaSolana (SOL) $ 167.46
    • usd-coinUSDC (USDC) $ 0.999898
    • dogecoinDogecoin (DOGE) $ 0.217962
    • cardanoCardano (ADA) $ 0.753382
    • tronTRON (TRX) $ 0.269109
    • staked-etherLido Staked Ether (STETH) $ 2,487.78
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,305.00
    • suiSui (SUI) $ 3.77
    • wrapped-stethWrapped stETH (WSTETH) $ 2,988.49
    • chainlinkChainlink (LINK) $ 15.49
    • avalanche-2Avalanche (AVAX) $ 22.72
    • hyperliquidHyperliquid (HYPE) $ 27.01
    • stellarStellar (XLM) $ 0.289622
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.95
    • hedera-hashgraphHedera (HBAR) $ 0.193793
    • bitcoin-cashBitcoin Cash (BCH) $ 397.03
    • the-open-networkToncoin (TON) $ 3.05
    • litecoinLitecoin (LTC) $ 99.14
    • polkadotPolkadot (DOT) $ 4.68
    • usdsUSDS (USDS) $ 0.999913
    • wethWETH (WETH) $ 2,490.38
    • moneroMonero (XMR) $ 338.85
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • wrapped-eethWrapped eETH (WEETH) $ 2,651.79
    • bitget-tokenBitget Token (BGB) $ 4.95
    • pepePepe (PEPE) $ 0.000012
    • pi-networkPi Network (PI) $ 0.723848
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 103,424.00
    • whitebitWhiteBIT Coin (WBT) $ 30.13
    • bittensorBittensor (TAO) $ 423.89
    • daiDai (DAI) $ 0.999946
    • uniswapUniswap (UNI) $ 5.94
    • aaveAave (AAVE) $ 226.58
    • nearNEAR Protocol (NEAR) $ 2.76
    • aptosAptos (APT) $ 5.17
    • okbOKB (OKB) $ 53.05
    • kaspaKaspa (KAS) $ 0.115971
    • jito-staked-solJito Staked SOL (JITOSOL) $ 202.45
    • ondo-financeOndo (ONDO) $ 0.922834
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.099155
    • tokenize-xchangeTokenize Xchange (TKX) $ 35.32
    • ethereum-classicEthereum Classic (ETC) $ 18.41