Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets

Altszn.com by Altszn.com
August 11, 2023
in Zcash
0
Libbitcoin vulnerability leads to 0k theft from Bitcoin wallets
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter

[ad_1]

Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets

Share





A vulnerability in the Libbitcoin Explorer 3.x library has led to the theft of over $900,000 from Bitcoin users.

Blockchain security firm SlowMist reported the issue.

🚨SlowMist Security Alert🚨

Recently, #Distrust discovered a severe vulnerability affecting cryptocurrency wallets using the #Libbitcoin Explorer 3.x versions. This vulnerability allows attackers to access wallet private keys by exploiting the Mersenne Twister pseudo-random…

— SlowMist (@SlowMist_Team) August 10, 2023

It could also affect users of other digital currencies like Ethereum (ETH), Ripple (XRP), Dogecoin (DOGE), Solana (SOL), Litecoin (LTC), Bitcoin Cash (BCH), and Zcash that employ Libbitcoin to create accounts.

Libbitcoin is a Bitcoin wallet implementation used by various applications, including Airbitz, Bitprim, Blockchain Commons, and Cancoin. SlowMist did not specify which applications are affected by the vulnerability.

The vulnerability, known as the “Milk Sad,” was first discovered by the cybersecurity team “Distrust” and reported to the CEV cybersecurity vulnerability database on Aug. 7. It involves a faulty key generation mechanism in the Libbitcoin Explorer, which allows attackers to guess private keys.

The attackers exploited this vulnerability to steal over $900,000 worth of crypto, including a single attack that siphoned away over $278,318

SlowMist claims to have “blocked” the address, implying that they have contacted exchanges to prevent the attacker from cashing out the funds. They will also be monitoring the address in case funds are moved elsewhere.

The Distrust team and eight freelance security consultants have set up an informational website explaining the vulnerability. They have found that the vulnerability occurs when users generate a wallet seed using the “bx seed” command, which lacks sufficient randomness and can produce the same seed for multiple users.

The vulnerability was discovered when a Libbitcoin user reported missing BTC on July 21. More digging showed that other users were having their Bitcoin stolen similarly.

Eric Voskuil, a member of the Libbitcoin Institute, stated that the “bx seed” command is not intended for production wallets, and changes may be made to strengthen the warning against its use or remove the command altogether.

Wallet vulnerabilities remain a problem for crypto users in 2023, with over $100 million lost in a hack of the Atomic Wallet in June. According to the wallet security rankings released by CER in July, nly six out of 45 wallet brands employ penetration testing to discover vulnerabilities.


Follow Us on Google News



[ad_2]

Read More: crypto.news

Tags: 900KBitcoinleadsLibbitcoinTheftvulnerabilityWalletsZcash
ADVERTISEMENT

Recent

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025
U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

June 10, 2025

Categories

  • Bitcoin (20)
  • Blockchain (5,435)
  • Crypto (5,435)
  • Dark Web (11)
  • DeFi (5,435)
  • Ethereum (2,850)
  • Metaverse (3,389)
  • Monero (19)
  • Solana (3,091)
  • Web3 (12,686)
  • Zcash (260)

Category

Advertise

Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

Useful Links

Advertise
DMCA
Contact Us
Privacy Policy
Shipping & Returns
Terms of Use

Resources

Exchanges
Changelly
Web3 Jobs

Recent News

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025

© 2022 Altszn.com. All Rights Reserved.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3

© Altszn.com. All Rights Reserved.

  • bitcoinBitcoin (BTC) $ 96,812.00
  • ethereumEthereum (ETH) $ 3,365.90
  • tetherTether (USDT) $ 0.999732
  • xrpXRP (XRP) $ 2.11
  • bnbBNB (BNB) $ 939.72
  • usd-coinUSDC (USDC) $ 0.999808
  • staked-etherLido Staked Ether (STETH) $ 3,365.87
  • tronTRON (TRX) $ 0.304593
  • dogecoinDogecoin (DOGE) $ 0.143990
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.404622
  • wrapped-stethWrapped stETH (WSTETH) $ 4,120.90
  • moneroMonero (XMR) $ 711.46
  • bitcoin-cashBitcoin Cash (BCH) $ 626.18
  • whitebitWhiteBIT Coin (WBT) $ 57.74
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,662.47
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 96,609.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,655.54
  • chainlinkChainlink (LINK) $ 14.03
  • usdsUSDS (USDS) $ 0.999635
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999395
  • wethWETH (WETH) $ 3,366.94
  • leo-tokenLEO Token (LEO) $ 8.90
  • stellarStellar (XLM) $ 0.231713
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 96,843.00
  • zcashZcash (ZEC) $ 442.33
  • suiSui (SUI) $ 1.84
  • ethena-usdeEthena USDe (USDE) $ 0.999698
  • avalanche-2Avalanche (AVAX) $ 14.37
  • hyperliquidHyperliquid (HYPE) $ 25.24
  • litecoinLitecoin (LTC) $ 75.71
  • hedera-hashgraphHedera (HBAR) $ 0.121341
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • canton-networkCanton (CC) $ 0.131664
  • usdt0USDT0 (USDT0) $ 0.999647
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.171214
  • daiDai (DAI) $ 0.999854
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.78
  • crypto-com-chainCronos (CRO) $ 0.102288
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999991
  • polkadotPolkadot (DOT) $ 2.20
  • uniswapUniswap (UNI) $ 5.54
  • usd1-wlfiUSD1 (USD1) $ 0.999219
  • rainRain (RAIN) $ 0.009572
  • mantleMantle (MNT) $ 0.969355
  • bittensorBittensor (TAO) $ 283.95
  • memecoreMemeCore (M) $ 1.58
  • aaveAave (AAVE) $ 174.64