Fun

News Feed - 2023-08-10 10:08:59

Tom Mitchelhill7 hours agoFireblocks discloses massive vulnerability affecting crypto walletsFireblocks said the vulnerabilities affecting Coinbase, Binance and Zengo have since been fixed and has reached out to more than 12 others still at risk.2329 Total views14 Total sharesListen to article 0:00NewsJoin us on social networksOver 15 widely-used crypto wallet providers and projects have gaping vulnerabilities that could potentially see millions of crypto wallets drained, according to digital asset infrastructure firm Fireblocks.


In an Aug. 9 press release, Fireblocks said the series of vulnerabilities, dubbed BitForge, are affecting wallets using multi-party computation (MPC) technology, which allows for multiple parties to control and manage cryptocurrency holdings.1/ The Fireblocks research team has uncovered BitForge, a set of vulnerabilities in some of the most widely adopted MPC protocols, that allow an attacker to retrieve a private key from a single device. Read on → https://t.co/xo2r9zgCvj pic.twitter.com/7q1nEeVBwO— Fireblocks (@FireblocksHQ) August 9, 2023


The identified issues were disclosed as “zero day” vulnerabilities — meaning that the flaws had not previously been identified by the projects.“If left unremediated, the exposures would allow attackers and malicious insiders to drain funds from the wallets of millions of retail and institutional customers in seconds, with no knowledge to the user or vendor.”


The firm disclosed that the BitForge vulnerabilities affected many of the top wallet providers, including Coinbase, Zengo and Binance. Following an industry-standard “90 day disclosure period” from Fireblocks, the three firms have since resolved the identified issues.


In a statement, Coinbase’s chief information security officer, Jeff Lunglhofer, thanked Fireblocks for identifying and responsibly disclosing the issue, adding that Coinbase customers and funds were never at risk. Zengo Chief Technology Officer Tal Be"ery noted that the issue was promptly fixed and no user funds were affected.3/ We want to extend our gratitude to the researchers at Fireblocks for identifying this issue, conducting an ethical disclosure, and helping to improve the security of the ecosystem.— Coinbase Cloud ️ (@CoinbaseCloud) August 9, 2023


Fireblocks said it has worked to identify other firms that may be implicated in similar security concerns and have reached out to them.


MPC wallets encrypt a user’s private key and share it between several parties — typically comprised of the wallet owner, a wallet provider, and another third party. Theoretically, no one of these entities should be able to unlock the wallet without first communicating with the others.


Related:Tel Aviv Stock Exchange to offer crypto services via Fireblocks pact


However, according to Fireblocks’ technical reports on the BitForge vulnerabilities, the vulnerabilities would have allowed hackers to “extract the full private key if they were able to compromise only one device.”


“While we are encouraged to see that MPC is now ubiquitous within the digital asset industry, it is evident from our findings — and our subsequent disclosure process — that not all MPC developers and teams are created equal,” said Fireblocks’ chief technology officer and co-founder, Pavel Berengoltz.


“Companies leveraging Web3 technology should work closely with security experts with the know-how and resources to stay ahead of and mitigate vulnerabilities,” he added.


Deposit risk: What do crypto exchanges really do with your money?# Blockchain# Coinbase# Business# Wallet# Cryptocurrency Exchange# Hot wallet# BinanceAdd reactionAdd reactionRelated NewsHow to use index funds and ETFs for passive crypto incomeEnsuring integrity of blockchain transactions: Trust through auditsWhat will Bitcoin do if the Justice Department takes aim at Binance?Binance Blockchain Week picks Turkey to host thousands of Web3 loversKuCoin denies mass layoffs, says cuts are part of normal operationsBinance starts BTC/FDUSD and ETH/FDUSD trading pairs with zero-fees

News Feed

Helen Partz13 hours agoCoinbase suspends 80 non-USD trading pairs to improve liquidityCoinbase crypto exchange has been removing dozens of trading pairs in an effort to improve liquidity on its platforms.3923 Total views
Bank of America Expects the Fed to Keep Hiking Rates Until ‘Point of Pain’ for Consumer Demand
Bank of America Expects the Fed to Keep Hiking Rates Until "Point of Pain" for Consumer Demand Bank of America has warned that the Federal Reserve will have to keep raising interes
‘Ethereum Killers’ Managed to ‘Kill’ Themselves in 2022 Rather Than Beat the Smart Contract Economy’s Heavyweight Champ
‘Ethereum Killers’ Managed to ‘Kill’ Themselves in 2022 Rather Than Beat the Smart Contract Economy’s Heavyweight Champ At the end of 2021, a myriad of people thought a h
Bahrain Central Bank Issues License to Shariah-Compliant Crypto Exchange
Bahrain Central Bank Issues License to Shariah-Compliant Crypto Exchange Middle Eastern crypto exchange Coinmena said this week that it had obtained a crypto ass
UFC Partners With Dapper Labs to Launch NFT Collection ‘UFC Strike’
UFC Partners With Dapper Labs to Launch NFT Collection "UFC Strike" The creators of the Flow blockchain network and NBA Top Shot, Dapper Labs, announced the launch of a new non-fun
Crypto Fear and Greed Index Shows ‘Extreme Fear’ and Shaky Sentiment Persist
Crypto Fear and Greed Index Shows "Extreme Fear" and Shaky Sentiment Persist For a few weeks now, bitcoin sentiment stemming from the Crypto Fear and Greed Index (CFGI) has been in
Brayden Lindrea4 hours agoSEC’s Gary Gensler believes AI can strengthen its enforcement regimeThe Securities and Exchange Commission chair highlighted market surveillance and other instances where agency staff could be
Mark Zuckerberg to Overhaul Meta’s Metaverse App Horizon Worlds After Criticism of Its Simple Graphics
Mark Zuckerberg to Overhaul Meta"s Metaverse App Horizon Worlds After Criticism of Its Simple Graphics Meta CEO Mark Zuckerberg has decided to overhaul the company’s flagshi
KyberSwap Launches on BitTorrent Chain With $1.5M in Liquidity Mining and Incentive Rewards
KyberSwap Launches on BitTorrent Chain With $1.5M in Liquidity Mining and Incentive Rewards sponsored Kyber Network and BitTorrent have announced the integration of KyberSwap with B
A Sea Change to Crypto Hits America, Again
A Sea Change to Crypto Hits America, Again A sea change is coming to cryptocurrency in America. It is likely to hit in two separate waves: a central bank digital currency (CBDC)
South Africa’s Digital Bank Tyme Completes Series B Round With Additional $70M Capital Raise
South Africa"s Digital Bank Tyme Completes Series B Round With Additional $70M Capital Raise Tymebank, a South Africa-based digital bank, recently completed its Series B funding ro
Elon Musk’s $258 Billion Dogecoin Lawsuit Grows as New Defendants, DOGE Investors Join
Elon Musk"s $258 Billion Dogecoin Lawsuit Grows as New Defendants, DOGE Investors Join The $258 billion lawsuit filed against Elon Musk, Tesla, and Spacex over their dogecoin promo