Fun

News Feed - 2023-08-10 10:08:59

Tom Mitchelhill7 hours agoFireblocks discloses massive vulnerability affecting crypto walletsFireblocks said the vulnerabilities affecting Coinbase, Binance and Zengo have since been fixed and has reached out to more than 12 others still at risk.2329 Total views14 Total sharesListen to article 0:00NewsJoin us on social networksOver 15 widely-used crypto wallet providers and projects have gaping vulnerabilities that could potentially see millions of crypto wallets drained, according to digital asset infrastructure firm Fireblocks.


In an Aug. 9 press release, Fireblocks said the series of vulnerabilities, dubbed BitForge, are affecting wallets using multi-party computation (MPC) technology, which allows for multiple parties to control and manage cryptocurrency holdings.1/ The Fireblocks research team has uncovered BitForge, a set of vulnerabilities in some of the most widely adopted MPC protocols, that allow an attacker to retrieve a private key from a single device. Read on → https://t.co/xo2r9zgCvj pic.twitter.com/7q1nEeVBwO— Fireblocks (@FireblocksHQ) August 9, 2023


The identified issues were disclosed as “zero day” vulnerabilities — meaning that the flaws had not previously been identified by the projects.“If left unremediated, the exposures would allow attackers and malicious insiders to drain funds from the wallets of millions of retail and institutional customers in seconds, with no knowledge to the user or vendor.”


The firm disclosed that the BitForge vulnerabilities affected many of the top wallet providers, including Coinbase, Zengo and Binance. Following an industry-standard “90 day disclosure period” from Fireblocks, the three firms have since resolved the identified issues.


In a statement, Coinbase’s chief information security officer, Jeff Lunglhofer, thanked Fireblocks for identifying and responsibly disclosing the issue, adding that Coinbase customers and funds were never at risk. Zengo Chief Technology Officer Tal Be"ery noted that the issue was promptly fixed and no user funds were affected.3/ We want to extend our gratitude to the researchers at Fireblocks for identifying this issue, conducting an ethical disclosure, and helping to improve the security of the ecosystem.— Coinbase Cloud ️ (@CoinbaseCloud) August 9, 2023


Fireblocks said it has worked to identify other firms that may be implicated in similar security concerns and have reached out to them.


MPC wallets encrypt a user’s private key and share it between several parties — typically comprised of the wallet owner, a wallet provider, and another third party. Theoretically, no one of these entities should be able to unlock the wallet without first communicating with the others.


Related:Tel Aviv Stock Exchange to offer crypto services via Fireblocks pact


However, according to Fireblocks’ technical reports on the BitForge vulnerabilities, the vulnerabilities would have allowed hackers to “extract the full private key if they were able to compromise only one device.”


“While we are encouraged to see that MPC is now ubiquitous within the digital asset industry, it is evident from our findings — and our subsequent disclosure process — that not all MPC developers and teams are created equal,” said Fireblocks’ chief technology officer and co-founder, Pavel Berengoltz.


“Companies leveraging Web3 technology should work closely with security experts with the know-how and resources to stay ahead of and mitigate vulnerabilities,” he added.


Deposit risk: What do crypto exchanges really do with your money?# Blockchain# Coinbase# Business# Wallet# Cryptocurrency Exchange# Hot wallet# BinanceAdd reactionAdd reactionRelated NewsHow to use index funds and ETFs for passive crypto incomeEnsuring integrity of blockchain transactions: Trust through auditsWhat will Bitcoin do if the Justice Department takes aim at Binance?Binance Blockchain Week picks Turkey to host thousands of Web3 loversKuCoin denies mass layoffs, says cuts are part of normal operationsBinance starts BTC/FDUSD and ETH/FDUSD trading pairs with zero-fees

News Feed

Gracy Chen7 hours agoOpinion: Bitget acted ethically on crypto influencer’s accountBitget managing director Gracy Chen argues her exchange had a duty to act when a crypto influencer began selling his holdings in a proj
China’s Inner Mongolia Plans to Shut Down Bitcoin Mining Operations by April This Year
China"s Inner Mongolia Plans to Shut Down Bitcoin Mining Operations by April This Year Inner Mongolia, an autonomous region in northern China, is planning to shu
Bank of Russia to Collect Data on Crypto-Related Transactions Between Individuals
Bank of Russia to Collect Data on Crypto-Related Transactions Between Individuals The Central Bank of Russia (CBR) plans to obtain information from commercial banks pertaining to s
DOJ recommends harsher sentences AI-enhanced crimes
Tristan Greene2 hours agoDOJ recommends harsher sentences AI-enhanced crimesUsing AI to plan, commit, or help cover up a plan could lead to harsher sentencing in the US soon.649 Total views1 Total sharesListen to article
Germany’s Biggest TV Channel Features Ripple, XRP On Air
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
How NFTs and the Metaverse Can Help Save the Planet
How NFTs and the Metaverse Can Help Save the Planet The head of a leading South Korean cryptocurrency exchange has recently promised that its non-fungible tokens featuring the worl
Amaka Nwaokocha13 hours agoAdobe, IBM, Nvidia join US President Biden’s efforts to prevent AI misuseAdobe, IBM, Nvidia and five other companies have joined the initiative, unveiled in July, aimed at preventing the misu
ETH 2.0 Scheduled for December, Vitalik Deposits $1.4M Worth of Ether Into Phase 0 Contract
ETH 2.0 Scheduled for December, Vitalik Deposits $1.4M Worth of Ether Into Phase 0 Contract This December the cryptocurrency community may see the first introduc
Core Scientific drops 10% after $400 million convertible senior note offer
Stephen Katte3 hours agoCore Scientific drops 10% after $400 million convertible senior note offerCore Scientific stock has dropped to $8.46 per share on the Nasdaq following an announcement of offering convertible senio
Exploring the CropBytes Metaverse: A Futuristic Crypto Game With Real Economics and Immersive Graphics
Exploring the CropBytes Metaverse: A Futuristic Crypto Game With Real Economics and Immersive Graphics On January 20th, CropBytes, the four-year-old metaverse farming game, is laun
Base TVL doubles in a month as pundits tip memecoins to drive adoption
Brayden Lindrea7 hours agoBase TVL doubles in a month as pundits tip memecoins to drive adoptionIt took 203 days for Coinbase"s Base network to notch $1 billion in total value locked but only 25 days to reach $2 billion.
NFT Digital Art That Changes With Bitcoin Price Volatility Sold for Record $101,000
NFT Digital Art That Changes With Bitcoin Price Volatility Sold for Record $101,000Matt Kane’s “Right Place & Right Time,” a non-fungible token (NFT) digital artwo