Fun

News Feed - 2023-08-11 03:08:00

Tom Blackstone5 hours agoNewly discovered Bitcoin wallet loophole let hackers steal $900K — SlowMistA series of attacks drained the wallets of BTC users by exploiting a faulty random seed generation algorithm.2038 Total views9 Total sharesListen to article 0:00NewsJoin us on social networksA newly discovered vulnerability in the Libbitcoin Explorer 3.x library has allowed over $900,000 to be stolen from Bitcoin users, according to a report from blockchain security firm SlowMist. The vulnerability can also affect users of Ethereum, Ripple, Dogecoin, Solana, Litecoin, Bitcoin Cash and Zcash who use Libbitcoin to generate accounts.SlowMist Security Alert

Recently, #Distrust discovered a severe vulnerability affecting cryptocurrency wallets using the #Libbitcoin Explorer 3.x versions. This vulnerability allows attackers to access wallet private keys by exploiting the Mersenne Twister pseudo-random…— SlowMist (@SlowMist_Team) August 10, 2023


Libbitcoin is a Bitcoin wallet implementation that developers and validators sometimes use to create Bitcoin (BTC) and other cryptocurrency accounts. According to its official website, it is used by “Airbitz (mobile wallet), Bitprim (developer interface), Blockchain Commons (decentralized wallet identity), Cancoin (decentralized exchange)” and other applications. SlowMist did not specify which applications that use Libbitcoin, if any, are affected by the vulnerability.


SlowMist identified cybersecurity team “Distrust" as the team that originally discovered the loophole, which is called the “Milk Sad” vulnerability. It was reported to the CEV cybersecurity vulnerability database on Aug. 7.


According to the post, the Libbitcoin Explorer has a faulty key generation mechanism, allowing private keys to be guessed by attackers. As a result, attackers exploited this vulnerability to steal over $900,000 worth of crypto as of Aug. 10.


SlowMist emphasized that one attack in particular siphoned away over 9.7441 BTC (approximately $278,318). The firm claims to have “blocked” the address, implying that the team has contacted exchanges to prevent the attacker from cashing out the funds. The team also stated that it will be monitoring the address in case funds are moved elsewhere.


Four members of the Distrust team, along with eight freelance security consultants who claim to have helped discover the vulnerability, have set up an informational website explaining the vulnerability. They explained that the loophole is created when users employ the “bx seed” command to generate a wallet seed. This command “uses the Mersenne Twister pseudorandom number generator (PRNG) initialized with 32 bits of system time,” which lacks sufficient randomness and therefore sometimes produces the same seed for multiple persons.Bx seed command producing the same seed twice. Source: Milk Sad information site


The researchers claim to have discovered the vulnerability when they were contacted by a Libbitcoin user whose BTC had mysteriously gone missing on July 21. When the user reached out to other Libbitcoin users to try to determine how the BTC could have gone missing, the person found that other users were also having their BTC siphoned away.


Cointelegraph reached out to Libbitcoin Institute member Eric Voskuil for comment. In response, Voskuil stated that the bx seed command "is provided as a convenience for when the tool is used to demonstrate behavior that requires entropy" and is not intended to be used in production wallets. "If people did in fact use it for production key seeding (as opposed to rolling dice for example) then the warning is insufficient," Voskuil stated. In that case, "We"ll likely make some change within the next few days to strengthen the warning against production use, or remove the command altogether."


Wallet vulnerabilities continue to pose a problem for crypto users in 2023. Over $100 million was lost in a hack of the Atomic Wallet in June, which was acknowledged by the app’s team on June 22. Cybersecurity certification platform CER released its wallet security rankings in July, noting that only six out of 45 wallet brands employ penetration testing to discover vulnerabilities.


Update (Aug. 10 20:51 UTC): This article has been updated to include a comment from Eric Voskuil.# Bitcoin# Blockchain# Bitcoin Wallet# Wallet# Mobile Wallet# Hot walletAdd reactionAdd reactionRelated NewsHow to send and receive payments on the Lightning NetworkBlackRock’s misguided effort to create ‘Crypto for Dummies’What will Bitcoin do if the Justice Department takes aim at Binance?

News Feed

Earn by Holding USDCoin in V2 of the BlockBank Application
Earn by Holding USDCoin in V2 of the BlockBank Application sponsored BlockBank will be enabling its users to earn interest on the stablecoin USD Coin (USDC), with rates up to 60x th
Bitcoin Could Crash To $70,000, Warn Leading Financial Analysts
Este artículo también está disponible en español. The recent rejection at the $100,000 has prompted a wave of warnings from leading financial analysts, who caution that B
ZkSync hit with claims of ‘almost no Sybil filtering’ in slated token airdrop
Jesse Coghlan1 hour agoZkSync hit with claims of ‘almost no Sybil filtering’ in slated token airdropMudit Gupta from zkSync rival Polygon said the ZK token airdrop could be the most “farmed airdrop ever,” claimin
Defi Index CVX Measures Crypto ‘Market Fear’ and Implied Volatility
Defi Index CVX Measures Crypto "Market Fear" and Implied Volatility The decentralized finance (defi) platform cvx.finance has launched the beta version of its &l
William Suberg13 hours agoHow low can the Bitcoin price go?Bitcoin is down to one-month lows, and BTC price predictions are tending to assume worse is to come — how much lower can bears manage?57911 Total views155 Tota
Lil Pump and dump: Rapper tattoos ‘Solana’ on forehead after selling SOL tokens
Ezra Reguerra14 hours agoLil Pump and dump: Rapper tattoos ‘Solana’ on forehead after selling SOL tokensLil Pump’s new Solana tattoo sparked mixed reactions from fans and the crypto community, with some criticizing
Is GameFi subject to the same market forces as the traditional game industry?
Stephen Katte9 hours agoIs GameFi subject to the same market forces as the traditional game industry?Web3 and Web2 games differ in several key areas, but the market forces that govern their success might be the same.260
Ethereum’s Transition to Proof-of-Stake Yields Deflationary Results
Ethereum"s Transition to Proof-of-Stake Yields Deflationary Results After the transition from proof-of-work (PoW) to proof-of-stake (PoS), Ethereum’s annual issuance rate ha
Report: Japanese Carmakers Toyota and Nissan Enter the Metaverse
Report: Japanese Carmakers Toyota and Nissan Enter the Metaverse Two Japanese carmakers, Nissan and Toyota, have launched operations in the metaverse. Nissan’s virtual showr
Earn Yield Farming Rewards with DeFi Yield Protocol (DYP)
Earn Yield Farming Rewards with DeFi Yield Protocol (DYP) PRESS RELEASE. DeFi Yield Protocol (DYP) is a decentralized yield farming platform that allows liquidit
SuperRare Expands into Bitcoin Ordinals, Unveils 'No Brainers' NFT Collection
Ezra Reguerra13 minutes agoSuperRare Expands into Bitcoin Ordinals, Unveils "No Brainers" NFT CollectionSuperRare Labs" Zack Yanger said being able to help artists connect with a new class of collectors is “a massive w
ETH Volumes Top $119.5 Billion in Q3: High-Risk Dapps Dominate Tron Network
ETH Volumes Top $119.5 Billion in Q3: High-Risk Dapps Dominate Tron NetworkA recent report says total Dapps transaction volumes reached $125 Billion in Q3 2020, a figure which is $1