Fun

‘Dark Skippy’ method can steal Bitcoin hardware wallet keys

News Feed - 2024-08-09 07:08:05

Christopher Roark1 hour ago‘Dark Skippy’ method can steal Bitcoin hardware wallet keysMalicious firmware can embed secret data into a public Bitcoin transaction, which the attacker can then use to extract a person’s seed words.1824 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onSecurity researchers have discovered a troubling new method that hackers can use to extract private keys from a Bitcoin hardware wallet even with only signed two transactions, which they’ve named “Dark Skippy.”


The vulnerability potentially affects all hardware wallet models — though it can only wor if the attacker tricks the victim into downloading malicious firmware.


A previous version of the method required the victim to post “dozens” of transactions to the blockchain. But the new “Dark Skippy” version can be performed even if the victim only posts a couple of transactions to the blockchain. In addition, the attack can be executed even if the user relies on a separate device to generate seed words.


The disclosure report was published by Lloyd Fournier, Nick Farrow, and Robin Linus on Aug. 5. Fournier and Farrow are co-founders of hardware wallet manufacturer Frostsnap, while Linus is a co-developer of Bitcoin protocols ZeroSync and BitVM.Source: Nick Farrow.


According to the report, a hardware wallet’s firmware can be programmed to embed portions of the user’s seed words into “low entropy secret nonces” which are then used to sign transactions. The resulting signatures get posted to the blockchain when transactions are confirmed. The attacker can then scan the blockchain to find and record these signatures.


The resulting signatures contain only “public nonces,” not the portions of seed words themselves. However, the attacker can enter these public nonces into Pollard’s Kangaroo Algorithm to successfully compute the secret nonces from their public versions.


Pollard’s Kangaroo Algorithm, discovered by mathematician John M. Pollard, is an algorithm in computational algebra that can be used to solve the discrete logarithm problem.


According to the researchers, a user’s full set of seed words can be derived using this method, even if the user only produces two signatures from their compromised device and even if the seed words were produced on a separate device.


Related:Major Wallet Vulnerability Revealed As User Barely Reclaims 9 BTC


Previous versions of the vulnerability have been documented in the past, the researchers stated. However, these older versions relied upon “nonce grinding,” a much slower process that required many more transactions to be posted to the blockchain. Even so, the researchers stopped short of calling Dark Skippy a new vulnerability, claiming instead that it is “a new way of exploiting an existing vulnerability.”


To mitigate against the threat, the report suggests that hardware wallet manufacturers should take extra care to prevent malicious firmware from getting into users’ devices, which they can do through features like “secure boot and locked JTAG/SWD interfaces […] reproducible and vendor signed firmware builds[,...] [and] various other security features.” In addition, it suggests that wallet owners may want to employ practices to keep their devices secure, including “secret places, personal safes, or maybe even tamper-evident bags,” although the report also suggests that these practices may be “cumbersome.”Dark Skippy mitigation techniques. Source: Dark Skippy researchers.


Another suggestion it provides is for wallet software to use “anti-exfiltration” signing protocols, which prevent the hardware wallet from producing nonces on its own.


Bitcoin wallet vulnerabilities have caused significant losses to users in the past. In August, 2023, cybersecurity firm Slowmist reported that over $900,000 worth of Bitcoin had been stolen via a flaw in the Libbitcoin explorer library. In November, Unciphered reported that $2.1 billion worth of Bitcoin held in old wallets may be in danger of being drained by attackers because of a flaw in BitcoinJS wallet software.


Magazine: ‘Elon Musk at Bitcoin 2024’ scam, Lazarus Group hacks, MOG phishing: Crypto-Sec# Bitcoin# Blockchain# Cybersecurity# HacksAdd reaction

News Feed

Blockchain Gaming Publisher Animoca Brands Secures $75M — Firm’s Pre-Money Valuation Rises to $5.9B
Blockchain Gaming Publisher Animoca Brands Secures $75M — Firm"s Pre-Money Valuation Rises to $5.9B The non-fungible token and blockchain gaming company Animoca Brands has announ
Martin Young3 hours agoCoinbase futures approval seen as a major win amid the war on cryptoThe recent approval allows Coinbase to join the ranks of the two major derivative exchanges in the United States, CME and CBOE.40
Shiba Inu Price Gearing Up To Fly After Lows, Here’s The Target
Este artículo también está disponible en español. Recent technical analysis suggests that the Shiba Inu price may be preparing for a bullish rally, as the second-largest
Biggest Movers: ADA Hits Fresh Record Low, BNB Down for Seventh Straight Day
Biggest Movers: ADA Hits Fresh Record Low, BNB Down for Seventh Straight Day Cardano fell to a fresh all-time low on Saturday, as prices plunged by over 10% to start the weekend. T
ChatGPT launches AI-powered search engine prototype
Turner Wright4 hours agoChatGPT launches AI-powered search engine prototypeAccording to OpenAI, SearchGPT will give users a more intuitive search experience, allowing them to ask questions to refine a search as they woul
Bitcoin, Ethereum Technical Analysis: BTC Back Above $23,000 Following Tesla Q4 Earnings Report
Bitcoin, Ethereum Technical Analysis: BTC Back Above $23,000 Following Tesla Q4 Earnings Report Bitcoin rallied back above $23,000 on Thursday, following the release of Teslaȁ
Binance tax evasion trial moved to May 17 in Nigeria
Amaka Nwaokocha11 hours agoBinance tax evasion trial moved to May 17 in NigeriaGambaryan’s lawyer, Chukwuka Ikuazom, objected, citing Nigerian law, stating he couldn’t plead until Binance, the primary defendant, was
Why Ethereum Is A Must-Watch: Expert Analysis Highlights 4 Strong Bullish Indicators
Este artículo también está disponible en español. As the new week begins, Ethereum (ETH)—the second-largest cryptocurrency by market capitalization—has seen a signifi
Robinhood Discusses Crypto Wallet Launch and Listing Strategy as Petition to List Shiba Inu Exceeds 526K Signers
Robinhood Discusses Crypto Wallet Launch and Listing Strategy as Petition to List Shiba Inu Exceeds 526K Signers The chief operating officer (COO) of Robinhood Crypto has provided
$500B plunge: Largest 3-day wipeout for crypto in a year
Tom Mitchelhill8 hours ago$500B plunge: Largest 3-day wipeout for crypto in a yearThe crypto market has just witnessed its largest three-day sell-off in 12 months amid weak jobs data in the US and revived fears of a rece
The Bitcoin Cash Network’s Block Reward Officially Halved – Block 630,000 Mined
The Bitcoin Cash Network"s Block Reward Officially Halved - Block 630,000 Mined On April 8, 2020, the Bitcoin Cash network’s block reward halved as of block 630,000 and BCH
Egypt’s Central Bank Issues Crypto Warning — Violators Risk Imprisonment
Egypt"s Central Bank Issues Crypto Warning — Violators Risk Imprisonment The Central Bank of Egypt (CBE) has issued a fresh warning about cryptocurrency, noting that violators co