‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

TL;DR Breakdown

  • Fireblocks identified “BitForge” vulnerabilities in over 15 major cryptocurrency wallets, highlighting potential risks to user funds on platforms like Coinbase and Binance.
  • The BitForge flaws target security methods called MPCs, allowing faster unauthorized access to secured assets if exploited.
  • Despite the challenges posed by BitForge, industry giants like Coinbase promptly addressed the concerns, showcasing the crypto-sector’s commitment to user security.

Description

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight. Cybersecurity company Fireblocks presented its findings at the Black Hat … Read more

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight.

Cybersecurity company Fireblocks presented its findings at the Black Hat USA conference, disclosing that over 15 predominant cryptocurrency wallets, making up over 80% of the market, were affected. These vulnerabilities could have easily been harnessed to compromise user funds on celebrated exchanges, including Binance and Coinbase.

These security flaws primarily targeted multiparty computation protocols (MPCs). MPCs typically fracture private keys into multiple fragments, dispersed over different devices. This method should ideally bolster security. However, it was discovered that certain implementations of MPCs made it feasible for malicious actors to access the full key after merely 16 transactions. Such rapid-fire transactions could occur within seconds on high-frequency wallets.

Fireblocks’ CEO, Michael Shaulov, explained the simplicity of exploiting these vulnerabilities. He remarked, “The BitForge vulnerabilities operate in line with common cyber-attack mechanisms. A single compromised user through malware is all that’s needed.” This underscores the ever-present threat of malware, often delivered via phishing scams designed to deceive users into downloading malevolent software or revealing sensitive data.

This vulnerability’s disclosure comes amidst a mixed landscape of crypto crimes. While the overall figure was down 65% to $3.3 billion in H1 2023 from 2022, ransomware attacks – malicious software that encrypts a victim’s files and demands payment for their release, typically in cryptocurrency – are rising sharply. These are predicted to nearly touch $900 million this year, only slightly behind 2021’s $940 million.

The international community and regulatory bodies have long been apprehensive about cybersecurity linked to digital assets. Given the burgeoning incidents of cryptocurrency thefts, many governments are ramping up efforts to integrate digital assets and their providers within a regulatory framework. As an illustration, Hong Kong’s Securities and Futures Commission (SFC) now necessitates cryptocurrency exchanges operating within its jurisdiction to acquire a license. This move seeks to impose benchmarks in cybersecurity, private key management, and other areas.

However, uncertainties remain. While Fireblocks has pinpointed vulnerabilities in a significant number of wallet providers, determining the exact number affected by these flawed MPC implementations remains elusive.

A deep dive into BitForge

Fireblocks’ research pinpointed vulnerabilities in implementations of certain multi-party computation (MPC) protocols, specifically GG-18, GG-20, and Lindell17. These vulnerabilities were traced back to deviations from standard implementations or previous efforts to patch known flaws.

Notably, GG-18 and GG-20 protocols faced issues where earlier attempts to rectify vulnerabilities inadvertently introduced newer ones. Lindell17’s flaw, on the other hand, revolved around deviations from the original academic specifications and mishandling of failed signatures.

As a testament to industry collaboration, Fireblocks undertook a 90-day disclosure process. Their endeavors were met with a proactive response. Leading wallet providers, particularly Coinbase WaaS and Zengo, were commended for their swift action in addressing and rectifying the security flaws.

As digital currencies continue to weave themselves into the world’s financial fabric, it’s evident that maintaining cybersecurity will remain a top priority for providers and regulators alike.

文章来源于互联网:‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年8月12日 09:01
Next 2023年8月12日 10:00

Related articles

  • Binance Faces Regulatory Heat: Investigation by Canadian Securities Regulator Unveiled

    TL;DR Breakdown Canadian Securities Regulator Investigation: Binance has received an investigation order from the Ontario Securities Commission (OSC), probing whether the exchange attempted to circumvent local regulations. Binance Withdraws from Canadian Market: Following the OSC’s investigation order, Binance announced its withdrawal from the Canadian market. Binance Holdings Ltd, the world’s largest digital asset exchange, has recently disclosed that it is under investigation by the Ontario Securities Commission (OSC), one of Canada’s securities regulators. The OSC has ordered an investigation into whether Binance attempted to bypass local regulations and compliance controls while seeking approvals in Canada. This development follows Binance’s withdrawal from the Canadian market, citing new regulatory guidance related to stablecoins and investor limits.  The investigation order from the OSC grants broad authority to examine Binance’s compliance with Ontario securities law and its overall conduct. Binance has faced increasing regulatory scrutiny in multiple jurisdictions in recent years, and this investigation adds to the growing legal challenges it is facing. Contents hide 1 OSC Investigation Order and Binance’s Withdrawal from the Canadian Market 2 OSC’s Investigation and Binance’s Response 3 Implications…

    Article 2023年6月5日
  • What to know about DBS’ digital yuan payment solution

    TL;DR Breakdown DBS launches an e-CNY merchant collection solution, marking a significant innovation in digital currency transactions in China. The solution allows businesses to collect payments in e-CNY, China’s central bank digital currency, enhancing transaction efficiency. Description In the intricate weave of today’s global finance, DBS, one of Singapore’s most influential banks, is pioneering innovative solutions for the rapidly emerging digital currency market. In particular, the bank’s recent launch of an e-CNY merchant collection solution in China, marking one of the first foreign bank endeavors in this arena, is a significant step … Read more In the intricate weave of today’s global finance, DBS, one of Singapore’s most influential banks, is pioneering innovative solutions for the rapidly emerging digital currency market. In particular, the bank’s recent launch of an e-CNY merchant collection solution in China, marking one of the first foreign bank endeavors in this arena, is a significant step forward. This new addition to the digital banking landscape empowers corporate clients to collect and reconcile payments in e-CNY, China’s central bank digital currency (CBDC), efficiently and effectively. A revolutionary…

    Article 2023年7月7日
  • Adidas x Fewocious collabo set to shake the NFT market

    TL;DR Breakdown Adidas, the global apparel giant, has joined forces with renowned digital artist Fewocious on an exciting collaboration that combines physical sneakers with NFT technology.  The release of the Trefoil Flower NFT will follow a three-tier pre-sale, followed by a public mint. Fewocious, also known as Victor Langlois, is a 20-year-old transgender artist who has gained significant recognition in the NFT space. Adidas, the global apparel giant, has joined forces with renowned digital artist Fewocious on an exciting collaboration that combines physical sneakers with NFT technology. The collaboration aims to explore the “art of play” and will feature 4,500 editions of an NFT mint pass named “Trefoil Flower.” These passes will be exclusively available for purchase on the OpenSea marketplace starting from June 22. Step into The Art of Play with @FEWOCiOUS as we explore the possibilities of a world where art imitates life and life imitates art, blurring the physical and virtual landscape of the Campus 00s.​​Coming June 22 👉 https://t.co/ZPnRLB2Mmh pic.twitter.com/QS9TkKy9Hd — adidas Originals (@adidasoriginals) June 13, 2023 The Trefoil Flower NFT mint pass serves as a unique…

    Article 2023年6月17日
  • Fei Labs denies discord seizure amid class-action lawsuit

    TL;DR Breakdown The legal representative of Fei Labs has cleared the air after rumors of its discord seizure surfaced on Twitter. Class-action lawsuit reaches preliminary settlement stage. Description In recent developments surrounding the ongoing class action lawsuit against DeFi project Fei Labs, new information has emerged regarding the widely reported seizure of the platform’s Discord server. Contrary to previous reports, it has now been clarified that the notice posted on the server was not a result of authorities seizing control. Instead, the purpose … Read more In recent developments surrounding the ongoing class action lawsuit against DeFi project Fei Labs, new information has emerged regarding the widely reported seizure of the platform’s Discord server. Contrary to previous reports, it has now been clarified that the notice posted on the server was not a result of authorities seizing control. Instead, the purpose of the notice was to inform investors who were negatively affected by the project’s volatile launch event two years ago. This article will delve into the details of the situation, shedding light on the Fei Labs lawsuit, the recent…

    Article 2023年7月12日
  • UK’s National Crime Agency expands crypto investigation team amid rising crypto crime

    TL;DR Breakdown The UK’s National Crime Agency (NCA) is hiring senior investigators to combat crypto-related crimes, in response to significant losses to crypto fraud in 2022. The NCA has opened multiple positions to strengthen its crypto investigation team and will collaborate with London police and other agencies. The UK is moving towards stricter crypto regulations, aligning with EU rules and public demands for greater oversight in the crypto industry. Description The United Kingdom’s National Crime Agency (NCA) is taking significant steps to combat the rise in crypto-related crimes by expanding its digital assets investigation team. The NCA is hiring four senior investigators for its Complex Financial Crime Team (CFCT) to focus on high-end crypto fraud, money laundering, and other blockchain-enabled crimes carried out by organized … Read more The United Kingdom’s National Crime Agency (NCA) is taking significant steps to combat the rise in crypto-related crimes by expanding its digital assets investigation team. The NCA is hiring four senior investigators for its Complex Financial Crime Team (CFCT) to focus on high-end crypto fraud, money laundering, and other blockchain-enabled crimes carried…

    Article 2023年8月8日
TOP