‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

TL;DR Breakdown

  • Fireblocks identified “BitForge” vulnerabilities in over 15 major cryptocurrency wallets, highlighting potential risks to user funds on platforms like Coinbase and Binance.
  • The BitForge flaws target security methods called MPCs, allowing faster unauthorized access to secured assets if exploited.
  • Despite the challenges posed by BitForge, industry giants like Coinbase promptly addressed the concerns, showcasing the crypto-sector’s commitment to user security.

Description

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight. Cybersecurity company Fireblocks presented its findings at the Black Hat … Read more

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight.

Cybersecurity company Fireblocks presented its findings at the Black Hat USA conference, disclosing that over 15 predominant cryptocurrency wallets, making up over 80% of the market, were affected. These vulnerabilities could have easily been harnessed to compromise user funds on celebrated exchanges, including Binance and Coinbase.

These security flaws primarily targeted multiparty computation protocols (MPCs). MPCs typically fracture private keys into multiple fragments, dispersed over different devices. This method should ideally bolster security. However, it was discovered that certain implementations of MPCs made it feasible for malicious actors to access the full key after merely 16 transactions. Such rapid-fire transactions could occur within seconds on high-frequency wallets.

Fireblocks’ CEO, Michael Shaulov, explained the simplicity of exploiting these vulnerabilities. He remarked, “The BitForge vulnerabilities operate in line with common cyber-attack mechanisms. A single compromised user through malware is all that’s needed.” This underscores the ever-present threat of malware, often delivered via phishing scams designed to deceive users into downloading malevolent software or revealing sensitive data.

This vulnerability’s disclosure comes amidst a mixed landscape of crypto crimes. While the overall figure was down 65% to $3.3 billion in H1 2023 from 2022, ransomware attacks – malicious software that encrypts a victim’s files and demands payment for their release, typically in cryptocurrency – are rising sharply. These are predicted to nearly touch $900 million this year, only slightly behind 2021’s $940 million.

The international community and regulatory bodies have long been apprehensive about cybersecurity linked to digital assets. Given the burgeoning incidents of cryptocurrency thefts, many governments are ramping up efforts to integrate digital assets and their providers within a regulatory framework. As an illustration, Hong Kong’s Securities and Futures Commission (SFC) now necessitates cryptocurrency exchanges operating within its jurisdiction to acquire a license. This move seeks to impose benchmarks in cybersecurity, private key management, and other areas.

However, uncertainties remain. While Fireblocks has pinpointed vulnerabilities in a significant number of wallet providers, determining the exact number affected by these flawed MPC implementations remains elusive.

A deep dive into BitForge

Fireblocks’ research pinpointed vulnerabilities in implementations of certain multi-party computation (MPC) protocols, specifically GG-18, GG-20, and Lindell17. These vulnerabilities were traced back to deviations from standard implementations or previous efforts to patch known flaws.

Notably, GG-18 and GG-20 protocols faced issues where earlier attempts to rectify vulnerabilities inadvertently introduced newer ones. Lindell17’s flaw, on the other hand, revolved around deviations from the original academic specifications and mishandling of failed signatures.

As a testament to industry collaboration, Fireblocks undertook a 90-day disclosure process. Their endeavors were met with a proactive response. Leading wallet providers, particularly Coinbase WaaS and Zengo, were commended for their swift action in addressing and rectifying the security flaws.

As digital currencies continue to weave themselves into the world’s financial fabric, it’s evident that maintaining cybersecurity will remain a top priority for providers and regulators alike.

文章来源于互联网:‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年8月12日 09:01
Next 2023年8月12日 10:00

Related articles

  • Uniswap impersonation scam exposes crypto community to deceptive tactics

    TL;DR Breakdown Uniswap, a decentralized exchange protocol, was targeted by an elaborate impersonation scam in China, involving a fake website and a staged video featuring individuals posing as high-ranking Uniswap executives. Uniswap’s creator, Hayden Adams, expressed surprise and disassociation from the scam, urging caution and vigilance within the cryptocurrency community. The motives behind the scam and its organization within China, where cryptocurrencies are banned, remain unclear, but it highlights the audacity of fraudulent actors and the need for thorough verification of conferences and investment opportunities. Uniswap, a leading decentralized exchange protocol, recently fell prey to a sophisticated impersonation scheme that targeted its Chinese community. Hayden Adams, the creator of Uniswap and CEO of Uniswap Labs, expressed his surprise and concern about the elaborate nature of the scam. The incident raises questions about the audacity of fraudulent actors and the need for vigilance within the cryptocurrency industry. Deceptive scheme targets Uniswap community Hayden Adams took to Twitter to express his astonishment regarding a scam involving a fake Uniswap website. The scammers created an intricate website and went to great lengths to…

    Article 2023年6月7日
  • On Fed rate hike frenzy: Is it really over?

    Description The Federal Reserve’s latest policy meeting culminates this Wednesday, with speculations aplenty about whether they’ll keep the interest rates on hold. Investors, analysts, and armchair economists globally are scurrying for hints. Is this the end of the Fed’s groundbreaking rate escalation? Or is it simply a recess in their ongoing endeavor to reshape the world’s … Read more The Federal Reserve’s latest policy meeting culminates this Wednesday, with speculations aplenty about whether they’ll keep the interest rates on hold. Investors, analysts, and armchair economists globally are scurrying for hints. Is this the end of the Fed’s groundbreaking rate escalation? Or is it simply a recess in their ongoing endeavor to reshape the world’s economic landscape? A Delicate Dance with Inflation The current scenario unfolds like a high-stakes drama. The Fed, in a calculated move, signaled that the interest rates would remain untouched during this two-day meet, hovering between 5.25 and 5.5 percent. This decision arrives on the heels of their last increase by 0.25 percentage points in July. But why the sudden halt in pace? Stepping back, it’s clear:…

    Article 2023年9月19日
  • Crypto market braces for weekend volatility with $5B BTC options set to expire

    TL;DR Breakdown Crypto markets head into the weekend on negative sentiment, with Bitcoin struggling to maintain the price above $30K. Almost $5 billion worth of Bitcoin options are scheduled to expire today, marking the largest mass expiration in months and posing a risk of market volatility. Ethereum options worth around $2.3 billion are also set to expire on June 30. Description Historically, the crypto markets have suffered from weekend volatility. This weekend is no exception. A massive amount of Bitcoin options are slated to expire today, according to crypto market analysts, marking the largest bulk expiry in months. Derivatives trading fever has recently risen in response to many ETF registrations, but will speculators get burned? Crypto … Read more Historically, the crypto markets have suffered from weekend volatility. This weekend is no exception. A massive amount of Bitcoin options are slated to expire today, according to crypto market analysts, marking the largest bulk expiry in months. Derivatives trading fever has recently risen in response to many ETF registrations, but will speculators get burned? Crypto markets head into the weekend on…

    Article 2023年7月2日
  • Cardano Foundation Disputes SEC’s Security Classification; Robinhood Considers Delisting ADA

    TL;DR Breakdown The Cardano Foundation disputes the SEC’s classification of ADA as a security, emphasizing the importance of regulatory clarity in the crypto industry. Robinhood may delist ADA and other cryptocurrencies involved in SEC lawsuits to comply with US securities laws, highlighting the ongoing regulatory challenges faced by the crypto market. The cryptocurrency market is facing regulatory hurdles and compliance concerns in the United States, particularly impacting Cardano (ADA), Solana (SOL), and Polygon (MATIC). In a recent lawsuit against Binance, the United States Securities and Exchange Commission (SEC) classified several prominent cryptocurrencies, including Cardano, as securities. However, the Cardano Foundation’s CEO disagrees with this classification, highlighting the pressing need for regulatory clarity in the crypto industry. Contents hide 1 Cardano Foundation Challenges ADA’s Security Classification 2 SEC Lawsuits and Potential Delisting on Robinhood 3 Cardano’s Journey on Robinhood and Broader Crypto Offerings 4 Conclusion Cardano Foundation Challenges ADA’s Security Classification The Cardano Foundation, an influential blockchain platform, has expressed its disagreement with the SEC’s classification of ADA as a security. Frederik Gregaard, CEO of the Cardano Foundation, has emphasized the…

    Article 2023年6月13日
  • Spot Bitcoin ETF may not stir crypto markets, says JP Morgan

    TL;DR Breakdown JPMorgan analysts argue that approval of a spot Bitcoin ETF by the U.S. Securities and Exchange Commission (SEC) won’t significantly change the crypto market landscape. Despite optimism around potential approval following recent filings by BlackRock, Invesco, and Wisdom Tree, spot Bitcoin ETFs have seen limited investor interest abroad in Canada and Europe, which could continue in the U.S. The introduction of spot Bitcoin ETFs could, however, cause a shift in trading activity and liquidity away from Bitcoin futures markets towards spot Bitcoin markets. Description Despite the buzz around a possible U.S. Securities and Exchange Commission (SEC) approval of a spot bitcoin exchange-traded fund (ETF), banking giant JPMorgan has doused the high spirits, expressing doubt in a recent research report on the game-changing potential of such a move. Limited influence despite renewed optimism While anticipation grows with asset managers like … Read more Despite the buzz around a possible U.S. Securities and Exchange Commission (SEC) approval of a spot bitcoin exchange-traded fund (ETF), banking giant JPMorgan has doused the high spirits, expressing doubt in a recent research report on…

    Article 2023年7月9日
TOP