‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

TL;DR Breakdown

  • Fireblocks identified “BitForge” vulnerabilities in over 15 major cryptocurrency wallets, highlighting potential risks to user funds on platforms like Coinbase and Binance.
  • The BitForge flaws target security methods called MPCs, allowing faster unauthorized access to secured assets if exploited.
  • Despite the challenges posed by BitForge, industry giants like Coinbase promptly addressed the concerns, showcasing the crypto-sector’s commitment to user security.

Description

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight. Cybersecurity company Fireblocks presented its findings at the Black Hat … Read more

Recent revelations indicate that a host of leading cryptocurrency wallet providers were susceptible to potential security breaches. These vulnerabilities, now known as ‘BitForge’, have highlighted the inherent cyber risks in the cryptocurrency realm, even as the world grapples with increasing adoption and tighter regulatory oversight.

Cybersecurity company Fireblocks presented its findings at the Black Hat USA conference, disclosing that over 15 predominant cryptocurrency wallets, making up over 80% of the market, were affected. These vulnerabilities could have easily been harnessed to compromise user funds on celebrated exchanges, including Binance and Coinbase.

These security flaws primarily targeted multiparty computation protocols (MPCs). MPCs typically fracture private keys into multiple fragments, dispersed over different devices. This method should ideally bolster security. However, it was discovered that certain implementations of MPCs made it feasible for malicious actors to access the full key after merely 16 transactions. Such rapid-fire transactions could occur within seconds on high-frequency wallets.

Fireblocks’ CEO, Michael Shaulov, explained the simplicity of exploiting these vulnerabilities. He remarked, “The BitForge vulnerabilities operate in line with common cyber-attack mechanisms. A single compromised user through malware is all that’s needed.” This underscores the ever-present threat of malware, often delivered via phishing scams designed to deceive users into downloading malevolent software or revealing sensitive data.

This vulnerability’s disclosure comes amidst a mixed landscape of crypto crimes. While the overall figure was down 65% to $3.3 billion in H1 2023 from 2022, ransomware attacks – malicious software that encrypts a victim’s files and demands payment for their release, typically in cryptocurrency – are rising sharply. These are predicted to nearly touch $900 million this year, only slightly behind 2021’s $940 million.

The international community and regulatory bodies have long been apprehensive about cybersecurity linked to digital assets. Given the burgeoning incidents of cryptocurrency thefts, many governments are ramping up efforts to integrate digital assets and their providers within a regulatory framework. As an illustration, Hong Kong’s Securities and Futures Commission (SFC) now necessitates cryptocurrency exchanges operating within its jurisdiction to acquire a license. This move seeks to impose benchmarks in cybersecurity, private key management, and other areas.

However, uncertainties remain. While Fireblocks has pinpointed vulnerabilities in a significant number of wallet providers, determining the exact number affected by these flawed MPC implementations remains elusive.

A deep dive into BitForge

Fireblocks’ research pinpointed vulnerabilities in implementations of certain multi-party computation (MPC) protocols, specifically GG-18, GG-20, and Lindell17. These vulnerabilities were traced back to deviations from standard implementations or previous efforts to patch known flaws.

Notably, GG-18 and GG-20 protocols faced issues where earlier attempts to rectify vulnerabilities inadvertently introduced newer ones. Lindell17’s flaw, on the other hand, revolved around deviations from the original academic specifications and mishandling of failed signatures.

As a testament to industry collaboration, Fireblocks undertook a 90-day disclosure process. Their endeavors were met with a proactive response. Leading wallet providers, particularly Coinbase WaaS and Zengo, were commended for their swift action in addressing and rectifying the security flaws.

As digital currencies continue to weave themselves into the world’s financial fabric, it’s evident that maintaining cybersecurity will remain a top priority for providers and regulators alike.

文章来源于互联网:‘BitForge’ security flaw to threaten Binance, Coinbase, and other crypto exchanges 

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年8月12日 09:01
Next 2023年8月12日 10:00

Related articles

  • Why is Japan in the middle of US-China rivalry

    TL;DR Breakdown Japan is a central figure in the growing US-China rivalry. US views Japan as an indispensable partner, emphasizing shared global perspectives. Japan’s PM, Kishida, has intensified US-Japan alignment, though deeper national sentiments play a role. Description Japan, the historical titan of the East, now finds itself caught in the midst of a modern-day superpower showdown between the US and China. Both the Pacific giants view Japan as a pivotal player in their global chess match, yet Japan’s stance remains as enigmatic as ever. What’s behind this intense spotlight on Japan? Tokyo’s … Read more Japan, the historical titan of the East, now finds itself caught in the midst of a modern-day superpower showdown between the US and China. Both the Pacific giants view Japan as a pivotal player in their global chess match, yet Japan’s stance remains as enigmatic as ever. What’s behind this intense spotlight on Japan? Tokyo’s strategic alignment with Washington Historically, the US and Japan have been firm allies, tied together by mutual interests and shared visions. Yet, this alliance has never been more important…

    Article 2023年8月11日
  • Best Twitter threads of the day – June 13th

    SEC Hinman email release summary 1/25 SEC Hinman email release summary: -Not a big impact to the $XRP case.-Decently positive for $ETH.-Nuance puts Gensler in a corner. Let’s recap the Hinman speech and I’ll explain why this is damning for Gensler’s position! pic.twitter.com/Ca4ljiJYZr — Adam Cochran (adamscochran.eth) (@adamscochran) June 13, 2023 3/25 Hinman’s guidance in his speech certainly went beyond the scope of Howey by attempting to understand the nuanced intent of users vs investors – as well as trying to ask the question of ‘morphing’ this concept of can something be a security and then later not a security. — Adam Cochran (adamscochran.eth) (@adamscochran) June 13, 2023 4/25 (Which caveat, I think we can derive from Howey itself but that’s another thread) But, Hinman was so focused on this idea of “morphing” that he wanted that to be the initial name of the speech. pic.twitter.com/Ctq0Z7REz0 — Adam Cochran (adamscochran.eth) (@adamscochran) June 13, 2023 7/25 Then Hinman points out something Gensler has seemingly forgotten: “In Howey, orange groves did not become a security, even though the sale of the future…

    Article 2023年6月16日
  • PancakeSwap price analysis: CAKE slowly trends towards $1.50 resistance

    TL;DR Breakdown . PancakeSwap price touched the $1.43 mark . CAKE could rise up to $1.5 over the coming 24 hours . Uptrend potential could be invalidated if price falls below $1.3 Description PancakeSwap price analysis shows a meagre uptrend taking place, as price slowly begins to trend upwards. CAKE price reached up to the $1.43 mark over the past 24 hours, in pursuit of the $1.5 resistance. The highest point this month has been set around $1.73, on June 5, when price declined 9 percent to initiate … Read more PancakeSwap price analysis shows a meagre uptrend taking place, as price slowly begins to trend upwards. CAKE price reached up to the $1.43 mark over the past 24 hours, in pursuit of the $1.5 resistance. The highest point this month has been set around $1.73, on June 5, when price declined 9 percent to initiate the current bearish trend. Price over the past 24 hours increased around 1 percent, suggestive of a slow-burning uptrend potentially in place for CAKE. Trading volume for PancakeSwap dropped more than 20 percent over…

    Article 2023年6月21日
  • Web3 platforms gain traction amidst payment and censorship concerns for content creators

    TL;DR Breakdown Content creators are turning to Web3 platforms such as Only1 and WetSpace to avoid censorship and payment challenges faced on centralized platforms like Patreon and OnlyFans. Leon Lee, CEO of Only1, envisions a future where blockchain technology empowers creators by eliminating intermediaries, giving them direct access to their audience and complete control over their content. Description With the recent disruptions in traditional platforms like Patreon and OnlyFans, creators are now turning to Web3 for greater autonomy over their content and to evade the risk of censorship. Decentralized platforms promise not only better financial independence but also a safeguard against being arbitrarily removed from platforms due to controversial content. Contents hide 1 … Read more With the recent disruptions in traditional platforms like Patreon and OnlyFans, creators are now turning to Web3 for greater autonomy over their content and to evade the risk of censorship. Decentralized platforms promise not only better financial independence but also a safeguard against being arbitrarily removed from platforms due to controversial content. Contents hide 1 Power shift from intermediaries to content creators 2 Crypto:…

    Article 2023年9月21日
  • Meta slapped with massive $1.3B fine for EU-U.S. data transfers

    TL;DR Breakdown Meta faces a record €1.2 billion ($1.3 billion) fine by EU privacy regulators for user data transfer to the U.S. The decision follows a case arguing that the transfer framework doesn’t protect Europeans from U.S. surveillance. The company is directed to stop future data transfers to the U.S. within five months, but the company plans to appeal. In a landmark development, Meta, the global social media giant, has been dealt a record €1.2 billion ($1.3 billion) blow by European privacy regulators. This ruling is directly linked to the transfer of EU user data to the U.S., a topic that has been a long-standing bone of contention. Dissecting the EU’s unprecedented penalty This monumental decision stems from a case brought forward by Austrian privacy campaigner Max Schrems. He proposed that the existing mechanism for data transfer from the EU to the U.S. failed to adequately safeguard Europeans against American surveillance. Following the argument, numerous mechanisms that facilitated legal transfer of personal data between the U.S. and the EU have come under scrutiny. Privacy Shield, the latest of such mechanisms,…

    Article 2023年5月24日
TOP