By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > Markets > Crypto > Fireblocks Uncovers ‘BitForge’ Vulnerabilities Posing Threat to Major MPC Wallets
Crypto

Fireblocks Uncovers ‘BitForge’ Vulnerabilities Posing Threat to Major MPC Wallets

News Room
Last updated: 2023/08/10 at 6:58 PM
By News Room
Share
3 Min Read
SHARE

Crypto infrastructure company Fireblocks has identified a set of vulnerabilities known as “BitForge” that pose a threat to popular crypto wallets that use multi-party computation (MPC) technology. 

These vulnerabilities were classified as “zero-day,” meaning they were unknown to the developers of the affected software before Fireblocks disclosed them, the company said in a Wednesday press release. 

Major companies such as Coinbase, ZenGo, and Binance have worked with Fireblocks to address the vulnerabilities and prevent potential exploits. 

In the announcement, Fireblocks said the attackers could have used the vulnerabilities to drain funds from the wallets of “millions of retail and institutional customers in seconds, with no knowledge to the user or vendor.”

Generally, to exploit these vulnerabilities, an attacker would need to compromise a wallet user’s device or break into the internal systems of the wallet service or a third-party custodian with access to a piece of the encrypted private key. 

The specific steps depended on the wallet being used.

Fireblocks has also identified other teams that might be impacted and has reached out to them through the industry-standard 90-day responsible disclosure process.

Fireblocks CEO Michael Shaulov said that although the vulnerabilities could have been exploited, the complexity of the attacks made it unlikely that they were discovered by malicious actors before Fireblocks disclosed them.

BitForge Vulnerability Undermines Security of MPC Wallets

While the vulnerabilities may have been patched in major wallets, the incident raises concerns about the safety of supposedly ultra-safe multi-party computation (MPC) wallets. 

MPC technology in crypto wallets was designed to eliminate single points of failure by splitting a user’s private key across multiple parties, such as the wallet user, the wallet provider, and a trusted third party. 

No single entity can unlock the wallet without assistance from the others. 

However, the BitForge vulnerabilities would have allowed a hacker to extract the full private key if they compromised just one device, undermining the multi-party aspect of MPC.

Coinbase stated that its user-facing wallet service, Coinbase Wallet, was not affected, but its Wallet-as-a-Service (WaaS) offering was technically vulnerable before the company implemented a fix. 

Coinbase claimed that the vulnerabilities discovered by Fireblocks would have been extremely difficult to exploit in its case, as it would require a malicious server within Coinbase’s infrastructure to trick users into initiating numerous authenticated signing requests.

“While Coinbase customers and funds were never at risk, maintaining a fully trustless cryptographic model is an important aspect of any MPC implementation,” Jeff Lunglhofer, chief information security officer at Coinbase, said. 

Likewise, Binance CEO Changpeng Zhao has revealed that the issue “was present in the TSS Library Binance open-sourced,” which has been fixed. 

 



Read the full article here

News Room August 10, 2023 August 10, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Netflix earnings: What investors need to know about the streaming giant’s Q3 miss

Watch full video on YouTube

Inside Amazon’s massive Anthropic data center, training AI without Nvidia

Watch full video on YouTube

Cannabis Investing In The Trump Era

Listen here or on the go via Apple Podcasts or Spotify Josh…

The argument Iranians have in private

Unlock the Editor’s Digest for freeRoula Khalaf, Editor of the FT, selects…

Carmakers sour on EU’s ‘disastrous’ petrol engine rule changes

Stay informed with free updatesSimply sign up to the Electric vehicles myFT…

- Advertisement -
Ad imageAd image

You Might Also Like

Crypto

'Fundamental Shift' in Traditional Bitcoin Market Cycle May Be on the Horizon

By News Room
Crypto

FTX/Alameda Unstakes Over $1B in Solana – Is a Major Price Shift Coming?

By News Room
Crypto

Mastercard Launches “Crypto Credential” To Replace Wallet Addresses With Usernames

By News Room
Crypto

Polygon Executive Pivots Roles To Developing ZK Proof Tech

By News Room
Crypto

Altcoin Interest Driving South Korean Crypto Craze – Report

By News Room
Crypto

Russian Central Bank Flags Sharp Rise in Crypto-related Activity

By News Room
Crypto

BitGo’s $100M Suit Against Galaxy Gets Green Light from Delaware Supreme Court

By News Room
Crypto

Here Are Your Top Crypto Gainers Today on DEXScreener

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?