By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
AmextaFinanceAmextaFinance
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
AmextaFinanceAmextaFinance
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
AmextaFinance > Markets > Crypto > Fireblocks Uncovers ‘BitForge’ Vulnerabilities Posing Threat to Major MPC Wallets
Crypto

Fireblocks Uncovers ‘BitForge’ Vulnerabilities Posing Threat to Major MPC Wallets

News Room
Last updated: 2023/08/10 at 6:58 PM
By News Room
Share
3 Min Read
SHARE

Crypto infrastructure company Fireblocks has identified a set of vulnerabilities known as “BitForge” that pose a threat to popular crypto wallets that use multi-party computation (MPC) technology. 

These vulnerabilities were classified as “zero-day,” meaning they were unknown to the developers of the affected software before Fireblocks disclosed them, the company said in a Wednesday press release. 

Major companies such as Coinbase, ZenGo, and Binance have worked with Fireblocks to address the vulnerabilities and prevent potential exploits. 

In the announcement, Fireblocks said the attackers could have used the vulnerabilities to drain funds from the wallets of “millions of retail and institutional customers in seconds, with no knowledge to the user or vendor.”

Generally, to exploit these vulnerabilities, an attacker would need to compromise a wallet user’s device or break into the internal systems of the wallet service or a third-party custodian with access to a piece of the encrypted private key. 

The specific steps depended on the wallet being used.

Fireblocks has also identified other teams that might be impacted and has reached out to them through the industry-standard 90-day responsible disclosure process.

Fireblocks CEO Michael Shaulov said that although the vulnerabilities could have been exploited, the complexity of the attacks made it unlikely that they were discovered by malicious actors before Fireblocks disclosed them.

BitForge Vulnerability Undermines Security of MPC Wallets

While the vulnerabilities may have been patched in major wallets, the incident raises concerns about the safety of supposedly ultra-safe multi-party computation (MPC) wallets. 

MPC technology in crypto wallets was designed to eliminate single points of failure by splitting a user’s private key across multiple parties, such as the wallet user, the wallet provider, and a trusted third party. 

No single entity can unlock the wallet without assistance from the others. 

However, the BitForge vulnerabilities would have allowed a hacker to extract the full private key if they compromised just one device, undermining the multi-party aspect of MPC.

Coinbase stated that its user-facing wallet service, Coinbase Wallet, was not affected, but its Wallet-as-a-Service (WaaS) offering was technically vulnerable before the company implemented a fix. 

Coinbase claimed that the vulnerabilities discovered by Fireblocks would have been extremely difficult to exploit in its case, as it would require a malicious server within Coinbase’s infrastructure to trick users into initiating numerous authenticated signing requests.

“While Coinbase customers and funds were never at risk, maintaining a fully trustless cryptographic model is an important aspect of any MPC implementation,” Jeff Lunglhofer, chief information security officer at Coinbase, said. 

Likewise, Binance CEO Changpeng Zhao has revealed that the issue “was present in the TSS Library Binance open-sourced,” which has been fixed. 

 



Read the full article here

News Room August 10, 2023 August 10, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Comparing VDE With XLE In A Sideways Range For Crude Oil (NYSEARCA:VDE)

This article was written byFollowAndrew Hecht is a 35-year Wall Street veteran…

Inside Intel’s new Arizona fab, where the chipmaker’s fate hangs in the balance

Watch full video on YouTube

3 elements of an AI bubble. 🗯️

Watch full video on YouTube

Poland races to build bomb shelters

Unlock the Editor’s Digest for freeRoula Khalaf, Editor of the FT, selects…

How Gen Z Is Reviving Legacy Brands

Watch full video on YouTube

- Advertisement -
Ad imageAd image

You Might Also Like

Crypto

'Fundamental Shift' in Traditional Bitcoin Market Cycle May Be on the Horizon

By News Room
Crypto

FTX/Alameda Unstakes Over $1B in Solana – Is a Major Price Shift Coming?

By News Room
Crypto

Man Utd launch Player Trading Cards digital collectibles and Fantasy United game | 31 July 2024

By News Room
Crypto

Solana Meme Coin Prices Surge – Sealana Raises Over 3 Million

By News Room
Crypto

Can New AI Meme Coin Oracle Meme Surge Like Pepe?

By News Room
Crypto

The Next 100X AI Crypto?

By News Room
Crypto

Argentinian Regulators Talk Bitcoin with El Salvador Authorities

By News Room
Crypto

BitGo’s $100M Suit Against Galaxy Gets Green Light from Delaware Supreme Court

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

YOUR EMAIL HAS BEEN CONFIRMED.
THANK YOU!

Welcome Back!

Sign in to your account

Lost your password?