September 21, 2023 9:40 pm

Bitcoin loophole allowed hackers to steal $900K from newly found wallets: SlowMist

Facebook
Twitter
LinkedIn
Pinterest
WhatsApp
Telegram

URGENT: JUST 11 DAYS REMAIN TO HELP SAVE INDEPENDENT MEDIA & ANR, TO ENSURE WE ARE FULLY FUNDED FOR NEXT MONTH,SO LET'S CUT THE BS & GET TO THE POINT - WE WILL BE FORCED LAY OFF STAFF & REDUCE OPERATIONS UNLESS WE ARE FULLY FUNDED WITHIN THE NEXT 2 WEEKS - Sadly, less than 0.5% of readers currently donate or subscribe to us But YOU can easily change that. Imagine the impact we'd make if 3 in 10 readers supported us today. To start with we’d remove this annoying banner as we could fight for a full year...

A critical vulnerability in the Libbitcoin Explorer 3.x library has resulted in the theft of over $900,000 from cryptocurrency users, according to a report from blockchain security firm SlowMist. This vulnerability not only affects Bitcoin users, but also the users of Ethereum, Ripple, Dogecoin, Solana, Litecoin, Bitcoin Cash, and Zcash who rely on Libbitcoin to generate their accounts.

Libbitcoin is a widely used Bitcoin wallet implementation that is utilized by various applications such as Airbitz, Bitprim, Blockchain Commons, and Cancoin. However, it is unclear which specific applications using Libbitcoin are impacted by this vulnerability.

Cointelegraph reached out to the Libbitcoin Institute for comment but did not receive a response at the time of publication. SlowMist credited a cybersecurity team called “Distrust” for discovering the vulnerability, which has been labeled the “Milk Sad” vulnerability. The team reported the vulnerability to the CEV cybersecurity vulnerability database on August 7.

According to SlowMist’s findings, the Libbitcoin Explorer suffers from a flawed key generation mechanism, which allows attackers to guess private keys. As a result, attackers have exploited this vulnerability to steal over $900,000 in cryptocurrencies as of August 10.

In one specific attack, SlowMist identified that an attacker siphoned away over 9.7441 BTC, equivalent to approximately $278,318. The firm claims to have blocked the attacker’s address and has contacted exchanges to prevent the funds from being cashed out. Additionally, SlowMist stated that they will continue monitoring the address in case the funds are transferred elsewhere.

To provide more information about the vulnerability, members of the Distrust team, along with eight freelance security consultants who contributed to its discovery, have set up a dedicated website called “milksad.info.” The website explains that the vulnerability occurs when users utilize the “bx seed” command to generate a wallet seed. This command relies on the Mersenne Twister pseudo-random number generator (PRNG), which, when initialized with 32 bits of system time, lacks sufficient randomness and may produce the same seed for multiple users.

The Distrust team became aware of the vulnerability after a Libbitcoin user reported mysteriously missing BTC on July 21. Upon contacting other Libbitcoin users, they discovered that similar thefts were occurring. This prompted their investigation, leading to the discovery of the Milk Sad vulnerability.

This incident underscores the ongoing challenges faced by cryptocurrency users regarding wallet security. In June, the Atomic Wallet experienced a hack that resulted in the loss of over $100 million. Wallet security rankings released by cybersecurity certification platform CER in July revealed that only six out of 45 wallet brands employ penetration testing to detect vulnerabilities.

As the cryptocurrency landscape continues to evolve, it is crucial for users to remain vigilant and choose wallets that prioritize rigorous security measures. Additionally, developers and validators should regularly update their systems and libraries to address potential vulnerabilities, thus safeguarding user funds from potential exploitation.

Source link

Opinion pieces don’t necessarily reflect the position of our news site but of our Opinion writers.

Original Source: Bitcoin loophole allowed hackers to steal $900K from newly found wallets: SlowMist

Support the ANR from as little as $8 – it only takes a minute. If you can, please consider supporting us with a regular amount each month. Thank you.

Related News

Subscribe for free to our ANR news emails and access 2 free ebooks plus Reports to share with family and friends about Covid fraud and the danger of the vaccines.

Australian National Review is Australia’s first real free and independent press, one with no editorial control by the elite, but a publication that can generate critical thinkers and critical debate and hold those spreading mistruths and deliberate propaganda in mainstream media to account.

News with a difference that will be educational, compelling and create a platform for political and social change in this country and address the real issues facing this country and the world.

Watch Full Documentary

URGENT: JUST 3 DAYS REMAIN TO HELP SAVE INDEPENDENT MEDIA & ANR, SO LET'S CUT THE BS & GET TO THE POINT - WE WILL BE FORCED TO LAY OFF STAFF & REDUCE OPERATIONS UNLESS WE ARE FULLY FUNDED WITHIN THE NEXT 2 WEEKS

Sadly, less than 0.5% of readers currently donate or subscribe to us But YOU can easily change that. Imagine the impact we'd make if 3 in 10 readers supported us today. To start with we’d remove this annoying banner as we could fight for a full year...

Get access to TruthMed- how to save your family and friends that have been vaxx with vaccine detox, & how the Unvaxxed can prevent spike protein infection from the jabbed.

Free with ANR Subscription from $8

Download the Full PDF - THE COVID-19 FRAUD & WAR ON HUMANITY