TDI.NEWS
  • NFT World
    • NFT Art
    • NFT Trends
    • NFT Projects News
    • NFT Gaming
  • More and more
  • About TDI.NEWS
  • Privacy Policy
No Result
View All Result
TDI.NEWS
  • NFT World
    • NFT Art
    • NFT Trends
    • NFT Projects News
    • NFT Gaming
  • More and more
  • About TDI.NEWS
  • Privacy Policy
No Result
View All Result
TDI.NEWS
No Result
View All Result

Researchers Find Bugs that Could Expose Crypto Wallets on Exchanges

RSS News by RSS News
Agosto 10, 2020
in Uncategorized
184 4
0
Researchers Find Bugs that Could Expose Crypto Wallets on Exchanges
400
SHARES
2.4k
VIEWS
Share on FacebookShare on Twitter


Source: Adobe/Alexander

Security experts said they have unveiled a number of vulnerabilities in the open-source libraries used by numerous crypto exchanges and financial institutions – which could be exploited by hackers looking for a way into users’ wallets.

At a recent Black Hat cybersecurity conference, experts said that some of the issues that affected exchanges have now been fixed – but claimed that others still pose a threat to their owners.

Jean-Philippe Aumasson, the co-founder of crypto exchange technology firm Taurus Group and Vice President at Kudelski Security, made note of the vulnerabilities, which were discovered by Omer Shlomovits, co-founder of mobile wallet maker ZenGo, into three categories of attacks, reported Wired.

The first type of attack requires hackers to use an insider at one of the exchanges to exploit a vulnerability in an open-source library made by a leading exchange that the researchers chose not to name.

By using a flaw in the library’s mechanism for refreshing keys, hackers could manipulate the process to change key components – while leaving all other components intact. As a result, the attackers could prevent the exchange from accessing crypto on its own platform.

The researchers informed the library developer of the bug’s existence one week after the code went live. But, since it was found in an open-source library, it is possible that other exchanges may still be using it in their operations.

The second scenario involves hackers exploiting a flaw in the key rotation process. Here, a failure in the validation of all of the statements that users and exchanges make to each other could allow a rogue exchange to extract its users’ private keys over multiple key refreshes, seizing control of their crypto assets.

Again, the bug was found in an open-source library developed by a major management firm whose name was not disclosed by the researchers.

The third category of attacks could occur when trusted parties originally derive their segments of a key, generating random numbers that are then publicly verified and tested for later use.

The researchers found that, as part of this process, a protocol in an open-source library developed by crypto exchange Binance failed to check these random numbers.

This issue could allow a rogue party in the key generation procedure to capitalize on the failure to extract other parties’ segments of the key.

Binance fixed the bug in March, when it called on its users to upgrade to a new version of “tss-lib” library.
___

Learn more:
How Bitcoin Critic Peter Schiff Launched Another ‘Proof of Keys’ Day
Discovered Vulnerability Made Ledger to Choose Between ‘Security and Usability’
‘A New Class of Attack’ In Crypto Is ‘Actively Exploited’ – Research
Seedless Wallets Want to Make Bitcoin More User Friendly



Source link

Recent

Hidden in a London attic, I discovered a Bible inscribed by Van Gogh

Hidden in a London attic, I discovered a Bible inscribed by Van Gogh

Febbraio 4, 2023
Rijksmuseum’s groundbreaking slavery exhibition heads to United Nations headquarters in New York

Rijksmuseum’s groundbreaking slavery exhibition heads to United Nations headquarters in New York

Febbraio 4, 2023
Yuga Labs Clear the Waters of its NFT Copyright

Yuga Labs Clear the Waters of its NFT Copyright

Febbraio 4, 2023

Categories

  • More and more (3.859)
  • NFT Art (1.221)
  • NFT Gaming (645)
  • NFT Gaming News (2.219)
  • NFT Projects News (2.016)
  • NFT Trends (812)
  • NFT World (4.618)
  • Uncategorized (21.166)

Category

  • More and more
  • NFT Art
  • NFT Gaming
  • NFT Gaming News
  • NFT Projects News
  • NFT Trends
  • NFT World
  • Uncategorized

Advertise

TDI.NEWS  is dedicated to spreading the word about exciting NFT projects!

We have various options available to help all qualifying promo partners get noticed throughout the NFT community.

info@thedailyinvestor.news

The Digital Art, NFT and related Cryptos Magazine

Recent News

Hidden in a London attic, I discovered a Bible inscribed by Van Gogh

Hidden in a London attic, I discovered a Bible inscribed by Van Gogh

Febbraio 4, 2023
Rijksmuseum’s groundbreaking slavery exhibition heads to United Nations headquarters in New York

Rijksmuseum’s groundbreaking slavery exhibition heads to United Nations headquarters in New York

Febbraio 4, 2023

© 2021 TDI.NEWS – Digital News, Art & Magazine

No Result
View All Result
  • NFT World
    • NFT Art
    • NFT Trends
    • NFT Projects News
    • NFT Gaming
  • More and more
  • About TDI.NEWS
  • Privacy Policy

© 2021 TDI.NEWS Newsdigital & Magazine - All rights reserved

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist