Get 40% Off
These stocks are up over 10% post earnings. Did you spot the buying opportunity? Our AI did.Read how

Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets

Published 08/11/2023, 07:35 AM
Updated 08/11/2023, 08:00 AM
Libbitcoin vulnerability leads to $900k theft from Bitcoin wallets

Crypto.news - A vulnerability in the Libbitcoin Explorer 3.x library has led to the theft of over $900,000 from Bitcoin users.

Blockchain security firm SlowMist reported the issue.

It could also affect users of other digital currencies like Ethereum (ETH), Ripple (XRP), Dogecoin (DOGE), Solana (SOL), Litecoin (LTC), Bitcoin Cash (BCH), and Zcash that employ Libbitcoin to create accounts.

Libbitcoin is a Bitcoin wallet implementation used by various applications, including Airbitz, Bitprim, Blockchain Commons, and Cancoin. SlowMist did not specify which applications are affected by the vulnerability.

The vulnerability, known as the “Milk Sad,” was first discovered by the cybersecurity team “Distrust” and reported to the CEV cybersecurity vulnerability database on Aug. 7. It involves a faulty key generation mechanism in the Libbitcoin Explorer, which allows attackers to guess private keys.

The attackers exploited this vulnerability to steal over $900,000 worth of crypto, including a single attack that siphoned away over $278,318

SlowMist claims to have “blocked” the address, implying that they have contacted exchanges to prevent the attacker from cashing out the funds. They will also be monitoring the address in case funds are moved elsewhere.

The Distrust team and eight freelance security consultants have set up an informational website explaining the vulnerability. They have found that the vulnerability occurs when users generate a wallet seed using the “bx seed” command, which lacks sufficient randomness and can produce the same seed for multiple users.

The vulnerability was discovered when a Libbitcoin user reported missing BTC on July 21. More digging showed that other users were having their Bitcoin stolen similarly.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Eric Voskuil, a member of the Libbitcoin Institute, stated that the “bx seed” command is not intended for production wallets, and changes may be made to strengthen the warning against its use or remove the command altogether.

Wallet vulnerabilities remain a problem for crypto users in 2023, with over $100 million lost in a hack of the Atomic Wallet in June. According to the wallet security rankings released by CER in July, nly six out of 45 wallet brands employ penetration testing to discover vulnerabilities.

This article was originally published on Crypto.news

Latest comments

Hahaha hahahahahahahaha scammers got scammed
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.