7

BitGo fixes critical flaw in Ethereum wallet software discovered by Fireblocks

 1 year ago
source link: https://siliconangle.com/2023/03/17/bitgo-fixes-critical-flaw-ethereum-wallet-software-discovered-fireblocks/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

BitGo fixes critical flaw in Ethereum wallet software discovered by Fireblocks

security-1202344_1280-TBIT-Pixabay.png
BLOCKCHAIN

Enterprise cryptocurrency wallet BitGo Inc. today patched a critical flaw that could have exposed users’ Ethereum private keys after researchers at the digital asset custody firm Fireblocks Inc. discovered the exploit.

The researchers found the vulnerability and notified BitGo in December, the team said, which affected the company’s implementation of its Ethereum TSS enabled self-managed wallet. The exploit was related to the BitGo Threshold Signature Scheme protocol, which could allow an attacker to steal the private keys using a small bit of JavaScript code.

Fireblocks named the attack the Zero Proof Vulnerability, since it took advantage of a missing security layer in the Elliptic Curve Digital Signature Algorithm TSS protocol that used zero-knowledge proofs. Without the addition of the zero-knowledge proofs, the use of TSS acts only as a communication conduit and attackers can bypass security layers altogether.

After notifying BitGo of the attack on Dec. 5, Fireblocks said that the affected service was taken offline by BitGo on Dec. 10. That was followed quickly by a patch in February, which would require all affected clients to update their wallet software by today.

Fireblocks says it maintained a fully “coordinated disclosure” with BitGo about the vulnerability, which is where cybersecurity researchers discover an exploit in code and work privately with a company and then wait for them to fully patch the code before revealing it publicly.

In response to the revelation, BitGo claimed that Fireblocks is “trying to drum up unnecessary fear” and “turning a known gap into a publicity stunt.”

The company stated that the particular wallet that was affected was in fact in early access, and currently remains in early access, and was accessible to only 20 developers, thus limiting the total damage that could have been done if it had been exploited.

BitGo went on to say that the Fireblocks disclosure contained a number of false claims, but did not mention what they were. However, Bitgo did stress that Fireblocks did not mention that the product was in early release. That’s a form of beta testing used to allow developers and engineers to shake down a new product to help discover and reveal flaws before general availability to the public.

“It is unusual for a firm to repeatedly contact reporters, regulators and clients about a known issue in a pre-release product, and we are surprised that Fireblocks decided to take that path after we informed them that this was early-release software,” BitGo said in a statement.

BitGo added that its products are all open source and its team stands by its open-source security processes and welcomes further scrutiny from the rest of the community.

Image: TBIT/Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK