Most people use either an app, an online platform, or a small hardware device as a wallet to store their cryptocurrency safely. The exchanges through which cryptocurrency changes hands, though, and other high stakes operations need something more like a massive digital bank vault. At the Black Hat security conference on Thursday, researchers detailed potential weaknesses in these specially secured wallet schemes, including some that affected real exchanges that have now been fixed.
The attacks aren't the digital equivalent of jackhammering a weak point on a safe or blowing up a lock. They're more like opening an old-timey bank vault with six keys that all have to turn at the same time. Breaking cryptocurrency private keys into smaller chunks similarly means an attacker has to cobble them together first to steal funds. But unlike distributing physical keys, the cryptographic mechanisms that underly multiparty key management are complex and difficult to implement correctly. Mistakes could be costly.
"These organizations are managing a lot of money, so they have quite high privacy and security requirements," says Jean-Philippe Aumasson, cofounder of the cryptocurrency exchange technology firm Taurus Group and vice president at Kudelski Security. "They need a way to split the cryptocurrency private keys into different components, different shares, so no party ever knows the full key and there isn't a single point of failure. But we found some flaws in how these schemes are set up that are not just theoretical. They could really have been carried out by a malicious party."
For the work, Aumasson, a cryptographer, validated and refined vulnerability discoveries made by Omer Shlomovits, cofounder of the mobile wallet maker ZenGo. The findings break down into three categories of attacks.
The first would require an insider at a cryptocurrency exchange or other financial institution exploiting a vulnerability in an open-source library produced by a prominent cryptocurrency exchange that the researchers declined to name. The attack takes advantage of a flaw in the library's mechanism for refreshing, or rotating, keys. In distributed key schemes, you don't want the secret key or its components to stay the same forever, because over time an attacker could slowly compromise each part and eventually reassemble it. But in the vulnerable library, the refresh mechanism allowed one of the key holders to initiate a refresh and then manipulate the process so some components of the key actually changed and others stayed the same. While you couldn't merge chunks of an old and new key, an attacker could essentially cause a denial of service, permanently locking the exchange out of its own funds.
Most distributed key schemes are set up so only a predetermined majority of the chunks of a key need to be present to authorize transactions. That way the key isn't lost entirely if one portion is accidentally eliminated or destroyed. The researchers point out that an attacker could use this fact to extort money from a target, letting enough portions of the key refreshincluding the one they controlthat they can contribute their portion and restore access only if the victim pays a price.
The researchers disclosed the flaw to the library developer a week after the code went live, so it's unlikely that any exchanges had time to incorporate the library into their systems. But because it was in an open-source library, it could have found its way into numerous financial institutions.
In the second scenario, an attacker would focus on the relationship between an exchange and its customers. Another flaw in the key rotation process, in which it fails to validate all of the statements the two parties make to each other, could allow an exchange with malicious motivations to slowly extract the private keys of its users over multiple key refreshes. From there a rogue exchange could initiate transactions to steal cryptocurrency from its customers. This could also be carried out quietly by an attacker who first compromises an exchange. The flaw is another open-source library, this time from an unnamed key management firm. The firm does not use the library in its own offerings, but the vulnerability could have been incorporated elsewhere.
See the original post:
Flaws Could Have Exposed Cryptocurrency Exchanges to Hackers - WIRED
- Bitcoin Center NYC To Support Wednesday's CryptoCurrency Convention By Hosting After-Party [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Qoinpro Cryptocurrency Faucet - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- Global Issues Cryptocurrency Project - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- cryptocurrency - Video [Last Updated On: April 11th, 2014] [Originally Added On: April 11th, 2014]
- PotCoin @ Cryptocurrency convention NYC, Good Audio - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 2014 - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- Unobtanium Cryptocurrency Explained - Video [Last Updated On: April 12th, 2014] [Originally Added On: April 12th, 2014]
- How To Create Your Own Cryptocurrency Co.Labs code ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- CryptoCoinsNews - Cryptocurrency and Bitcoin News with ... [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Joe Rogan and Reddit Co-founder Alexis Ohanian talk Dogecoin, Cryptocurrency - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- How To Assess A CryptoCurrency: AltCoin Assessment Protocol. What's the next big AltCoin? - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- Reggie Middleton's UltraCoin @ NYC CryptoCurrency Convention - Video [Last Updated On: April 14th, 2014] [Originally Added On: April 14th, 2014]
- The future is Nxt (cryptocurrency platform) - Video [Last Updated On: April 19th, 2014] [Originally Added On: April 19th, 2014]
- CryptoCurrency Convention 4/9/14 - Dan Larimer Bitshares - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- CryptoCurrency Convention 4/9/14 - Xavier Hawk Permacredits - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Does a cryptocurrency have the potential to revolutionize Ukraine? - Video [Last Updated On: April 20th, 2014] [Originally Added On: April 20th, 2014]
- Marscoin @ CryptoCurrency Convention NYC 4/9/14 - Lennart Lopin - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Vertcoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fisher - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- UltraCoin @ CryptoCurrency Convention NYC 4/9/14 - Reggie Middleton - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- iCoin @ CryptoCurrency Convention NYC 4/9/14 - Ryan Ridgeway - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video [Last Updated On: April 22nd, 2014] [Originally Added On: April 22nd, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- The Future of Cryptocurrency, Investing, and Crowdfunding (Toronto #BitcoinExpo Highlights) #548 - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video [Last Updated On: April 24th, 2014] [Originally Added On: April 24th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- - Cryptocurrency Mining System - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Know How 74 Cryptocurrency - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- CryptoCurrency of the World Unite! - Video [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video [Last Updated On: May 13th, 2014] [Originally Added On: May 13th, 2014]
- Bitpagar Cryptocurrency - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- Violincoin - The first cryptocurrency for musician - - Video [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency: Get Mining! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- The Cryptocurrency Store - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- Bitcoin Song - The Cryptocurrency Store - Video [Last Updated On: May 25th, 2014] [Originally Added On: May 25th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Sudbury Cryptocurrency Conference, May 26th: Ethereum - Video [Last Updated On: May 30th, 2014] [Originally Added On: May 30th, 2014]
- 2014 Cubieboard 1, 2 - Mining Peercoins (SHA-256 based) Cryptocurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- 2nd Salaries in CryptoCurrency - Video [Last Updated On: June 2nd, 2014] [Originally Added On: June 2nd, 2014]
- The Best Cryptocurrency Trading Platform - Video [Last Updated On: June 3rd, 2014] [Originally Added On: June 3rd, 2014]
- Cryptocurrency business forum - Video [Last Updated On: June 4th, 2014] [Originally Added On: June 4th, 2014]
- Cryptocurrency Opportunities in Southeast Asia | John KIM - Video [Last Updated On: June 7th, 2014] [Originally Added On: June 7th, 2014]
- Facebook Approves Cryptocurrency Tipping Apps -- Bitcoin Weekend In San Francisco - Video [Last Updated On: June 8th, 2014] [Originally Added On: June 8th, 2014]
- Wolf of Wall Street & Cryptocurrency w/ Patrick "PK" McDonnell - Video [Last Updated On: June 9th, 2014] [Originally Added On: June 9th, 2014]
- BankNote CryptoCurrency Review - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- CryptoCurrency 4 Housing for Father's Day! - Video [Last Updated On: June 13th, 2014] [Originally Added On: June 13th, 2014]
- Hyper CryptoCurrency Review - Video [Last Updated On: June 14th, 2014] [Originally Added On: June 14th, 2014]
- 0NE " EPIC " (HD dubstep mix) spot - a cryptocurrency with an Engine - Video [Last Updated On: June 15th, 2014] [Originally Added On: June 15th, 2014]
- Bitcoin,Litecoin mining rig cryptocurrency 2500W system, 6x 280x ASUS Beast 2014 - Video [Last Updated On: June 17th, 2014] [Originally Added On: June 17th, 2014]
- The Rundown Live #281 Tatiana Moroz (Chemtrails,CryptoCurrency,Anti-War) - Video [Last Updated On: June 19th, 2014] [Originally Added On: June 19th, 2014]
- Neutrality Coin New Alternative Cryptocurrency - Video [Last Updated On: June 20th, 2014] [Originally Added On: June 20th, 2014]
- Cryptocurrency Update - Buy Low, Sell High! - Video [Last Updated On: June 21st, 2014] [Originally Added On: June 21st, 2014]