🎄 聖誕季相遇 Gate 廣場,共享節日驚喜!
🎉 Gate 廣場社區成長值「聖誕抽獎狂歡」第 1️⃣ 5️⃣ 期火熱開啟!
立即參與 👉 https://www.gate.com/activities/pointprize?now_period=15
✨ 如何參與?
1️⃣ 前往 Gate 廣場【積分中心】完成日常任務,輕鬆賺取成長值
2️⃣ 每累計 300 成長值,即可抽獎一次!
🎁 聖誕豪禮等你解鎖:
金條 10g、Gate 聖誕限定周邊等超值好禮,統統帶回家!
📅 12 月 18 日 - 12 月 26 日 24:00 (UTC+8)
🎅 聖誕好運不停,驚喜輪番來襲!
了解更多 👉 https://www.gate.com/announcements/article/48766
#BTC #ETH #SOL #GT
New Wallet Vulnerability Leads to $900K Theft from Bitcoin Users, Ethereum, Ripple, Dogecoin, Solana, Litecoin, Bitcoin Cash, and Zcash Also at Risk – Report
Libbitcoin, a Bitcoin wallet implementation used by developers and validators to create crypto accounts, has been compromised according to blockchain security firm SlowMist. Investigation into the vulnerability of the Libbitcoin Explorer 3.x library disclosed that more than $900,000 has so far been stolen from Bitcoin users. Users of other cryptos including Ethereum, Dogecoin, Ripple, Solana, Bitcoin Cash, Litecoin, and Zcash who use Libbitcoin for their accounts are reportedly not safe and are advised to transfer all funds to secure wallets.
The blockchain security firm explains that the vulnerability stems from the implementation of the pseudo-random number generator (PRNG) in the Libbitcoin Explorer 3.x versions. Upon assessment, it was observed that implementation used the Mersenne Twister algorithm as well as utilizing 32 bits of time as seed. This means threat actors would need just a few days to brute force the private keys of users
Libbitcoin is currently used by Airbitz (mobile wallet), Cancoin (decentralized exchanges), Blockchain Commons (decentralized wallet Identity), etc. However, none of these were specified to be affected by the vulnerability
More on the Libbitcoin Vulnerability
In a report found on the CVE cybersecurity vulnerability database, the Libbitcoin Explorer was said to have a faulty key generation mechanism. This makes it easier for threat actors to guess private keys. According to SlowMist, hackers made away with 9.7441 BTC ($278,318) in one attack. The initial action was to contact exchanges to prevent the attacker from withdrawing the funds
Following these concerns, reporters reached out to Libbitcoin Institute member Eric Voskuil for a comment. Interestingly, he clarified that the “bx seed” is not meant to be used in production wallets. Rather, it is intended as “a convenience for when the tool is used to demonstrate behavior that requires entropy.” He further stated that if people used it for production key seeding, then the warning is not sufficient. For now, they intend to make changes in a few days by either removing the command altogether or strengthening the warning against production use
Wallet vulnerabilities have contributed to millions of dollars lost on ious exchanges. In June, the hack of Atomic Wallet saw hackers stealing about $100 million. Most of these are linked to negligence. Cybersecurity certification platform CER recently disclosed that only 6 out of 45 wallet brands used penetration testing to uncover vulnerabilities
Best Crypto Exchange for Everyone: