Researchers Find Hundreds of Ethereum Wallets at Risk Due to Weak Key Pairs

Researchers Find Hundreds of Ethereum Wallets at Risk Due to Weak Key Pairs
фото показано с : news.bitcoin.com

2019-4-25 16:58

On April 23, the security consulting firm Independent Security Evaluators (ISE) published a document concerning a number of unsound public and private key pairs tied to the Ethereum blockchain. The probability of chance needed to crack 256-bit encryption would take years for hackers to access random private keys. However, ISE recently queried 49,060 ETH transactions which found 732 “weak” public keys, essentially revealing the corresponding private keys.

Also read: Bitcoin Cash Markets and Network Gather Strong Momentum in Q1

732 Private Keys and Discovering the Blockchain Bandit

An independent security consulting firm headquartered in Baltimore, Maryland has recently released a new study concerning “weak keys” found on the Ethereum blockchain. The researchers ISE detail that this trend could be detected on any blockchain implementation that uses public key signing based on ECDSA encryption. According to ISE they devised a scheme that can discover private keys that were generated by using either faulty code or defective random number generators (RNG), and a combination of both.

“We discovered that funds from these weak-key addresses are being pilfered and sent to a destination address belonging to an individual or group that is running active campaigns to compromise/gather private keys and obtain these funds,” the ISE report reveals.

While studying the matter, ISE found an individual or group they dubbed ‘Blockchain Bandit’ who has been pilfering these weak key addresses. ISE claims Blockchain Bandit managed to steal 37,926 ETH valued at $54.3 million by January 13, 2018.

“Even when faced with this statistical improbability, ISE discovered 732 private keys as well as their corresponding public keys that committed 49,060 transactions to the Ethereum blockchain,” explains the study. “Additionally, we identified 13,319 Ethereum that was transferred to either invalid destination addresses, or wallets derived from weak keys that at the height of the Ethereum market had a combined total value of $18,899,969.”

The number of all the Ethereum private/public keypairs the researchers have access to according to the study. Highly Successful Hacking Campaigns

In addition to the 732 key pairs found, there were 60,286,012 ERC20 based tokens held within these keys. ISE says with 50 million public Ethereum addresses there’s likely to be some weak keys found or a general lack of randomness. One of the biggest would be key truncation which is when the key length of the symmetric 256-bit encryption is generated but only a small subset is used due to errors. All kinds of errors can exist like type confusion, random device or RNG errors, seed re-use, memory reference errors, memory corruption, code logic errors and entropy errors. While querying another region of key space on the chain, the researchers discovered more vulnerable key pairs.

“Scanning this region of the key space yielded 8,920 transactions through 464 private keys,” the ISE paper details. “The total value of transactions using these weak private keys was 28.9456 Ethereum — While transactions are common in this range, there is currently a balance of 0 ETH.”

The 8,920 ETH queried transactions that show 464 private keys.

The ISE paper underscores that the use of weak private key pairs is not a “widespread problem” and it took the researchers 1024 hours total to complete the task. But the researchers note that any similar cryptographic algorithms can be examined for key generation errors which would include networks like BTC, ZEC, XRP, XMR and others. Because these cryptocurrencies are so popular, ISE can envision “highly successful hacking campaigns ongoing to steal these virtual currencies.” If the cryptocurrency network effect continues to grow, ISE stresses that software developers who build infrastructure need to incorporate every defense mechanism available to keep private keys safe. Innovative measures need to be taken to counter successful attackers like Blockchain Bandit and future hacking attempts.

What do you think about the private keys found by ISE due to errors and weak key pairs? Let us know what you think about this subject in the comments section below.

Image credits: Shutterstock, Independent Security Evaluators (ISE), and Pixabay.

Have you tried the open source, noncustodial Bitcoin.com Wallet? Try it today over 3.9 million wallets created so far!

The post Researchers Find Hundreds of Ethereum Wallets at Risk Due to Weak Key Pairs appeared first on Bitcoin News.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Selfkey (KEY) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.0055279
Капитализация $0 Rank 99999
Цена в час новости $ 0.0024982 (-100%)

pairs ethereum key researchers private ise security

pairs ethereum → Результатов: 108


Binance Expands Its Stablecoin Market with New Pairs for LTC, TRX, BCHSV and BCHABC

Earlier today, the popular cryptocurrency exchange of Binance announced that it will be adding additional trading pairs for Litecoin (LTC) and Tron (TRX). The new trading pairs will be in Binance’s Stablecoin Market and will be as follows: LTC/TUSD LTC/PAX LTC/USDC TRX/PAX TRX/USDC Trading of the new stablecoin pairs with LTC and TRX will begin […] The post Binance Expands Its Stablecoin Market with New Pairs for LTC, TRX, BCHSV and BCHABC appeared first on Ethereum World News.

2019-1-23 12:50


Binance To Add 3 New Stablecoin Pairs: PAX/TUSD, USDC/TUSD and USDC/PAX

In an announcement earlier today, the team at Binance let the crypto community know that it was going to open trading for three new stablecoin pairs: PAX/TUSD, USDC/TUSD and USDC/PAX. The announcement went on to provide a time frame for the new additions as follows: Fellow Binancians, Binance will open trading for PAX/TUSD, USDC/TUSD and USDC/PAX trading […] The post Binance To Add 3 New Stablecoin Pairs: PAX/TUSD, USDC/TUSD and USDC/PAX appeared first on Ethereum World News.

2019-1-7 13:13


TradePlace ICO

TradePlace is a global cryptocurrency exchange platform. It will form a new innovative platform to trade Bitcoin, Ethereum, Litecoin, EOS and other popular cryptocurrencies and tokens. Users will receive expert analysis of the current state of coin and token pairs, and they’ll be able to withdraw their money easily and receive alerts for scam cryptocurrencies.

2018-11-25 02:33


Ripple goes full throttle and extends the lead over Ethereum: Binance to add XRP as base pair

Ripple’s continued success does not seem to be coming to an end, so the price has risen further in the last 24 hours and has increased its lead over competitor Ethereum. In order to further advance the adoption, it is necessary to further spread the available base pairs on exchanges in order to simply trade […] The post Ripple goes full throttle and extends the lead over Ethereum: Binance to add XRP as base pair appeared first on CaptainAltcoin.

2018-11-18 17:00


Tron (TRX)’s New Listing On Indacoin Comes With New Trading Pairs, Enters Australia And Russia As Trading Volumes Increase By 260%

Things are looking up for Tron’s TRX as it gets another listing on a new London-based crypto exchange. The exchange, called Indacoin, also plans to offer 5 fiat trading pairs for the crypto. This comes just days after Tron launched a new smart contract system that quickly achieved over 12 million triggers.

2018-11-9 03:54


EtherMium: Decentralized Ethereum ERC20 Token Exchange?

What Is EtherMium? EtherMium is an Ethereum-based cryptocurrency exchange platform that operates cryptocurrency pairs and tokens with an ERC20 standard compliance. The platform seeks to provide leading trading services worldwide through its highly secure and unique features that will make it possible for users to access a wide range of cryptocurrencies as well as the ability […]

2018-11-1 09:49


Фото:

Binance will launch its first cryptocurrency-to-fiat trading pairs in Uganda

After a registration process lasting some four months, Binance will finally offer fiat-to-cryptocurrency trading pairs through its new Uganda exchange, with deposits opening on Wednesday. Announced via press release, Ugandans are now able to fully submit identity documents and begin depositing fiat ahead of live trade, something expected to start in two weeks.

2018-10-15 14:54


Binance Uganda Officially Launched, Pairs the Ugandan Shilling with BTC and ETH

Back in late June, the team at Binance had announced their intentions of open operations in Uganda. The main goal of opening an exchange in the African country, was that Binance wished to expand its reach not only in the developed countries, but to those less developed and with the potential to grow into thriving […] The post Binance Uganda Officially Launched, Pairs the Ugandan Shilling with BTC and ETH appeared first on Ethereum World News.

2018-10-15 14:30