Lord777
Professional
- Messages
- 2,579
- Reaction score
- 1,479
- Points
- 113
Created between 2011 and 2015, more than 1 million BitcoinJS wallets and their derivatives contain the Randstorm vulnerability. It can lead to hacking and the loss of $2.1 billion held on them, according to Unciphered.
In addition to bitcoin, Dogecoin, Litecoin and ZCash wallets may be at risk.
The software provider has notified the owners of the need to move crypto assets from the old addresses.
In the report, experts emphasized that BitcoinJS wallets are easy to set up, which has provided them with a large market share. The easiest way to hack those that were created before March 2012.
According to experts, the source of the vulnerability is the SecureRandom() function from the JSBN javascript library (it was used until March 2014), combined with weaknesses in the main browser implementations of Math.random().
Today we release our work on Randstorm: a vulnerability affecting a significant number of browser generated cryptocurrency wallets
Reporting @washingtonpost
Technical write-up:
#Bitcoin #blockchain pic.twitter.com/aN7CZh9sv4
— Unciphered LLC (@uncipheredLLC) November 14, 2023
In addition to bitcoin, Dogecoin, Litecoin and ZCash wallets may be at risk.
The software provider has notified the owners of the need to move crypto assets from the old addresses.
In the report, experts emphasized that BitcoinJS wallets are easy to set up, which has provided them with a large market share. The easiest way to hack those that were created before March 2012.
According to experts, the source of the vulnerability is the SecureRandom() function from the JSBN javascript library (it was used until March 2014), combined with weaknesses in the main browser implementations of Math.random().