Cryptocurrency wallet BitGo has patched a critical vulnerability that could have exposed the private keys of retail and institutional users.Cryptography research team Fireblocks identified the flaw and notified the BitGo team in December 2022.
The vulnerability was related to BitGo Threshold Signature Scheme (TSS) wallets and had the potential to expose the private keys of exchanges, banks, businesses and users of the platform.The Fireblocks team named the vulnerability the BitGo Zero Proof Vulnerability, which would allow potential attackers to extract a private key in under a minute using a small amount of JavaScript code.
BitGo suspended the vulnerable service on Dec. 10 and released a patch in February 2023 that required client-side updates to the latest version by March 17.The Fireblocks team outlined how it identified the exploit using a free BitGo account on mainnet.
A missing part of mandatory zero-knowledge proofs in BitGo’s ECDSA TSS wallet protocol allowed the team to expose the private key through a simple attack. Related: Euler Finance hacked for over $195M in a flash loan attack Industry-standard enterprise-grade cryptocurrency asset platforms make use of either multiparty-computation (MPC/TSS) or multisignature technology to remove the possibility of a single point of attack.
Read more on cointelegraph.com