• About Us
  • Privacy Policy
  • Contact Us
Newsletter
Token Tatler
Advertisement
  • Home
  • Bitcoin
  • Cryptocurrency
    • Altcoin
    • Ethereum
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO
No Result
View All Result
  • Home
  • Bitcoin
  • Cryptocurrency
    • Altcoin
    • Ethereum
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO
No Result
View All Result
Token Tatler
No Result
View All Result
Home Market

‘Bypass’ Attack in Coldcard Bitcoin Wallet Could Trick Users Into Sending Incorrect Funds

tokentatler by tokentatler
November 25, 2020
in Market
0
‘Bypass’ Attack in Coldcard Bitcoin Wallet Could Trick Users Into Sending Incorrect Funds
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The bitcoin-only {hardware} pockets Coldcard has launched a beta firmware patch for a vulnerability that additionally affected a competitor {hardware} pockets earlier this 12 months.

Ben Ma, a safety researcher who works for {hardware} pockets producer Shift Crypto, found that the Coldcard {hardware} pockets has a flaw: An attacker might trick a Coldcard consumer into sending an actual bitcoin transaction once they suppose they’re sending a “testnet” transaction – or a fee on Bitcoin’s testing community, which isn’t the identical because the mainnet.

Each testnet and mainnet bitcoin transactions, although, “have the very same transaction illustration underneath the hood,” Ma writes in his submit disclosing the vulnerability. An attacker, then, might generate a bitcoin mainnet transaction for the {hardware} pockets however make it appear like a testnet transaction. The mainnet transaction is introduced like a testnet transaction on the consumer’s pockets, making it troublesome for customers to acknowledge the error.

Ma discovered of the vulnerability after a pseudonymous researcher found the so-called “isolation bypass” assault within the French-manufactured Ledger {hardware} pockets. 

In contrast to Coldcard, Ledger helps many cash, so the bypass assault might work by tricking pockets customers into sending bitcoin once they imply to ship litecoin and bitcoin money, along with testnet BTC.

When the preliminary vulnerability within the Ledger pockets was disclosed, Coinkite founder and Coldcard creator Rodolfo Novak mentioned, “Coldcard doesn’t assist any shitcoins, we discover that to be the very best path,” implying that his bitcoin-only pockets could be secure because the flaw (partially) resulted from the truth that Ledger gadgets beforehand managed totally different cash utilizing the identical non-public key. 

Since Coldcard doesn’t assist a number of cash, it theoretically shouldn’t have this downside. And it wouldn’t, if it weren’t for the truth that it may be exploited with bitcoin testnet addresses, as nicely.

If a consumer’s pc is compromised – and their Coldcard machine is unlocked and linked to that pc – then an adversary might trick them into sending actual bitcoin once they suppose they’re sending testnet bitcoin.

“The attacker merely has to persuade the consumer to e.g. ‘strive a testnet transaction’ or to purchase an ICO with testnet cash (I’ve heard there was a ICO like this not too long ago) or any variety of social engineering assaults to make the consumer carry out a testnet transaction. After the consumer confirms a testnet transaction, the attacker receives mainnet bitcoin in the identical quantity,” Ma writes within the submit. 

Seeing as an attacker might execute this assault remotely, it met Shift Crypto’s standards as a crucial situation, triggering the accountable disclosure course of. 

In keeping with the submit, Ma disclosed the vulnerability to Coinkite on Aug. four and Novak acknowledged it the subsequent day. On Nov. 23, Coldcard launched a beta firmware to patch the vulnerability.



Source link

Related articles

‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

November 11, 2021
This Imprisoned Russian Artist Is Selling NFTs to Support His Family and Fellow Inmates

This Imprisoned Russian Artist Is Selling NFTs to Support His Family and Fellow Inmates

November 11, 2021
Share76Tweet47

Related Posts

‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

by tokentatler
November 11, 2021
0

The newest salvo within the multibillion-dollar “Curve Wars” could be essentially the most daring but, and the protocol’s response...

This Imprisoned Russian Artist Is Selling NFTs to Support His Family and Fellow Inmates

This Imprisoned Russian Artist Is Selling NFTs to Support His Family and Fellow Inmates

by tokentatler
November 11, 2021
0

Skazkin, now 31, creates surreal digital artwork on an iPad and sells non-fungible tokens (NFT) of the works below...

Bitcoin, Ethereum, Crypto News and Price Data

Bitcoin, Ethereum, Crypto News and Price Data

by tokentatler
November 11, 2021
0

The chief in information and data on cryptocurrency, digital property and the way forward for cash, CoinDesk is a...

Crypto-Focused Bank Silvergate Gains 6% as Morgan Stanley Sees Big Upside for Shares — CoinDesk

Crypto-Focused Bank Silvergate Rallies After JPMorgan Sees Industry Adoption Growth

by tokentatler
November 11, 2021
0

“Silvergate’s standing because the pure-play financial institution of the crypto ecosystem, has led to the creation of a financial...

Hive Leads Crypto Mining Stocks Higher as Bitcoin Hits All-Time-High

Bitfarms Buys 24MW Crypto Mining Facility in Washington State for $26M

by tokentatler
November 11, 2021
0

“This low-cost energy mixed with the trade main effectivity of the Bitmain S19j Professional means 6,200 miners in Washington...

Load More
  • Trending
  • Comments
  • Latest
Can Blockchain Transactions be Hacked?

Can Blockchain Transactions be Hacked?

February 18, 2020
Ethereum Price Shoots 20% to $270 in Its Best Trading Day for the Year

Ethereum Price Shoots 20% to $270 in Its Best Trading Day for the Year

February 16, 2020
Grayscale Becomes Official Digital Currency Asset Management Partner of New York Giants

Grayscale Becomes Official Digital Currency Asset Management Partner of New York Giants

May 6, 2021
Apple Reveals Earnings for Fiscal Q2, Results Beat Expectations, AAPL Stock Down 3% Now

Apple Reveals Earnings for Fiscal Q2, Results Beat Expectations, AAPL Stock Down 3% Now

May 1, 2020
Pirate Chain Coin Now Available for Trading on Bitcoin.com Exchange, Joins New Alliance

Pirate Chain Coin Now Available for Trading on Bitcoin.com Exchange, Joins New Alliance

0
Bitcoin (BTC) Soars to 4-Month High, Crosses $10K Mark

Bitcoin (BTC) Soars to 4-Month High, Crosses $10K Mark

0
Bitcoin Rally Stalls, Bullish Recovery Depends On These Levels

Bitcoin Rally Stalls, Bullish Recovery Depends On These Levels

0
Ethereum (ETH) Almost Doubled This Year

Ethereum (ETH) Almost Doubled This Year

0

YouClout Lists on AscendEX

November 11, 2021
Bitcoin Daily Miner Revenue Rises To $60 Million As Fees Go Up

Bitcoin Daily Miner Revenue Rises To $60 Million As Fees Go Up

November 11, 2021
Rarible Marketplace Users Can Now Create, List, and Trade Flow-Based NFT Collectibles – Blockchain Bitcoin News

Rarible Marketplace Users Can Now Create, List, and Trade Flow-Based NFT Collectibles – Blockchain Bitcoin News

November 11, 2021
‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

‘Curve Wars’ Heat Up: Emergency DAO Invoked After ‘Clear Governance Attack’

November 11, 2021
Token Tatler

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Litecoin
  • Market
  • Regulation

Archives

  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020

Newsletter

  • About Us
  • Privacy Policy
  • Contact Us

© 2020 tokentatler.com

No Result
View All Result
  • Home
  • Bitcoin
  • Cryptocurrency
    • Altcoin
    • Ethereum
    • Litecoin
  • Blockchain
  • Regulation
  • Market
  • Prices
  • ICO

© 2020 tokentatler.com