BTC $65663.3988
ETH $2951.3430
BNB $571.9785
SOL $162.4630
XRP $0.5167
stETH $2947.7540
TON $6.7245
DOGE $0.1507
ADA $0.4603
AVAX $34.8064
TRX $0.1244
WBTC $65664.2294
wstETH $3442.1104
DOT $7.0090
WETH $2951.0632
LINK $15.9135
BCH $445.7670
MATIC $0.6952
UNI $7.2980
LTC $82.1658
FET $2.2467
ICP $12.2799
RNDR $10.0485
DAI $1.0007
IMX $2.5264
NEAR $8.0856
CAKE $2.5963
PEPE $0.0000
HBAR $0.1135
ETC $27.2264
FDUSD $0.9993
MNT $0.9705
FIL $5.7296
AR $45.6787
OKB $49.1549
STX $1.9892
KAS $0.1218
GRT $0.3022
WIF $2.8486
ATOM $8.5502
TAO $386.0669
VET $0.0352
MKR $2677.9402
XMR $133.3826
USDE $1.0012
INJ $23.8140
THETA $2.1720
BTC $65663.3988
ETH $2951.3430
BNB $571.9785
SOL $162.4630
XRP $0.5167
stETH $2947.7540
TON $6.7245
DOGE $0.1507
ADA $0.4603
AVAX $34.8064
TRX $0.1244
WBTC $65664.2294
wstETH $3442.1104
DOT $7.0090
WETH $2951.0632
LINK $15.9135
BCH $445.7670
MATIC $0.6952
UNI $7.2980
LTC $82.1658
FET $2.2467
ICP $12.2799
RNDR $10.0485
DAI $1.0007
IMX $2.5264
NEAR $8.0856
CAKE $2.5963
PEPE $0.0000
HBAR $0.1135
ETC $27.2264
FDUSD $0.9993
MNT $0.9705
FIL $5.7296
AR $45.6787
OKB $49.1549
STX $1.9892
KAS $0.1218
GRT $0.3022
WIF $2.8486
ATOM $8.5502
TAO $386.0669
VET $0.0352
MKR $2677.9402
XMR $133.3826
USDE $1.0012
INJ $23.8140
THETA $2.1720
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Due to the Randstorm vulnerability, 1.5 million bitcoins could be stolen.

    A new type of attack called Randstorm could potentially steal 1.5 million bitcoins, especially those made between 2011 and 2015. The Randstorm flaw is a result of bugs, bad design choices, and API changes that make the quality of random numbers generated by the web worse. Around 1.4 million bitcoins are believed to be in wallets made with weak cryptographic keys, which could support a creative space program for years.

    Unciphered discovered the Randstorm vulnerability in January 2022 while working for an unnamed client. The main reason for this vulnerability is the use of BitcoinJS, an open-source JavaScript library for creating browser-based cryptocurrency wallets. The exploit relies on the SecureRandom() function in the JSBN library, which was affected by cryptographic bugs in the way web browsers implemented the Math.random() function at the time. As of March 2014, BitcoinJS developers were no longer using JSBN.

    By brute force attacks, private keys can be used to get back the private keys of wallets made with the BitcoinJS library or projects that depend on it. The results highlight how flaws in core libraries used in open source projects can spread risks throughout the supply chain. In late 2021, a similar problem was seen with Apache Log4j.

    The security flaw is built into BitcoinJS wallets from the start, making them unfixable. If your wallet was made between 2011 and 2015, the only way to keep your money safe is to move it to a new wallet made with more up-to-date software.

    Author reign3d
    The Fall of a Crypto Titan: The Closure of Bittrex Global
    How scammers stole a million dollars from the crypto wallets of thousands of investors

    Comments 0

    Add comment