BTC $58379.9472
ETH $2982.7872
BNB $563.0335
SOL $134.7235
XRP $0.5177
stETH $2971.9755
DOGE $0.1303
TON $4.8905
ADA $0.4503
AVAX $33.3328
TRX $0.1205
wstETH $3474.4227
DOT $6.8866
WETH $2975.5564
WBTC $58376.0680
BCH $424.7496
LINK $13.3612
MATIC $0.6924
UNI $7.0434
ICP $13.2308
LTC $80.1663
DAI $1.0012
FDUSD $1.0026
CAKE $2.5276
RNDR $7.6591
IMX $2.0284
ETC $25.5672
NEAR $6.1572
HBAR $0.0999
FIL $5.7239
STX $2.1417
MNT $0.9501
PEPE $0.0000
OKB $48.7666
ATOM $8.7518
WIF $2.6145
VET $0.0353
KAS $0.1092
TAO $382.3435
MKR $2726.6998
USDE $0.9992
GRT $0.2436
XMR $123.2867
XLM $0.1111
FET $2.0170
INJ $23.7176
THETA $2.0387
BTC $58379.9472
ETH $2982.7872
BNB $563.0335
SOL $134.7235
XRP $0.5177
stETH $2971.9755
DOGE $0.1303
TON $4.8905
ADA $0.4503
AVAX $33.3328
TRX $0.1205
wstETH $3474.4227
DOT $6.8866
WETH $2975.5564
WBTC $58376.0680
BCH $424.7496
LINK $13.3612
MATIC $0.6924
UNI $7.0434
ICP $13.2308
LTC $80.1663
DAI $1.0012
FDUSD $1.0026
CAKE $2.5276
RNDR $7.6591
IMX $2.0284
ETC $25.5672
NEAR $6.1572
HBAR $0.0999
FIL $5.7239
STX $2.1417
MNT $0.9501
PEPE $0.0000
OKB $48.7666
ATOM $8.7518
WIF $2.6145
VET $0.0353
KAS $0.1092
TAO $382.3435
MKR $2726.6998
USDE $0.9992
GRT $0.2436
XMR $123.2867
XLM $0.1111
FET $2.0170
INJ $23.7176
THETA $2.0387
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Due to the Randstorm vulnerability, 1.5 million bitcoins could be stolen.

    A new type of attack called Randstorm could potentially steal 1.5 million bitcoins, especially those made between 2011 and 2015. The Randstorm flaw is a result of bugs, bad design choices, and API changes that make the quality of random numbers generated by the web worse. Around 1.4 million bitcoins are believed to be in wallets made with weak cryptographic keys, which could support a creative space program for years.

    Unciphered discovered the Randstorm vulnerability in January 2022 while working for an unnamed client. The main reason for this vulnerability is the use of BitcoinJS, an open-source JavaScript library for creating browser-based cryptocurrency wallets. The exploit relies on the SecureRandom() function in the JSBN library, which was affected by cryptographic bugs in the way web browsers implemented the Math.random() function at the time. As of March 2014, BitcoinJS developers were no longer using JSBN.

    By brute force attacks, private keys can be used to get back the private keys of wallets made with the BitcoinJS library or projects that depend on it. The results highlight how flaws in core libraries used in open source projects can spread risks throughout the supply chain. In late 2021, a similar problem was seen with Apache Log4j.

    The security flaw is built into BitcoinJS wallets from the start, making them unfixable. If your wallet was made between 2011 and 2015, the only way to keep your money safe is to move it to a new wallet made with more up-to-date software.

    Author reign3d
    The Fall of a Crypto Titan: The Closure of Bittrex Global
    How scammers stole a million dollars from the crypto wallets of thousands of investors

    Comments 0

    Add comment