BTC $105253.4219
ETH $2536.7414
XRP $2.1651
BNB $647.0731
SOL $152.2894
DOGE $0.1737
TRX $0.2723
ADA $0.6293
stETH $2531.8307
WBTC $105225.0714
HYPE $40.9323
wstETH $3063.7485
SUI $3.0141
BCH $461.0753
USDS $1.0002
LINK $13.1299
LEO $9.2628
AVAX $19.0735
XLM $0.2566
ONDO $0.7870
TON $2.9810
BTCB $105622.0912
WBT $39.4383
weETH $2714.1320
LTC $86.0318
HBAR $0.1525
WETH $2427.7112
BSC-USD $1.0051
DOT $3.7822
USDE $0.9994
XMR $311.9835
BGB $4.5146
PEPE $0.0000
PI $0.6036
AAVE $272.4915
UNI $7.0627
sUSDe $1.1822
DAI $0.9996
TAO $367.4616
OKB $51.4328
CBBTC $105258.6281
ICP $5.4192
APT $4.4910
CRO $0.0901
NEAR $2.1924
ETC $16.5423
JITOSOL $184.2161
BTC $105253.4219
ETH $2536.7414
XRP $2.1651
BNB $647.0731
SOL $152.2894
DOGE $0.1737
TRX $0.2723
ADA $0.6293
stETH $2531.8307
WBTC $105225.0714
HYPE $40.9323
wstETH $3063.7485
SUI $3.0141
BCH $461.0753
USDS $1.0002
LINK $13.1299
LEO $9.2628
AVAX $19.0735
XLM $0.2566
ONDO $0.7870
TON $2.9810
BTCB $105622.0912
WBT $39.4383
weETH $2714.1320
LTC $86.0318
HBAR $0.1525
WETH $2427.7112
BSC-USD $1.0051
DOT $3.7822
USDE $0.9994
XMR $311.9835
BGB $4.5146
PEPE $0.0000
PI $0.6036
AAVE $272.4915
UNI $7.0627
sUSDe $1.1822
DAI $0.9996
TAO $367.4616
OKB $51.4328
CBBTC $105258.6281
ICP $5.4192
APT $4.4910
CRO $0.0901
NEAR $2.1924
ETC $16.5423
JITOSOL $184.2161
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Due to the Randstorm vulnerability, 1.5 million bitcoins could be stolen.

    A new type of attack called Randstorm could potentially steal 1.5 million bitcoins, especially those made between 2011 and 2015. The Randstorm flaw is a result of bugs, bad design choices, and API changes that make the quality of random numbers generated by the web worse. Around 1.4 million bitcoins are believed to be in wallets made with weak cryptographic keys, which could support a creative space program for years.

    Unciphered discovered the Randstorm vulnerability in January 2022 while working for an unnamed client. The main reason for this vulnerability is the use of BitcoinJS, an open-source JavaScript library for creating browser-based cryptocurrency wallets. The exploit relies on the SecureRandom() function in the JSBN library, which was affected by cryptographic bugs in the way web browsers implemented the Math.random() function at the time. As of March 2014, BitcoinJS developers were no longer using JSBN.

    By brute force attacks, private keys can be used to get back the private keys of wallets made with the BitcoinJS library or projects that depend on it. The results highlight how flaws in core libraries used in open source projects can spread risks throughout the supply chain. In late 2021, a similar problem was seen with Apache Log4j.

    The security flaw is built into BitcoinJS wallets from the start, making them unfixable. If your wallet was made between 2011 and 2015, the only way to keep your money safe is to move it to a new wallet made with more up-to-date software.

    Author reign3d
    The Fall of a Crypto Titan: The Closure of Bittrex Global
    How scammers stole a million dollars from the crypto wallets of thousands of investors

    Comments 0

    Add comment