BTC $94167.1814
ETH $1786.6395
XRP $2.1956
BNB $602.7359
SOL $148.5148
DOGE $0.1817
ADA $0.7074
TRX $0.2517
stETH $1784.1381
WBTC $94129.3683
SUI $3.4353
LINK $14.7696
AVAX $21.9518
XLM $0.2889
USDS $1.0007
LEO $9.0325
TON $3.2197
HBAR $0.1910
wstETH $2144.0903
BCH $359.2934
DOT $4.2388
LTC $86.1975
HYPE $17.6418
BGB $4.4361
BSC-USD $0.9998
WETH $1787.0749
USDE $0.9994
BTCB $94120.0817
XMR $229.2697
PI $0.6453
weETH $1905.2350
WBT $29.2427
PEPE $0.0000
APT $5.5706
UNI $5.7876
DAI $1.0000
OKB $52.7132
ONDO $1.0001
NEAR $2.6093
TRUMP $15.0881
TAO $342.7013
ICP $5.2795
GT $22.7063
CBBTC $94233.7487
KAS $0.1008
CRO $0.0912
ETC $16.9617
BTC $94167.1814
ETH $1786.6395
XRP $2.1956
BNB $602.7359
SOL $148.5148
DOGE $0.1817
ADA $0.7074
TRX $0.2517
stETH $1784.1381
WBTC $94129.3683
SUI $3.4353
LINK $14.7696
AVAX $21.9518
XLM $0.2889
USDS $1.0007
LEO $9.0325
TON $3.2197
HBAR $0.1910
wstETH $2144.0903
BCH $359.2934
DOT $4.2388
LTC $86.1975
HYPE $17.6418
BGB $4.4361
BSC-USD $0.9998
WETH $1787.0749
USDE $0.9994
BTCB $94120.0817
XMR $229.2697
PI $0.6453
weETH $1905.2350
WBT $29.2427
PEPE $0.0000
APT $5.5706
UNI $5.7876
DAI $1.0000
OKB $52.7132
ONDO $1.0001
NEAR $2.6093
TRUMP $15.0881
TAO $342.7013
ICP $5.2795
GT $22.7063
CBBTC $94233.7487
KAS $0.1008
CRO $0.0912
ETC $16.9617
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Due to the Randstorm vulnerability, 1.5 million bitcoins could be stolen.

    A new type of attack called Randstorm could potentially steal 1.5 million bitcoins, especially those made between 2011 and 2015. The Randstorm flaw is a result of bugs, bad design choices, and API changes that make the quality of random numbers generated by the web worse. Around 1.4 million bitcoins are believed to be in wallets made with weak cryptographic keys, which could support a creative space program for years.

    Unciphered discovered the Randstorm vulnerability in January 2022 while working for an unnamed client. The main reason for this vulnerability is the use of BitcoinJS, an open-source JavaScript library for creating browser-based cryptocurrency wallets. The exploit relies on the SecureRandom() function in the JSBN library, which was affected by cryptographic bugs in the way web browsers implemented the Math.random() function at the time. As of March 2014, BitcoinJS developers were no longer using JSBN.

    By brute force attacks, private keys can be used to get back the private keys of wallets made with the BitcoinJS library or projects that depend on it. The results highlight how flaws in core libraries used in open source projects can spread risks throughout the supply chain. In late 2021, a similar problem was seen with Apache Log4j.

    The security flaw is built into BitcoinJS wallets from the start, making them unfixable. If your wallet was made between 2011 and 2015, the only way to keep your money safe is to move it to a new wallet made with more up-to-date software.

    Author reign3d
    The Fall of a Crypto Titan: The Closure of Bittrex Global
    How scammers stole a million dollars from the crypto wallets of thousands of investors

    Comments 0

    Add comment