o3n [ozone] blockchain layer

Blockchain source

Menu
  • Cybersecurity services
Menu

Ripple: Only XRP Private Keys That Used Software From Before August 2015 Are Vulnerable

Posted on January 16, 2019 by nbelov

Ripple software libraries published before August 2015 potentially rendered private keys which signed multiple transactions vulnerable.

Ripple (XRP) software libraries published before August 2015 potentially rendered private keys which signed multiple transactions vulnerable, Ripple announced in a statement released on Jan 16.

Recent research jointly conducted by the DFINITY Foundation and the University of California revealed that a portion of Bitcoin (BTC), Ethereum (ETH) and Ripple addresses are vulnerable.

As is known among cryptographers, the security of Elliptic Curve Digital Signature Algorithms (ECDAs) employed by the aforementioned cryptocurrencies is highly dependent on random data, which are known as nonces. The research further explains:

“It is well known that if an ECDSA private key is ever used to sign two messages with the same signature nonce, the long-term private key is trivial to compute [crack].”

The researchers claim to have successfully hacked hundreds of Bitcoin, some Ethereum, SSH (remote control for unix-like systems), HTTPS and one XRP private keys thanks to so-called biased nonces (with a low degree of randomness.) As the researchers explain, the consequences of such vulnerabilities are vast:

“In the case of cryptocurrencies, these keys give us, or any other attacker, the ability to claim the funds in the associated accounts. In the case of SSH or HTTPS, these keys would give us, or any other attacker, the ability to impersonate the end hosts.”

Still, the paper explains that such vulnerabilities can be prevented:

“All of the attacks we discuss in this paper can be prevented by using deterministic ECDSA nonce generation, which is already implemented in the default Bitcoin and Ethereum libraries.”

According to Ripple, deterministic nonce generation has also been part of their software since August 2015. This feature also makes addresses that interacted with the blockchain employing newer software libraries safe from this vulnerability.

While cryptography is far from perfect, centralized systems like exchanges and single computing systems are successfully attacked with success much more often than private keys, the research states.. The paper further notes that during the research, access has been obtained to only about $54 of BTC and $14 of XRP.

As Cointelegraph reported yesterday, the New Zealand cryptocurrency exchange Cryptopia has suspended services after detecting a major hack that has reportedly resulted in significant losses.

Also, recently news broke that a recent spate of ransomware attacks estimated to have earned hackers 705.08 Bitcoin ($2.5 million) likely came from Russian cybercriminals, not North Korean state-sponsored actors as initially thought.

Source: Cointelegraph https://cointelegraph.com/

Recent Posts

  • Fintech-Ideas brings blockchain functionality to its range of platforms – Crypto Mode July 3, 2022
  • Top 10 Universities to Pick for a Blockchain Degree – Analytics Insight July 3, 2022
  • Top Cryptocurrencies, Protocols, And Blockchains For NFTs In 2022 – Crypto Mode July 3, 2022
  • Israel’s regulator teases comprehensive crypto framework at ICC July 3, 2022
  • Ethereum average gas fee falls down to $1.57, the lowest since 2020 July 3, 2022
  • $XRP: Spanish Blockchain Startup Demonstrates a New Use for XRP Ledger – CryptoGlobe July 3, 2022
  • Head-To-Head Contrast: TELUS International (Cda) (NYSE:TIXT) & HIVE Blockchain Technologies (NASDAQ:HIVE) – Defense World July 3, 2022
  • Web5 vs. Web3: The future is a process, not a destination July 3, 2022
  • Crema Finance shuts liquidity protocol on Solana amid hack investigation July 3, 2022
  • India's blockchain and digital currency-related job listings grew by 804% since 2020: Indeed – CoinGeek July 3, 2022
  • The development of blockchain industry and how to defend against attacks on DeFi July 3, 2022
  • Jed McCaleb’s XRP bag is almost gone, Ethereum’s difficulty bomb delayed and FTX inks deal with BlockFi: Hodler’s Digest, June 26-July 2 July 2, 2022
  • How Blockchain Can Change 401(k)s – Investopedia July 2, 2022
  • Bitcoin indicator that nailed all bottoms predicts $15.6K BTC price floor July 2, 2022
  • How is the Government of Colombia planning to utilize Ripple's XRPL Blockchain? – The Coin Republic July 2, 2022
  • Why longevity matters to everyone: Living longer lives in the world of Web3 July 2, 2022
  • What determines the Bitcoin price? July 2, 2022
  • How to earn crypto passive income with forks and airdrops? July 2, 2022
  • Blockchain in Banking and Finance Market will Reach $94.58 billion by 2030, Growing by 63.1% Annually over 2020-2030 – Designer Women – Designer Women July 2, 2022
  • Aver, The "Decentralized" Prediction Exchange, Launches On Solana Blockchain – Crowdfund Insider – Crowdfund Insider July 2, 2022
  • Blockchain in Telecom Market 2022 Global Competition and Business Outlook –Dell Technologies, FireEye Inc., Google – Designer Women – Designer Women July 2, 2022
  • Blockchain in Healthcare Market will Reach $58.9 billion by 2030, Growing by 70.5% Annually over 2020-2030 – Designer Women – Designer Women July 2, 2022
  • KuCoin CEO slams insolvency rumors citing “no plan to halt withdrawal” July 2, 2022
  • DeSci: Tech trees to fund ambitious science and tech July 2, 2022
  • TickerWin Releases Report on '5 Major Tech Trends in the Blockchain Industry' – Digital Journal July 2, 2022
  • TickerWin Releases Report on 'How Blockchain is Improving the Efficiency of AI and Machine Learning' – Yahoo Finance July 2, 2022
  • Coinbase, Blockchain.com and Kraken are still hiring for hundreds of roles despite mass crypto layoffs – Yahoo News July 2, 2022
  • Humanity Forward Applauds The Introduction Of Blockchain Resolution At The United States Conference Of Mayors – CIOReview July 2, 2022
  • Bitcoin will see ‘long bear market’ says trader with BTC price stuck at $19K July 2, 2022
  • “Dissolve” NFT Collection: Grey Leifer's Push for LGBT+ Representation in Blockchain – Block Telegraph July 2, 2022

Ad

Ad

©2022 o3n [ozone] blockchain layer | WordPress Theme by Superbthemes.com