Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am guessing that the key pair generation process was faulty. The FBI found an exploit in a wallet used by the hackers allowing the private key to be predicted. The prefix is bc1,which is uncommon. A few weeks ago there was such a vulnerability with Cake Wallet.

Or they installed malware on the hacker's computers and were able to log the private key as it was generated.

Or the hackers foolishly stored the key pairs on a server

Bitcoin is falling and this news does not help because it shows that some aspect is less secure than previously thought.



bc1 is for bech32 addresses. A feature of the new segwit. Aparently there is a way to predict the private key derived from using multiple times the bc1 address. Details are available here: https://sudonull.com/post/8212-Bitcoin-Pseudo-Random-Number-...

Could it be that bech32 is less secure than thought?


Almost certainly what's not secure is the endpoint, wherever the keys were stored. That shouldn't really be news. The endpoints are always the weakest links in an encrypted channel.


bc1 isn't an uncommon prefix, its a bech32 native segwit address that's been in use for years now (IIRC 1 and 3 are the other prefixes, 1 being the first and most popular and 3 being a backwards compatible segwit address, i.e. non native). Stats: https://txstats.com/dashboard/db/bech32-statistics?orgId=1

faulty key pairs being generated is a well known issue with poorly developed wallets, not with Bitcoin itself. None of the popular wallets have this issue so it doesn't undermine Bitcoin.


I'm wondering if the attackers sent their coins through a mixer, and now some chump with money on coinbase just got his coins jacked b/c he deposited after using a shady mixer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: