$900K Bitcoin Heist Highlights Vulnerabilities in Legacy Libbitcoin Project

0

Disappearance of $900K Puts Focus on Vintage Bitcoin Project Libbitcoin0

In the early days of , specifically in 2011, a group of developers led by British-Iranian anarchist Amir Taaki began work on an alternative to Bitcoin Core. This software, named Libbitcoin, has since evolved into an essential library that provides tools for interacting with the Bitcoin blockchain and generating cryptographic keys.

Libbitcoin gained significant recognition when it was featured in Bitcoin educator Andreas Antonopoulos’s seminal book, “Mastering Bitcoin.” Its reputation was strong and its importance widely acknowledged. However, recent events have challenged the perceived security of the project.

The issue was brought to light through a report on milksad.info by Distrust, a security firm that, in collaboration with independent contributors, identified a vulnerability in July. This discovery sent shockwaves through the cryptocurrency community.

In May, hackers exploited a flaw within wallets generated by Libbitcoin’s explorer tool, BX. The vulnerability, dubbed “Milk Sad,” was named after the first two words of the compromised wallet-recovery seed phrase. Attackers used this weakness to drain funds from unsuspecting users.

The most significant incident occurred on July 12, resulting in the loss of 29.65 bitcoins, valued at approximately $870,000 at the time. Across multiple blockchains, the total value of stolen assets exceeded $900,000, affecting around 2,600 Bitcoin wallets.

While hardware wallets such as Trezor and Ledger were unaffected, many other wallets remain vulnerable. The full extent of the stolen funds is still being determined, as noted in an August 8 tweet by Anton Livaja, a member of the Distrust team.

The root cause lies in the BX command “bx seed,” which uses the computer’s clock to generate a seed phrase for wallet creation. The resulting phrases lack sufficient randomness. A malicious actor with a powerful gaming PC could potentially crack a user’s seed phrase via brute force within a single day.

This issue extends beyond Bitcoin, impacting major blockchains including Ethereum, Zcash, Solana, and Dogecoin. Similar but distinct vulnerabilities were also found in Cake Wallet and Trust Wallet, popular multi-chain wallet applications.

Technically, traditional seed phrases are generated using a tool with a large “key space,” offering billions of unique word combinations. This typically involves binary digits raised to the power of 128, 192, or 256. In contrast, BX’s seed generator has a limited 32-bit key space, allowing for only 4.3 billion unique combinations.

Eric Voskuil, the lead developer of BX, acknowledged the insecurity of the seed generator but insisted there was no software bug. He pointed to a cautionary note in the application’s GitHub documentation regarding the misuse of the bx seed command.

While Voskuil attributed the issue to poor wallet development practices, some in the Bitcoin community, including cryptographers, disagreed, calling for a broader assessment of the situation.

The Libbitcoin vulnerability serves as a stark reminder that even in the sophisticated world of cryptocurrencies, a single flaw can lead to substantial losses, undermining the promise of secure .

The post $900K Bitcoin Heist Highlights Vulnerabilities in Legacy Libbitcoin Project appeared first on BitcoinWorld.