HOME CATEGORIES WRITE AND EARN 🔍
CATEGORIES WRITE AND EARN MORE

CRYPTO NEWS

Your favorite crypto news blog

Mimblewimble Attacked Using $60 Per Week on AWS

Other 2019/11/18 19:55 by Osato Avan-Nomayo
mimblewimble hacked for less than $60 on AWS

Ivan Bogatyy of Dragonfly Research says he was able to use as little as $60 per week on Amazon Web Services (AWS) to expose a critical vulnerability on the Mimblewimble (MW) privacy architecture. This flaw in the MW protocol may dent the network’s aspiration of being a viable alternative to other privacy-focused blockchains like ZCash and Monero.


Massive Mimblewimble Flaw Uncovered

In a Medium post published on Monday (November 18, 2019), Bogatty revealed that he was able to expose the participating addresses in 96% of Grin transactions on MW. According to Bogatyy, this exploit of the MW protocol only cost $60 per week on AWS — Amazon’s cloud computing platform.

An excerpt from Bogatyy’s post showing the severity of the problem and the ease with which attackers can exploit vulnerability reads:

In my attack, I was able to link 96% of all transactions while only connecting to 200 peers out of the total 3000 peers in Grin’s network. But if I wanted to spend a bit more money, I could easily connect to 3000 nodes to disaggregate almost all transactions.

By “disaggregate,” Bogatyy is referring to the process of preventing transactions from coupling together in MW’s CoinJoin which ensures anonymity.

While other privacy-focused cryptos use decoy UTXOs or shielded transactions, MW achieves anonymity by means of massive CoinJoins. Each CoinJoin is an amalgamation of multiple transactions in a single block to create the ‘anonymity set.’

Still A Viable Alternative to ZEC and XMR?

Bogatyy did remark that the vulnerability was known to the MW developers. However, his findings prove that it requires little capital outlay to exploit the weakness in MW’s privacy architecture.

For Bogatyy, the presence of and ease with which attackers can take advantage of the vulnerability also makes MW a poor alternative to the likes of Zcash (ZEC) and Monero (XMR). According to Bogatyy:

The problem is inherent to Mimblewimble, and I don’t believe there’s a way to fix it. This means Mimblewimble should no longer be considered a viable alternative to Zcash or Monero when it comes to privacy.

The presence of this vulnerability may also affect Litecoin’s proposed MW integration. Back in early 2019, the Litecoin Foundation announced that it was looking to incorporate extension blocks on Litecoin to ensure privacy and anonymity.

What do you think about the vulnerability exposed in the Mimblewimble privacy architecture? Let us know in the comments below.


Images via Twitter @IvanBogatyy.

The post Mimblewimble Attacked Using $60 Per Week on AWS appeared first on Bitcoinist.com.

0 Like(s)



You should also read...

Altcoins 27/11/19 19:30 by Avi Mizrahi
European Crypto Exchange Bitbay Ends Monero Trading due to Anonymity Features
Authorities around the world are trying to stamp out online anonymity in various ways, sacrificing users’ privacy for alleged security. One of these ways is forcing digital asset exchanges to dr...
Read More
Bitcoin 03/05/20 13:48 by PR DESK
BitcoinMixer.to: An Effective Bitcoin Mixer for Anonymizing Crypto Payments
Bitcoin might be a safe and fast way to transact, but it doesn’t guarantee complete anonymity. A highly motivated hacker can easily trace your records. But thanks to BitcoinMixer.to, a platform ...
Read More
Crypto 21/07/20 16:27 by Bernice Nyambura
Dark Wallet Creator Amir Taaki Calls Zero-knowledge Accumulators the “New Anonymous Gold Standard”
CoinJoin-like schemes are not as anonymous as users may want to believe and some exchanges even have a zero-tolerance on mixing tools. Dark Wallet creator and early Bitcoin developer Amir Taaki re...
Read More
Altcoins 19/08/20 12:21 by Vincent Mislos
Tons Of Great Litecoin News Prove The Silver To Bitcoin’s Gold Is Far From Being “Boring”
For Charlie Lee, Litecoin’s ‘boringness’ makes the cryptocurrency better because money is ultimately boring. However, the number of news coming out of what was once the 3rd largest cryptocurren...
Read More
Crypto 16/02/21 13:56 by Guest Author
An Overview About Privacy Coins in 2021: What’s Ahead?
Maybe some people still believe it, but Bitcoin isn’t really anonymous. Indeed, isn’t anonymous at all: all the transactions in this currency are recorded in a public —and widely-ava...
Read More