HOME CATEGORIES WRITE AND EARN 🔍
CATEGORIES WRITE AND EARN MORE

CRYPTO NEWS

Your favorite crypto news blog

Researchers Discover Flaw in Major Bitcoin Wallets That Could Trick Users to Think They Received BTC

Bitcoin 2020/07/02 11:54 by Vincent Mislos
Researchers Discover Flaw That Could Trick Users to Believing They Have Bitcoin In Their Wallets

Bitcoin wallet ZenGo has disclosed the “BigSpender” vulnerability existing in many crypto wallets, wherein an attacker can cancel a transaction but still make the funds appear in the victim’s wallet.

Via the BigSpender Attack, the hacker creates the illusion that there are Bitcoins in the victim’s wallet, except that it doesn’t. The wallet will also be corrupted so the victim won’t be able to spend or use whatever is left inside.

ZenGo disclosed this vulnerability after informing the wallet providers that are prone to this attack. The company claimed only some fixed their wallets to prevent these kinds of attacks and as such, they disclosed the vulnerability to the public after 90 days customary notice to the exposed bitcoin wallets.

The Bitcoin blockchain has a mechanism called Replace-By-Fee (RBF,) a relay policy that can signal a 0-conf transaction (transactions with zero confirmations) to be replaced by the next transaction by the user. To do this, the user is advised to spend the same coins and provide a higher fee. RBF requires the user and wallet apps to identify unconfirmed transactions as unsafe.

According to ZenGo, many wallets have failed to do this, allowing the vulnerability called “BigSpender” to be possible. “Vulnerable wallets are not prepared for the option that a transaction might be canceled and implicitly assume it will get confirmed eventually,” ZenGo said in its disclosure blog post.

The vulnerability will make the users’ wallets appear to have more Bitcoins even if the incoming transaction is still unconfirmed. What’s more, the canceled transactions will not appear in the canceled transaction list and UTXO could still be selected by the wallet application despite the transaction actually not happening. 

Because of ‘BigSpender’, an attacker can do a basic double-spend attack for a minimum fee, making it pending for a long time. The attacker can basically ask for a good or service and when the goods or service is rendered, the attacker can cancel the transaction. However, the victim will believe the money is in their account because the Bitcoin wallet they use considered the transaction as fulfilled.

The attacker could amplify this by repeatedly sending small amounts of Bitcoin and then canceling it through the flaw.

Finally, because the vulnerable wallet designated a transaction as complete even when it isn’t, a user who tries to withdraw their holdings could experience failed transactions, because the wallet is trying to select coins that are not actually there.

ZenGo said this attack is either “hard or impossible to recover from.” The vulnerable wallet would not re-synchronize with the network to show the correct balance, making it corrupted.

ZenGo notified the providers and among them, Bread Wallet and Ledger Live have fixed the issue. Edge wallet acknowledged the vulnerability but has not yet fixed it. However, ZenGo said the issue with Edge showing incorrect balance can be resolved by clicking “Resync” in its options.

Researchers Discover Flaw That Could Trick Users to Think They Have Bitcoin in Their Wallets

Many, however, were doubting the “vulnerability,” as ZenGo claimed it to be. Ledger remarked that it is not a vulnerability but simply a UX bug or trickery. For one, it involved some social engineering; the attacker has to convince the victim first in order for the attacker to take advantage of ‘BigSpender’, just like in typical crypto scams.

0 Like(s)



You should also read...

Bitcoin 21/11/19 12:30 by Christine Vasileva
Bitcoin Price Forces Small Miners Out, Untagged Wallets Dump $20M
Miners made the biggest withdrawal of funds in 2019, just as Bitcoin price was fighting its last to keep above $8,000. The accelerated selling of rewards may look like an episode of miners capitulatin...
Read More
Crypto 07/01/21 07:59 by Bernice Nyambura
Coinbase, Square, Kraken Say New FinCEN Proposed Crypto Regulations Would Be Bad for America
Just before Christmas last year, the Financial Crimes Enforcement Network (FinCEN) rolled out a new proposed regulatory framework aimed at making it easier for the US government to track bitcoin tran...
Read More
Crypto 09/02/21 12:09 by Guest Author
How CryptoAPI by PixelPlex Allows You to Get the Most from Your Decentralized Infrastructure
Since 2013, PixelPlex — an experienced blockchain company— has been providing full-stack blockchain development services. It’s been assisting both giant businesses and startups in unleashing th...
Read More
Bitcoin 29/03/21 16:16 by Olivia Brooke
Over $100 Million Worth of Bitcoin Traded Monthly by Nigerians on WeChat and Telegram
There happen to be more Bitcoin trading activities going on in Nigeria than exchanges are recording. This is because cryptocurrency users are leaning towards simpler channels that filter the technica...
Read More
Bitcoin 12/05/21 19:30 by News BTC
Interview: CEO of OKEx Jay Hao and the Lightning Network Team on Platform’s Adoption of Bitcoin Layer-2 Scalability Solution
The leading global crypto exchange and derivatives trading platform OKEx recently announced support for Bitcoin’s scalability solution, Lightning Network. Regarding the new development, we had t...
Read More