{"id":45822,"date":"2023-02-24T17:21:16","date_gmt":"2023-02-24T21:21:16","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=45822"},"modified":"2023-02-24T17:21:19","modified_gmt":"2023-02-24T21:21:19","slug":"edge-wallet-claims-over-2000-private-keys-were-leaked","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/edge-wallet-claims-over-2000-private-keys-were-leaked\/","title":{"rendered":"Edge Wallet claims over 2000 private keys were leaked"},"content":{"rendered":"\n<p>About 2000 private keys were exposed in a security issue, according to <a href=\"https:\/\/coinscreed.com\/staging\/crypto-wallet-linked-to-mt-gox-hack-moves-10000-btc.html\" target=\"_blank\" rel=\"noreferrer noopener\">mobile crypto wallet Edge<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-1024x536.png\" alt=\"Edge Wallet claims over 2000 private keys were leaked\" class=\"wp-image-45824\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-1024x536.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-300x157.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-768x402.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-1536x804.png 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-1320x691.png 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-150x79.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-750x393.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1-1140x597.png 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Edge Wallet claims over 2000 private keys were leaked<\/figcaption><\/figure>\n\n\n\n<p>As they carry out their investigations, the business has recommended consumers to update to the most recent version of the Edge Wallet. Edge identified a flaw in the app that could allow the disclosure of private keys in an urgent notification on February 22.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Urgent notice:<br><br>We have identified a security vulnerability in Edge which has the potential to have affected a subset of users.<br><br>All users should read the blog post linked below and take immediate action:<a href=\"https:\/\/t.co\/soWkf8U17k\" target=\"_blank\">https:\/\/t.co\/soWkf8U17k<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>&mdash; Edge (@EdgeWallet) <a href=\"https:\/\/twitter.com\/EdgeWallet\/status\/1628516647404437504?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 22, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Over 2000 private keys were compromised by the vulnerability by being sent to Edge infrastructure since keys were visible on the Edge logs server.<\/p>\n\n\n\n<p>This represents less than 0.01% of the about total number of keys created on the platform, according to Edge. However, the business reaffirmed that user payments were remained secure and that the Edge log servers had not been compromised.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cA spot check of several dozen private keys show that many still have funds remaining. Through this, we ascertain that there has not been a wide sweeping compromise of Edge infrastructure which would have compromised a vast majority of funds on such keys.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>According to Edge, the attack took place on February 20. A user who experienced an unauthorized transaction that removed money from their Bitcoin wallet notified the staff of the attack. <\/p>\n\n\n\n<p>Only bitcoin (BTC) was taken; all other assets were left alone. As Edge creates unique master private keys for each wallet, the business concluded that only the <a href=\"https:\/\/www.google.com\/search?q=Edge+Wallet+claims+over+2000+private+keys+were+leaked&client=opera&ei=rc74Y8yZJOfp7_UP05ez6Ag&ved=0ahUKEwiMpKH9s679AhXn9LsIHdPLDI0Q4dUDCA4&uact=5&oq=Edge+Wallet+claims+over+2000+private+keys+were+leaked&gs_lcp=Cgxnd3Mtd2l6LXNlcnAQAzIFCAAQogQyBQgAEKIEMgUIABCiBDIFCAAQogQyBQgAEKIEOg0ILhCPARDqAhC0AhgBOg0IABCPARDqAhC0AhgBOhAILhCPARDUAhDqAhC0AhgBSgQIQRgAUK8LWK8LYIwOaAJwAHgAgAGjAogBowKSAQMyLTGYAQCgAQGgAQKwAQrAAQHaAQQIARgK&sclient=gws-wiz-serp\" target=\"_blank\" rel=\"noreferrer noopener\">user's bitcoin wallet's private key <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>had been hacked and not their account.<\/p>\n\n\n\n<p>Edge said that they had only received a small number of reports of users missing funds totaling under $5 million USD, suggesting that the incident may have been a deliberate attempt to target the users.<\/p>\n\n\n\n<p>The group identified a few activities that might have resulted in a private key vulnerability. The first was the encrypted private key for the wallet would have been stored on the device's disk if a user chose particular choices under the buy and sell tabs.<\/p>\n\n\n\n<p>The second scenario was if users chose to upload logs, which would send the logs\u2014along with the private key, assuming the buy and sell options were chosen\u2014to the Edge servers.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe are continuing investigation including deep device forensics to determine if malware may have had access to the unecrypted private keys on disk.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Since then, the business has recommended users to update to the most recent version of Edge (v3.3.1), which can be downloaded directly from their website, the<a href=\"https:\/\/coinscreed.com\/staging\/sharkbot-malware-reappears-on-google-play-store.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Google Play Store<\/a>, and the App Store.<\/p>\n\n\n\n<p>The new update, according to them, promptly deletes all previous logs from disk and solves all known vulnerabilities concerning wallet private keys.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>About 2000 private keys were exposed in a security issue, according to mobile crypto wallet Edge. As they carry out their investigations, the business has recommended consumers to update to the most recent version of the Edge Wallet. Edge identified a flaw in the app that could allow the disclosure of private keys in an [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":45824,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[2239,13482],"class_list":["post-45822","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-crypto-wallet","tag-edge-wallet"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/02\/EdgeLogoDark-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/45822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=45822"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/45822\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/45824"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=45822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=45822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=45822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}