{"id":56336,"date":"2023-08-10T07:59:20","date_gmt":"2023-08-10T11:59:20","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=56336"},"modified":"2023-08-10T07:59:23","modified_gmt":"2023-08-10T11:59:23","slug":"binance-tss-library-fixes-bitforge-bug-no-funds-lost","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/binance-tss-library-fixes-bitforge-bug-no-funds-lost\/","title":{"rendered":"Binance TSS Library Fixes BitForge Bug, No Funds Lost"},"content":{"rendered":"\n<p>Binance\u2019s CEO <a href=\"https:\/\/coinscreed.com\/staging\/binance-founder-changpeng-zhao-says-us-crypto-exchange-will-go-public-in-three-years.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Changpeng Zhao<\/a>, has confirmed that the BitForge vulnerability, which affected several MPC protocols, has been fixed in the TSS Library that Binance open-sourced. He also thanked Fireblocks for uncovering the issue and assured users that their funds are safe.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-1024x683.jpg\" alt=\"Binance TSS Library Fixes BitForge Bug, No Funds Lost\" class=\"wp-image-56341\" style=\"width:864px;height:576px\" width=\"864\" height=\"576\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-1024x683.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-300x200.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-768x512.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-750x500.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance-1140x760.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance.jpg 1200w\" sizes=\"(max-width: 864px) 100vw, 864px\" \/><\/figure>\n\n\n\n<p>Binance, one of the world\u2019s largest crypto exchanges, has addressed the BitForge vulnerability, a security issue that impacted several multi-party computation (MPC) protocols used by crypto wallet providers. <\/p>\n\n\n\n<p>Binance\u2019s CEO Changpeng Zhao (CZ) said that the vulnerability was present in the <a href=\"https:\/\/github.com\/bnb-chain\/tss-lib\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Threshold Signature Scheme (TSS) Library<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> that Binance open-sourced, but it has been fixed, and no user funds were affected.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-bitforge-poses-a-security-threat-to-mpc-protocols\">BitForge Poses a Security threat to MPC protocols<\/h3>\n\n\n\n<p>The BitForge vulnerability was discovered by Fireblocks, a digital asset infrastructure company, and disclosed in a press release on August 9. <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ The Fireblocks research team has uncovered BitForge, a set of vulnerabilities in some of the most widely adopted MPC protocols, that allow an attacker to retrieve a private key from a single device. Read on \u2192 <a href=\"https:\/\/t.co\/xo2r9zgCvj\" target=\"_blank\">https:\/\/t.co\/xo2r9zgCvj<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/7q1nEeVBwO\" target=\"_blank\">pic.twitter.com\/7q1nEeVBwO<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Fireblocks (@FireblocksHQ) <a href=\"https:\/\/twitter.com\/FireblocksHQ\/status\/1689389347274162178?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">August 9, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>According to <a href=\"https:\/\/www.fireblocks.com\/blog\/bitforge-fireblocks-researchers-uncover-vulnerabilities-in-over-15-major-wallet-providers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fireblocks,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> the vulnerability affected widely adopted MPC protocols, such as <strong>GG-18, GG-20, and Lindell17. <\/strong><\/p>\n\n\n\n<p>MPC protocols allow multiple parties to control and manage cryptocurrency holdings without disclosing their private keys.<\/p>\n\n\n\n<p>The vulnerability could allow attackers with privileged access to extract the full private key from a single device and drain funds from the wallets of millions of retail and institutional customers in seconds without their knowledge or consent. <\/p>\n\n\n\n<p>Fireblocks said it notified over <strong>15 wallet providers<\/strong> and projects potentially at risk and helped them fix the issue.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Binance\u2019s Response to the BitForge Vulnerability<\/h3>\n\n\n\n<p>Binance\u2019s CZ confirmed via <a href=\"https:\/\/twitter.com\/cz_binance\/status\/1689556596332867584\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Twitter<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> that the BitForge vulnerability was present in the TSS Library that Binance open-sourced, which implements a threshold signature scheme for <a href=\"https:\/\/www.encryptionconsulting.com\/education-center\/what-is-ecdsa\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ECDSA<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> and <a href=\"https:\/\/en.wikipedia.org\/wiki\/EdDSA\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">EDDSA.<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <\/p>\n\n\n\n<p>He reported that the issue had been fixed and thanked Fireblocks for uncovering it. He also assured users that no Binance user funds were compromised.<\/p>\n\n\n\n<p>CZ also advised users to remain <a href=\"https:\/\/themoneymongers.com\/safu-hodl-cryptocurrency-slangs\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">#SAFU,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> a term coined by Binance to promote security awareness among its users. <\/p>\n\n\n\n<p>He also stated that Binance will continue contributing to open-source blockchain development and improving funds and information security for <a href=\"https:\/\/coinscreed.com\/staging\/bnb-chain-launches-layer-2-solution-testnet.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BNB Chain,<\/a> Bitcoin networks, and more.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security and Transparency Challenges for Crypto Wallet Providers<\/h2>\n\n\n\n<p>The BitForge vulnerability highlights the importance of security and transparency in the crypto industry, especially for wallet providers and custodians who handle large amounts of funds. <\/p>\n\n\n\n<p>It also shows the need for collaboration and communication among different projects and platforms to identify and fix potential security issues before they cause any harm.<\/p>\n\n\n\n<p>Fireblocks\u2019 co-founder and CTO Pavel Berengoltz said that not all MPC developers and teams are created equal and urged users to do their due diligence before choosing a wallet provider. <\/p>\n\n\n\n<p>He also said that Fireblocks will continue to conduct research and share its findings with the community to enhance the security and reliability of MPC protocols.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Binance\u2019s CEO Changpeng Zhao, has confirmed that the BitForge vulnerability, which affected several MPC protocols, has been fixed in the TSS Library that Binance open-sourced. He also thanked Fireblocks for uncovering the issue and assured users that their funds are safe. Binance, one of the world\u2019s largest crypto exchanges, has addressed the BitForge vulnerability, a [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":56341,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[32],"tags":[5521,5407,15647,202,1406,14793],"class_list":["post-56336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-exchange-news","tag-binance-2","tag-changpeng-zhao-cz","tag-bitforge","tag-blockchain","tag-crypto-exchange","tag-mpc"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/CZ-Binance.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/56336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=56336"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/56336\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/56341"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=56336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=56336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=56336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}