{"id":71474,"date":"2024-02-15T08:27:38","date_gmt":"2024-02-15T12:27:38","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=71474"},"modified":"2024-02-15T08:27:42","modified_gmt":"2024-02-15T12:27:42","slug":"us-department-of-commerce-investigates-binance-trust-wallet-ios-app","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/us-department-of-commerce-investigates-binance-trust-wallet-ios-app\/","title":{"rendered":"US Department of Commerce Investigates Binance Trust Wallet iOS App"},"content":{"rendered":"\n<p>A division of the U.S. Department of Commerce is analyzing the Binance <a href=\"https:\/\/coinscreed.com\/staging\/trust-wallet-reports-third-party-hack-on-january-17.html\" target=\"_blank\" rel=\"noreferrer noopener\">Trust Wallet <\/a>application in search of a vulnerability that could enable a malicious actor to steal funds from users' crypto wallets.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"630\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51-1024x630.png\" alt=\"US Department of Commerce Investigates Binance Trust Wallet iOS App \" class=\"wp-image-71480\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51-1024x630.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51-300x184.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51-768x472.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51-750x461.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51.png 1031w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">US Department of Commerce Investigates Binance Trust Wallet iOS App <\/figcaption><\/figure>\n\n\n\n<p>The agency responsible for advancing U.S. innovation and industrial competitiveness, the National Institute of Standards and Technology (NIST), has identified a variant of the Binance Trust Wallet application that &#8220;misuses the trezor-crypto library&#8221; to produce mnemonic words that are exclusively verifiable at the entropy source.<\/p>\n\n\n\n<p>Data generation occurs at a physical location known as an entropy source. According to NIST, a similar vulnerability was exploited in July 2023, resulting in economic losses. It elaborated:<\/p>\n\n\n\n<p>\u201cAn attacker can systematically generate mnemonics for each timestamp within an applicable time frame and link them to specific <a href=\"https:\/\/coinscreed.com\/staging\/defi-platform-oasis-will-block-wallet-addresses-deemed-vulnerable.html\" target=\"_blank\" rel=\"noreferrer noopener\">wallet addresses<\/a> in order to steal funds from those wallets.\u201d<\/p>\n\n\n\n<p>Since its disclosure on February 8, the information has presently been undergoing evaluation to ascertain the practical magnitude of the vulnerability.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"493\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-49-750x493.png\" alt=\"\" class=\"wp-image-71478\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-49-750x493.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-49-300x197.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-49-768x504.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-49.png 950w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Binance Trust Wallet app for iOS under investigation for vulnerability. Source: NIST<\/figcaption><\/figure>\n\n\n\n<p>@@<\/p>\n\n\n\n<p>After many Ether wallets were compromised, Secbit Labs reportedly investigated the Binance Trust Wallet app for iOS, as reported by CVE, a program sponsored by the <a href=\"https:\/\/www.dhs.gov\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">U.S. Department of Homeland Security<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>. <\/p>\n\n\n\n<p>The investigators identified a trusted wallet generation vulnerability in the iOS version of the wallet from 2018 and established a correlation between it and the significant robberies that occurred on July 12, 2023.<\/p>\n\n\n\n<p>Milk Sad conducted an independent investigation and discovered a minimum of 6,572 distinct wallet mnemonics that pose a financial risk.<\/p>\n\n\n\n<p>It discovered that the Trust Wallet app for iOS utilized unintended-for-production open-source functions in the &#8220;trezor-crypto library&#8221; to generate new cryptocurrency wallet. After verifying their existence, the statement accused the weak wallets of involvement in the Milk Sad thefts.<\/p>\n\n\n\n<p>NIST will assign a severity-based base score between zero and ten to the application's vulnerability following the conclusion of the investigation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A division of the U.S. Department of Commerce is analyzing the Binance Trust Wallet application in search of a vulnerability that could enable a malicious actor to steal funds from users&#8217; crypto wallets. The agency responsible for advancing U.S. innovation and industrial competitiveness, the National Institute of Standards and Technology (NIST), has identified a variant [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":71480,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[834],"tags":[5521,18427,10743,18428],"class_list":["post-71474","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-binance","tag-binance-2","tag-ios-app","tag-trust-wallet","tag-us-department-of-commerce"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/02\/image-51.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/71474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=71474"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/71474\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/71480"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=71474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=71474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=71474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}