Well-known vulnerability in private keys likely exploited in $160M Wintermute hack

Share This Post

The vulnerability in private keys generated by the popular Profanity vanity key generator was noted in January and has already been implicated in at least one major hack.

Blockchain cybersecurity company Certik has said a vulnerable private key was attacked in the Wintermute hack. A vulnerability in private keys generated by the Profanity app was likely exploited. The vulnerability has been known since at least January.

The U.K.-based algorithmic crypto market maker announced the hack on Tues and said over-the-counter and centralized finance operations were not affected. About $162.5 million worth of cryptocurrencies were taken. “We are solvent with twice over that amount in equity left,” Wintermute CEO Evgeny Gaevoy said in a tweet.

Certik said in a blog post that the hack was due to a leaked or brute-forced private key, and not a smart contract vulnerability:

“The exploiter used a privileged function with the private key leak to specify that the swap contract was the attacker controlled contract.”

The company added that a vulnerability in the popular Profanity vanity address generator was probably at fault in the hack.

Certik noted that decentralized exchange 1inch Network disclosed the apparent Profanity vulnerability in a Sept. 13 blogpost and subsequent warning on Twitter. 1inch users spotted the vulnerability after a suspicious airdrop took place in June. 1inch said on its blog:

“Profanity is one of the most popular tools due to its high efficiency. Sadly, that could only mean that most of the Profanity wallets were secretly hacked.”

The vulnerability was blamed for the hacking of $3.3 million on Sept. 13. GitHub users spotted the issue in January 2022, leading the developer to abandon the project and then archive it on Sept. 15.

A private key is derived from a user’s seed phrase, which is a list of 12-24 words associated with a wallet that allows a user to recover the cryptocurrency in a wallet, even if the wallet is lost or deleted.

Related: Polygon CSO blames Web2 security gaps for recent spate of hacks

According to Certik, around $273.9 million has been lost this year due to compromised private keys, making the method “one of the largest attack vectors.” The Wintermute attack is by far the largest, with the Harmony Protocol hack in June coming in second at $97 million.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

XRP Market Update: Bears Target $2.10 Breakdown in Volatile Trading

XRP is dancing at $216, with a market value of $123 billion and a 24-hour trading hustle of $221 billion, bouncing between $215 and $220 as technical indicators send mixed vibes on where the price is

Dogecoin Price Could Soar To $23 Based On These Bullish Fractals

The Dogecoin price has struggled to build on its bullish momentum over the past few weeks, sinking to as low as $0267 on December 20 However, the meme coin appears to have stabilized just above the

Bitcoin Exchange Netflow-To-Reserve Ratio: New Metric Reveals BTC Accumulation

Bitcoin is currently navigating a volatile phase, consolidating below the $100,000 mark after failing to hold it as a key support level This recent setback has sparked uncertainty among investors,

Low Market Cap Cryptos Offering High-Risk, High-Reward Opportunities!

The post Low Market Cap Cryptos Offering High-Risk, High-Reward Opportunities! appeared first on Coinpedia Fintech News Digital currencies with smaller market values often hide opportunities for

Crypto Giants Stir: Vintage BTC Wallets Shift Millions, 1,940 Genesis ETH Lands on Coinbase

With the crypto market’s valuation sitting at $333 trillion and bitcoin holding steady above the $90,000 range for a cumulative 43 non-consecutive days, an intriguing trend has

These Cryptos Could Lead the Next Crypto Bull Run With Explosive Gains

The post These Cryptos Could Lead the Next Crypto Bull Run With Explosive Gains appeared first on Coinpedia Fintech News The crypto market is ablaze, and with Bitcoin reaching a new all-time high and