Bitcoin Forum
July 09, 2024, 05:05:34 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Disclosure: Key generation vulnerability found on WalletGenerator.net  (Read 182 times)
409H (OP)
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
May 24, 2019, 02:14:39 PM
Last edit: May 24, 2019, 03:01:28 PM by 409H
Merited by Avirunes (2)
 #1

⚠️ SECURITY ALERT ⚠️

After thorough investigation, we have reason to believe that anyone who has used a wallet from hxxp://WalletGenerator[.]net  from August 17 2018 and onward is at risk of losing their funds.

FULL DETAILS: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

TL;DR
Who is affected: Anyone who has put funds in a public/private key generated via WalletGenerator.net after August 17, 2018.
When: August 17, 2018 — Huh. While the malicious behavior is not presently found as of May 24, 2019, it could be reintroduced at any point.
What happened: There were changes to the code being served via WalletGenerator.net that resulted in duplicate keypairs being provided to users. These generated keypairs were also potentially stored server-side.
What you should do if you are affected: Securely create a new keypair / wallet and move your funds to that new, secure address. Some folks have recommended using bitaddress (offline) via https://github.com/pointbiz/bitaddress.org.
TryNinja
Legendary
*
Offline Offline

Activity: 2884
Merit: 7190


Top Crypto Casino


View Profile WWW
May 24, 2019, 04:17:10 PM
Merited by Avirunes (1)
 #2

Well, people shouldn’t be using online websites nor remain connected to the internet when generating a paper wallet. The point of it is that you have to download a safe and open source generator and run it in an airgapped machine. When you do that in a .org website, you can’t actually be sure about what is happening behind the scenes.

Thanks for the warning tho. I remember I’ve used this paper wallet generator multiple times in the past years. Thankfully, I only hold my coins on a hardware wallet now.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Avirunes
Legendary
*
Offline Offline

Activity: 3094
Merit: 1468


View Profile WWW
May 24, 2019, 04:58:47 PM
 #3

Never thought that there would be a way to cross the users like this. Gotta turn on my habit of offline generation of address from now onwards. I wonder why there wasn't any announcements regarding the site being sold especially if many users trust the sites to generate wallets.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!