Bitcoin Forum
May 04, 2024, 08:58:53 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Electrum code vulnerable like the Parity multisig wallet?  (Read 498 times)
adaseb (OP)
Legendary
*
Offline Offline

Activity: 3752
Merit: 1710



View Profile
July 20, 2017, 12:17:20 AM
 #1

I am not a coder so I don't have much depth into this situation but wondering if Electrum could have a similar vulnerability such as the Parity multisig wallet which was hacked earlier today.

Don't know how much of the code is similiar since its Bitcoin based and Parity was mostly Ethereum based.


.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714856333
Hero Member
*
Offline Offline

Posts: 1714856333

View Profile Personal Message (Offline)

Ignore
1714856333
Reply with quote  #2

1714856333
Report to moderator
1714856333
Hero Member
*
Offline Offline

Posts: 1714856333

View Profile Personal Message (Offline)

Ignore
1714856333
Reply with quote  #2

1714856333
Report to moderator
1714856333
Hero Member
*
Offline Offline

Posts: 1714856333

View Profile Personal Message (Offline)

Ignore
1714856333
Reply with quote  #2

1714856333
Report to moderator
pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10546



View Profile
July 20, 2017, 04:14:36 AM
 #2

i am not completely familiar with ethereum stuff but the multisig in ethereum is very different from multisig in bitcoin so there shouldn't be anything to worry about your bitcoin if you have them in a multisig address.
and besides bitcoin code, specifically P2SH is reviewed properly, tested, used for a long time and you can trust it.
i can not say the same for ETH code. and anything regarding their wallets, bugs and serious bugs leading to funds loss is becoming a very common thing with ETH.

in any case you can read this to get the general idea of difference:
https://ethereum.stackexchange.com/questions/6/how-can-i-create-a-multisignature-address-on-ethereum

Maybe mETH will rewind their blockchain again and create Ethereum SuperClassic - lol !!!   Cool
i don't think Vitalik or the Foundation lost anything so don't get your hopes up Wink
and i call for Ethereum Legacy for the name of new chain

oh and by the way DAO hack was 50 million dollar and this is  $32 million and growing. and if you add the white hat hack to it, then it is about $100 million dollar hack.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4166


View Profile
July 20, 2017, 12:14:37 PM
 #3

I am not a coder so I don't have much depth into this situation but wondering if Electrum could have a similar vulnerability such as the Parity multisig wallet which was hacked earlier today.

Don't know how much of the code is similiar since its Bitcoin based and Parity was mostly Ethereum based.
The Ethereum Multisig works differently from Bitcoin's multisig. The vulnerability allowed attackers to change the owner to their own and thus are able to authorise the transactions themselves. The issue was stemmed from a simple bug. This is not possible with Bitcoin however. To spend from a multisig address, you need the redeem script and the signatures of at least N addresses.

There is no way that anyone can change the address used to create the multisig.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
adaseb (OP)
Legendary
*
Offline Offline

Activity: 3752
Merit: 1710



View Profile
July 20, 2017, 10:54:54 PM
 #4

I am not a coder so I don't have much depth into this situation but wondering if Electrum could have a similar vulnerability such as the Parity multisig wallet which was hacked earlier today.

Don't know how much of the code is similiar since its Bitcoin based and Parity was mostly Ethereum based.
The Ethereum Multisig works differently from Bitcoin's multisig. The vulnerability allowed attackers to change the owner to their own and thus are able to authorise the transactions themselves. The issue was stemmed from a simple bug. This is not possible with Bitcoin however. To spend from a multisig address, you need the redeem script and the signatures of at least N addresses.

There is no way that anyone can change the address used to create the multisig.

Wasn't Bitfinex hacked a year ago a similiar way? They had a multisig wallet and they got hacked?

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
July 21, 2017, 08:54:00 AM
 #5

Wasn't Bitfinex hacked a year ago a similiar way? They had a multisig wallet and they got hacked?
Because they'd set up a stupid system whereby BitGo (the external party) would just Auto authorise whatever transactions were sent to it for signing...

Hacker "hacked Bitfinex"/got their key (inside job?)... Created transactions sending 120,000 BTC to themselves... BitGo blindly co-signed the transactions... Hacker got rich... Bitfinex users all took a 36% hit to share the pain... Undecided

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!