Bitcoin Forum
April 23, 2024, 07:31:23 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Disclosure: Key generation vulnerability found on WalletGenerator.net  (Read 182 times)
409H (OP)
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
May 24, 2019, 02:14:39 PM
Last edit: May 24, 2019, 03:01:28 PM by 409H
Merited by Avirunes (2)
 #1

⚠️ SECURITY ALERT ⚠️

After thorough investigation, we have reason to believe that anyone who has used a wallet from hxxp://WalletGenerator[.]net  from August 17 2018 and onward is at risk of losing their funds.

FULL DETAILS: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

TL;DR
Who is affected: Anyone who has put funds in a public/private key generated via WalletGenerator.net after August 17, 2018.
When: August 17, 2018 — Huh. While the malicious behavior is not presently found as of May 24, 2019, it could be reintroduced at any point.
What happened: There were changes to the code being served via WalletGenerator.net that resulted in duplicate keypairs being provided to users. These generated keypairs were also potentially stored server-side.
What you should do if you are affected: Securely create a new keypair / wallet and move your funds to that new, secure address. Some folks have recommended using bitaddress (offline) via https://github.com/pointbiz/bitaddress.org.
1713857483
Hero Member
*
Offline Offline

Posts: 1713857483

View Profile Personal Message (Offline)

Ignore
1713857483
Reply with quote  #2

1713857483
Report to moderator
1713857483
Hero Member
*
Offline Offline

Posts: 1713857483

View Profile Personal Message (Offline)

Ignore
1713857483
Reply with quote  #2

1713857483
Report to moderator
1713857483
Hero Member
*
Offline Offline

Posts: 1713857483

View Profile Personal Message (Offline)

Ignore
1713857483
Reply with quote  #2

1713857483
Report to moderator
TalkImg was created especially for hosting images on bitcointalk.org: try it next time you want to post an image
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713857483
Hero Member
*
Offline Offline

Posts: 1713857483

View Profile Personal Message (Offline)

Ignore
1713857483
Reply with quote  #2

1713857483
Report to moderator
1713857483
Hero Member
*
Offline Offline

Posts: 1713857483

View Profile Personal Message (Offline)

Ignore
1713857483
Reply with quote  #2

1713857483
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6965



View Profile WWW
May 24, 2019, 04:17:10 PM
Merited by Avirunes (1)
 #2

Well, people shouldn’t be using online websites nor remain connected to the internet when generating a paper wallet. The point of it is that you have to download a safe and open source generator and run it in an airgapped machine. When you do that in a .org website, you can’t actually be sure about what is happening behind the scenes.

Thanks for the warning tho. I remember I’ve used this paper wallet generator multiple times in the past years. Thankfully, I only hold my coins on a hardware wallet now.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Avirunes
Legendary
*
Offline Offline

Activity: 3094
Merit: 1468


View Profile WWW
May 24, 2019, 04:58:47 PM
 #3

Never thought that there would be a way to cross the users like this. Gotta turn on my habit of offline generation of address from now onwards. I wonder why there wasn't any announcements regarding the site being sold especially if many users trust the sites to generate wallets.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!