Bitcoin Forum
April 26, 2024, 05:27:44 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Disclosure: Key generation vulnerability found on WalletGenerator.net  (Read 182 times)
409H (OP)
Newbie
*
Offline Offline

Activity: 7
Merit: 4


View Profile WWW
May 24, 2019, 02:14:39 PM
Last edit: May 24, 2019, 03:01:28 PM by 409H
Merited by Avirunes (2)
 #1

⚠️ SECURITY ALERT ⚠️

After thorough investigation, we have reason to believe that anyone who has used a wallet from hxxp://WalletGenerator[.]net  from August 17 2018 and onward is at risk of losing their funds.

FULL DETAILS: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

TL;DR
Who is affected: Anyone who has put funds in a public/private key generated via WalletGenerator.net after August 17, 2018.
When: August 17, 2018 — Huh. While the malicious behavior is not presently found as of May 24, 2019, it could be reintroduced at any point.
What happened: There were changes to the code being served via WalletGenerator.net that resulted in duplicate keypairs being provided to users. These generated keypairs were also potentially stored server-side.
What you should do if you are affected: Securely create a new keypair / wallet and move your funds to that new, secure address. Some folks have recommended using bitaddress (offline) via https://github.com/pointbiz/bitaddress.org.
1714152464
Hero Member
*
Offline Offline

Posts: 1714152464

View Profile Personal Message (Offline)

Ignore
1714152464
Reply with quote  #2

1714152464
Report to moderator
1714152464
Hero Member
*
Offline Offline

Posts: 1714152464

View Profile Personal Message (Offline)

Ignore
1714152464
Reply with quote  #2

1714152464
Report to moderator
1714152464
Hero Member
*
Offline Offline

Posts: 1714152464

View Profile Personal Message (Offline)

Ignore
1714152464
Reply with quote  #2

1714152464
Report to moderator
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714152464
Hero Member
*
Offline Offline

Posts: 1714152464

View Profile Personal Message (Offline)

Ignore
1714152464
Reply with quote  #2

1714152464
Report to moderator
1714152464
Hero Member
*
Offline Offline

Posts: 1714152464

View Profile Personal Message (Offline)

Ignore
1714152464
Reply with quote  #2

1714152464
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2814
Merit: 6971



View Profile WWW
May 24, 2019, 04:17:10 PM
Merited by Avirunes (1)
 #2

Well, people shouldn’t be using online websites nor remain connected to the internet when generating a paper wallet. The point of it is that you have to download a safe and open source generator and run it in an airgapped machine. When you do that in a .org website, you can’t actually be sure about what is happening behind the scenes.

Thanks for the warning tho. I remember I’ve used this paper wallet generator multiple times in the past years. Thankfully, I only hold my coins on a hardware wallet now.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Avirunes
Legendary
*
Offline Offline

Activity: 3094
Merit: 1468


View Profile WWW
May 24, 2019, 04:58:47 PM
 #3

Never thought that there would be a way to cross the users like this. Gotta turn on my habit of offline generation of address from now onwards. I wonder why there wasn't any announcements regarding the site being sold especially if many users trust the sites to generate wallets.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!