{"id":75774,"date":"2023-03-17T18:12:23","date_gmt":"2023-03-17T16:12:23","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=75774"},"modified":"2025-09-10T13:31:59","modified_gmt":"2025-09-10T10:31:59","slug":"fireblocks-reveals-details-of-patched-vulnerability-in-bitgo-wallets","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/fireblocks-reveals-details-of-patched-vulnerability-in-bitgo-wallets\/","title":{"rendered":"Fireblocks reveals details of patched vulnerability in BitGo wallets"},"content":{"rendered":"<p>The security department of Fireblocks, the crypto custody services provider, <a href=\"https:\/\/www.fireblocks.com\/blog\/bitgo-wallet-zero-proof-vulnerability\">revealed<\/a> details of the vulnerability in BitGo&#8217;s wallets.<\/p>\n<p>According to the report, the exploit was detected in December 2022 \u2014 at that time the platform suspended wallet operations. In February 2023, the BitGo team implemented fixes and asked its clients to update to the latest version by March 17.<\/p>\n<p>The vulnerability itself resided in the wallets&#8217; <a href=\"https:\/\/hub.forklog.com\/vvedenie-v-porogovuyu-podpis-tss-i-drugie-kriptograficheskie-primitivy\/\">threshold signature<\/a> scheme and arose due to a flaw in the <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-zero-knowledge-proof\">ZK<\/a>-protocol.<\/p>\n<p>Using it, a potential attacker could access users&#8217; private keys in just a few seconds of computation, bypassing all levels of protection.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;The vulnerability is the result of the wallet provider not adhering to proven cryptographic standards,&#8221; said Idan Ofrat, co-founder and chief technology officer of Fireblocks.<\/p>\n<\/blockquote>\n<p>The company added that they worked closely with BitGo to fix the flaw and raise the security level.<\/p>\n<p>Experts also warned that some wallets could already have been compromised. Users who registered their addresses before the exploit was fixed are advised to create new accounts.<\/p>\n<p>In March 2023, MetaMask <a href=\"https:\/\/forklog.com\/en\/news\/metamask-fixes-privacy-flaw-linked-to-account-merging\">fixed<\/a> the privacy issue related to account merging.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fireblocks&#8217; security team disclosed details of the vulnerability in BitGo&#8217;s wallets.<\/p>\n","protected":false},"author":1,"featured_media":75775,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[194,1301,1386],"class_list":["post-75774","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-bitgo","tag-blockchain-vulnerabilities","tag-fireblocks"],"aioseo_notices":[],"amp_enabled":true,"views":"21","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/75774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=75774"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/75774\/revisions"}],"predecessor-version":[{"id":75776,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/75774\/revisions\/75776"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/75775"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=75774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=75774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=75774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}