US agency flags security flaw in Binance self-custody wallet

abdelaziz Fathi

The US National Institute of Standards and Technology (NIST) has pinpointed a critical vulnerability in the iOS version of the “Binance Trust Wallet.”

Binance USD

The flaw was detailed in the Common Vulnerabilities and Exposures (CVE) database on February 8, which means it presents a significant risk that could enable attackers to siphon off funds from unsuspecting users’ digital wallets.

This vulnerability arises from a misuse of the trezor-crypto library within the Trust Wallet app. Specifically, the mnemonic words — a series of words generated to provide access to cryptocurrencies — are created in a manner that might only be secure at the entropy source, essentially the starting point for data generation. The CVE database entry reveals that this security gap has already been exploited, with incidents in July 2023 showing attackers could guess these mnemonic words, leading to unauthorized access and financial losses.

NIST, which is a key agency within the U.S. Department of Commerce tasked with shaping technology and cybersecurity standards, said its ongoing investigation seeks to assess the real-world impact of this flaw. The severity of the vulnerability will eventually be scored on a scale from 0 to 10, reflecting its potential danger to users.

The backdrop to this issue is a series of cyber incidents faced by Trust Wallet in 2023, cumulating in losses exceeding $4 million. Trust Wallet, which was acquired by the cryptocurrency giant Binance in 2018, has since seen launch the exchange’s own Web3 wallet.

An independent probe by Milk Sad has shed additional light on the matter, identifying over 6,572 unique wallet mnemonics at risk. This investigation shows the use of unsafe functions within the trezor-crypto library, not intended for production use, that led to the creation of vulnerable wallets. These wallets are believed to be linked to the so-called Milk Sad thefts.

In response to the news, a Binance spokesperson clarified that Trust Wallet now operates as a separate legal entity, distinct from the group. The move came as the exchange discontinued its fiat-to-crypto payment platform, Binance Connect, just one year after its official launch in March 2022.

Binance Connect was initially introduced to facilitate crypto payments for merchants, aiming to assist businesses in becoming “crypto-ready.” The service provided support for over 50 cryptocurrencies and accepted major payment methods, including Visa and Mastercard. It served as a fiat-to-crypto payments gateway, bridging the gap between crypto and traditional financial systems, as well as the fiat-to-crypto on-ramp for the exchange’s self-custody Trust Wallet.

Read this next

blockdag

Top Potential Binance Listings to Keep an Eye on in 2024

As the largest cryptocurrency exchange in terms of trading volume, Binance significantly influences the crypto market. When a coin gets listed on Binance, it often experiences a sharp increase in price, which can be amplified by favorable market conditions.

blockdag

BlockDAG Reigns With Exceptional $24.9M Presale While Optimism & Shiba Inu Prices Surge in May

Discover the May 2024 crypto forecast: Shiba Inu’s rally post-Shibarium upgrade, Optimism’s Layer 3 innovation, and BlockDAG’s $24.9M presale success.

Retail FX

Weekly Roundup: Colombian president funded by crypto scam, Coinbase sued over Solana

The FX, Fintech, and cryptocurrency markets have been buzzing with action this past week, as usual. Stay in the loop and ahead of the game with a handpicked collection of top updates and stories.

blockdag

BlockDAG Lights Up Piccadilly Circus in Celebration of CoinMarketCap Listing: More On Polkadot (DOT) Price & LINK

Explore BlockDAG’s showcase at  Piccadilly Circus and its potential for 30,000x ROI. Dive into Chainlink’s Potential for growth and Polkadot’s price dynamics.

Digital Assets

Colombian president under fire for Daily COP’s crypto donations

Colombian President Gustavo Petro is embroiled in controversy following allegations that he accepted over $500,000 in cryptocurrency from a fraudulent crypto project to fund his 2022 presidential campaign.

Financewire

Enter the Wasteland: Survive, Conquer and Thrive in a Post-Apocalyptic Playground with DECIMATED

As the digital dawn of gaming rises, the visionary minds behind DECIMATED are ecstatic to unveil their groundbreaking foray into the desolate yet captivating future of online gaming.

Retail FX

Trading 212 offers multi-currency cards to its clients

London-based online broker Trading 212 has teamed up with Paynetics, a regulated e-money services provider, to offer real-time payment and banking services to customers.

Digital Assets

Kraken says SEC lawsuit overhauls US financial regulation

Cryptocurrency exchange Kraken is pushing for a U.S. court to dismiss a lawsuit filed by the Securities and Exchange Commission (SEC), arguing that the suit could lead to an undue expansion of the regulatory body’s authority over the crypto industry.

blockdag

Influencers Spotlight BlockDAG’s Mining Technology and $24.6M Presale as it Outshines Shiba Inu and Polkadot

Discover how BDAG’s groundbreaking X1 mining app and strong YouTube influencer support outperform Shiba Inu’s adoption and Polkadot’s market strategies.

<