Papers1 provider · 1 record
January 1, 2014· IACR Cryptology ePrint Archive
preprint

Private Key Recovery Combination Attacks: On Extreme Fragility of Popular Bitcoin Key Management, Wallet and Cold Storage Solutions in Presence of Poor RNG Events.

Authors:Nicolas T. CourtoisPinar EmirdagFilippo Valsorda

Abstract

Abstract. In this paper we study the question of key management and practical operational security in bitcoin digital currency storage systems. We study the security two most used bitcoin HD Wallet key management solutions (e.g. in BIP032 and in earlier systems). These systems have ex-tensive audit capabilities but this property comes at a very high price. They are excessively fragile. One small security incident in a remote corner of the system and everything collapses, all private keys can be re-covered and ALL bitcoins within the remit of the system can be stolen. Privilege escalation attacks on HD Wallet solutions are not new. In this paper we take it much further. We propose new more advanced combi-nation attacks in which the security of keys hold in cold storage can be compromised without executing any software exploit on the cold sys-tem, but through security incidents at operation such as bad random number or related random events. In our new attacks all bitcoins over whole large security domains can be

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.