Security Researchers Break Down McAfee-Endorsed Cryptocurrency Wallet, Find Nothing but a Cheap Smartphone

Security Researchers Break Down McAfee-Endorsed Cryptocurrency Wallet, Find Nothing but a Cheap Smartphone
ôîòî ïîêàçàíî ñ : btcmanager.com

2018-8-3 19:00

The world’s first “unhackable” cryptocurrency wallet, as claimed by John McAfee, faced the wrath of security researchers soon after its announcement on July 28, 2018.

Not so Unhackable

Cybersecurity blogger Ryan Castellucci first called out Bitfi’s supposed security features on his blog, breaking down several aspects that struck experts as suspicious. Post Castelluci’s coverage, researchers stated their findings and opinions over Twitter and Reddit.

For the uninitiated, McAfee advertised the Bitfi wallet on July 24, 2018, via Twitter, offering a bounty of $100,000 to anyone who can hack the “unhackable wallet.” Bitfi further claimed the amount was not a mere gimmick, priding on their “absolute security.”

However, Castellucci and others found out the wallet lacks sophisticated security software and closely resembled an entirely different device, calling it a “cheap stripped down Android phone” based on released photos.

Don’t trust the new BitFi hardware wallet. pic.twitter.com/ywFG8pS0Ms

— Whalepool (@whalepool) July 28, 2018

Researchers have compiled a substantial list of directories, available for public viewing on Pastebin, which load on the device’s RAM during startup. This step gives them an overview of all processes pre-installed on the Bitfi wallet.

While investigations revealed the lack of internal cold storage, researchers were most startled by the presence of a malware application called Adups FOTA, which infamously relays sensitive user data, such as calls, texts, and location, to its servers in China after a recurring period of 72 hours.

Tracking Device or Storage Device?

Bitfi additionally features a pre-installed version of Baidu, a Chinese application with inbuilt GPS tracking functionality. Alarmingly, both applications in question seemed to be transmitting data to Chinese servers during tests.

Update on the BitFi device so far

Most of the firmware looks just like a normal MTK phone, including:
– A Baidu GPS/WIFI tracker
– The well-known Adups FOTA malware suite
– The entire Mediatek library of example apps
– A tracker, capable of logging all activity on the device
1/2

— OverSoft (@OverSoftNL) July 30, 2018

Interestingly, the bounty comes with its own set of terms and conditions. Researchers have first to purchase a $120 Bitfi device, pay $10 to load it with coins, and then hack their own device. Castellucci added:

“A researcher found, for example, [if] the device had a weak RNG that allowed for key recovery by examining a series of transactions generated by it, they would not win the bounty. Neither would they for finding a way to hijack their automatic update system to install a keylogger.”

Other security researchers shared their findings on Twitter:

So now we have pictures of the bare @Bitfi6 board.

It's just a MEDIATEK MT6580.

No sign of a secure element.

Thanks to @Mindstalker612 pic.twitter.com/uhtYDxcQlm

— Ask Cybergibbons! (@cybergibbons) July 29, 2018

From what it seems, Bitfi has purchased cheap mobile phones in bulk and shipped them on the pretext of a cryptocurrency wallet, with no regard for data privacy or the potential loss of funds.

Meanwhile, McAfee confirmed the absence of internal storage on the Bitfi device on Twitter, stated the wallet receives instructions “for each coin from our servers.” This aspect makes the product nothing more than an online wallet offering with a dedicated device for accessibility.

The post Security Researchers Break Down McAfee-Endorsed Cryptocurrency Wallet, Find Nothing but a Cheap Smartphone appeared first on BTCMANAGER.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Global Cryptocurrency (GCC) íà Currencies.ru

$ 0 (+0.00%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 0.00 %, 7d: 0.00 %
Cåãîäíÿ L: $0 - H: $0
Êàïèòàëèçàöèÿ $0 Rank 99999
Öåíà â ÷àñ íîâîñòè $ 0.0024869 (-100%)

researchers security wallet cryptocurrency down unhackable cheap

researchers security → Ðåçóëüòàòîâ: 24


Ôîòî:

Security researchers attack the McCaffy-Backed Vault for “unopened” demands

Operating in such an environment, cautious users are always mindful of their security and learn to avoid outrageous claims that are sometimes nothing more than just that. A recently released wallet was said to be “unhackable” by its promoters, including John McAfee, and this has naturally triggered security researchers. Also Read: Football Team in Gibraltar

2018-8-1 09:29


Bitcoin Researchers Propose New Transaction Ordering Rule

Technology & Security This week four Bitcoin Cash (BCH) researchers and developers proposed a different transaction sorting process for the BCH protocol called ‘canonical transaction ordering.’ The proposed method would sort transactions against their identifiers, rather than the current topological transaction ordering rule, making it easier to for the network to process very large blocks.

2018-6-14 05:10