The National Institute of Standards and Technology is analyzing the iOS version of the Binance Trust Wallet app for a vulnerability that could potentially be used to steal funds from crypto wallets. ---

US investigates Binance Trust Wallet iOS app for vulnerability ***

US investigates Binance Trust Wallet iOS app for vulnerability
Staff Member
Thursday 15th of February 2024 04:30:00 PM 3 min read

An agency of the United States Department of Commerce is analyzing the Binance Trust Wallet app for a vulnerability that could allow an attacker to steal funds from crypto wallets.

According to the National Institute of Standards and Technology (NIST) — the agency tasked with promoting U.S. innovation and industrial competitiveness — a specific version of the Binance Trust Wallet app “misuses the trezor-crypto library” to generate mnemonic words that can be verified only at the entropy source.

An entropy source is a physical location from where data is generated. NIST noted that a similar vulnerability was exploited in July 2023, leading to economic losses. It explained:

“An attacker can systematically generate mnemonics for each timestamp within an applicable time frame, and link them to specific wallet addresses in order to steal funds from those wallets.”

The information was made public on Feb. 8 and is currently awaiting analysis to determine the real-world scope of the vulnerability.

According to CVE — a program sponsored by the U.S. Department of Homeland Security — Secbit Labs began investigating the Binance Trust Wallet app for iOS after numerous Ether wallets were hacked. The researchers tracked down an older wallet generation weakness in the iOS platform version of Trust Wallet from 2018 and connected it to the large thefts on July 12, 2023. 

Binance did not respond to Cointelegraph’s request for comment. However, an independent investigation by Milk Sad found at least 6,572 unique wallet mnemonics that risk loss of funds.

It found the Trust Wallet app for iOS using an open-source code for generating new cryptocurrency wallets using unsafe functions in the “trezor-crypto library” that were not meant for production. After confirming that the weak wallets existed, it alleged that they were involved in the Milk Sad thefts.

Upon completing the investigation, NIST will allot a base score to the app’s vulnerability ranging from 0-10, depending on its severity.

Source

Comments

Trade cryptocurrency with ease and enjoy low trading fees!
Trade cryptocurrency with ease and enjoy low trading fees!

Quickly and easily trade cryptocurrency at Wollito.com

Find your answers instantly in our Support Center
Find your answers instantly in our Support Center

Taking good care of our customers is our top priority. Wollito Customer Support is here to pro...

Wollito NFT - Coming Soon
Wollito NFT - Coming Soon

List your NFT for FREE with Wollito NFT's.