The US- based Independent Security Evaluators (ISE) has published a report on private keys for the Ethereum blockchain. A hacker managed to correctly guess several weak private keys, resulting in the theft of 45,000 ether (ETH).
Cointelegraph reached out to Adrian Bednarek, senior security at ISE, to learn more about this case.
Bednarek said in his interview that he discovered the hacker's activity by accident. At the time, he was engaged in another investigation.
“Generating a private key was one of the components we had to research. I was trying to understand the basics of the private key in Ethereum: How long is it? How is it generated? And how is it used to derive the public key and public address.”.
All major blockchains (e.g. Ethereum, bitcoin) that support the ECDSA (Elliptic Digital Signature Algorithm) protocol have 256-bit private keys. Predicting such a large key is extremely difficult. For this reason, researchers at ISE divided them into eight 32-bit “sub-regions”.
These 8 parts contained a total of 34 billion weak keys, which were scanned by the researchers. This process took an entire day.
These weak keys were created due to faulty code.
The private key acts as both a username and a password. They are not separate. So if two people use the same password to create a Brainwallet (i.e. a wallet that contains passphrases for creating private keys), then they will both have exactly the same wallet. In a way, it is like two people having the same bank account.
The researchers found 732 weak private keys, which were associated with 49,060 transactions.
Bednarek says there are about 50 million keys on the Ethereum blockchain. His team was only able to discover 732.
The researchers were observing how wallets were linked to private keys and noticed that many transactions were made to a specific address, but no money was ever returned from that address.
The hacker was taking money from 12 of the keys that the research team had access to. Apparently the hacker did the same process as the researchers, because predicting the keys is statistically impossible. So he was stealing users' funds as soon as they entered their wallets.
The researcher found that the hacker had created a node so that money from addresses with weak keys would be automatically transferred to his address. To make sure that this was indeed the case, the researchers used a honeypot. They used a weak key and sent a dollar. The researchers knew that the hacker knew this key. Essentially, they wanted to see how long it would take for the money to be transferred to his address. It only took a few seconds, which means that the process is automatic. As soon as money is deposited into an address that the hacker knows is protected by a weak key, he immediately sends a request to transfer the money.
According to the data, the hacker has approximately 45,000 ETH, which corresponds to 7.3 million dollars.
This hacker has been stealing money for several years now. Many have complained and reported incidents of theft that seem to be related to him.
The researcher admits that the perpetrator's techniques are always successful.
"This guy has taken a multi-layered approach to stealing money.".
The hacker carefully searches for wallets that have weak private keys or RPCs that are not properly configured. Thus, he can exploit these elements and steal the funds from the victim's wallet.
This type of theft is not unique to the Ethereum blockchain. The problem the researchers encountered is that they wanted to inform the owners of the addresses to be more careful. However, this is not possible, because it is not easy to find the owner's identity.
So Bednarek contacted the IFS for legal advice. They told him: “If you find something, leave it there. Don’t do any transfers. That way you won’t get yourself into trouble.”.
Bednarek says there are two main reasons private keys are vulnerable. The first reason is that there are bugs in the software that generates them. The second reason is that many users use easy and predictable passphrases for their keys.
Bednarek advises users to use well-known and trusted wallets or to prefer hardware and paper wallets, especially if they have large amounts of cryptocurrency. The hardware wallet ensures that the key will not be revealed, while the paper wallet allows for the existence of a random code, which is stored on paper, so that it has nothing to do with the computer and is therefore not at risk of attacks.
However, even the most well-known software is not completely secure. For example, the lota wallet was hacked by a developer, who was arrested after being accused of stealing $10 million.
ISE will continue to monitor blockchains and weak private keys. Bednarek said they plan to use GPUs, which will allow them to scan 38 billion keys in a matter of seconds.
With more efficient scanning, they will be able to expand into more areas.
Finally, the researchers plan to publish some information that will help cryptocurrency users be aware of potential attacks and do their own research. Perhaps the collaboration of users and experts will be more effective in addressing the situation.
