Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, March 23, 2018

The Race Between Segwit and Bitcoin Cash Is Heating Up

The introduction of Segwit and the launch of bitcoin cash (BCH) were two attempts at solving the bitcoin’s scaling problem. Both movements took a different approach, with Segwit seeking to reduce transaction size and BCH seeking to increase the block size. A new report compares the transaction volume on each chain, BTC (Segwit) and BCH, since last summer’s hard fork, and the numbers are remarkably close.

Segwit and BCH Show There’s More Than One Way to Scale a Blockchain

Blockchain scaling is one part technical, one part ideological. There was a number of reasons that led to the fork of bitcoin core in August to form bitcoin cash, but at its heart it came down to increasing transaction capacity. Segwit sought to compress the amount of data in each transaction, thereby freeing up block space, while bitcoin cash made the size of each block bigger, up to a maximum of 8MB. New data published by Bitmex Research shows how each chain has fared since bitcoin core and bitcoin cash went their separate ways.
The cumulative transaction volume between BCH and Segwit is remarkably close, showing that each scaling solution has found their levels of support. Bitmex Research explains: “Since the launch of Bitcoin Cash, 6.1 million Segwit transactions have taken place, only 20.1% more than the cumulative number of Bitcoin Cash transactions…Adjusting for the one-month head start [BCH had], SegWit has 31.5% more cumulative transaction volume than Bitcoin Cash, larger than 20.1% but still reasonably close.”
The Race Between Segwit and Bitcoin Cash Is Heating Up
Total transaction volume for Segwit and BCH is extremely close.

Segwit Had a Slow Start

Segwit adoption was low from the outset, and remained that way for several months, allowing bitcoin cash to get a head start. By late December, the total transaction volume of BCH and Segwit was neck and neck at around 4 million transactions apiece. It is only in the last month, when Coinbase belatedly introduced Segwit, pushing its adoption rate over 30% for the first time, that its total transaction volume has been able to compete with bitcoin cash.
Proponents of each chain have reasons to be content with these figures, and of how the future is shaping up for their preferred scaling solution. As Bitmex Research notes:
Although the data suggests that Segwit transaction have been adopted slightly faster than Bitcoin Cash, resulting in more transaction volume, Bitcoin Cash advocates could argue that the Bitcoin Cash token is more about a philosophy of larger capacity in the long term, rather than the speed of the actual increase in transaction volume in the short term. Therefore Bitcoin Cash supporters can still claim that Bitcoin Cash will eventually have more transaction volume than Bitcoin, once adoption of the coin increases.

Bitcoin Core Block Sizes Fall to Their Smallest in Two Years

Last week, the average block size for bitcoin core (BCT) fell to just over 0.5MB, its smallest since January 2016. Around 22% of block space is taken up by Segwit transactions, showing that the scaling technology is still under-utilized. The dramatic reduction in BTC block space owes less to Segwit and more to improved batching coupled with reduced transaction volume. It is no coincidence that the average number of daily BTC transactions is also at its lowest level in two years.
The Race Between Segwit and Bitcoin Cash Is Heating Up
BTC block sizes are at their lowest in two years.
The average number of daily BTC to BCH transactions for the moment maintains an average ratio of 10:1, which also mirrors each asset’s respective price. However, total transaction fees for sending BTC in the last 24 hours are 200x greater than BCH. Even if the transaction volume on each chain was equal, in other words, BTC would still cost 20x more to send.
Why do you think BTC transaction volume is so low right now? Let us know in the comments section below.

Images courtesy of Shutterstock, Bitmex Research and Blockchain.info
Source : bitcoin.com

Thursday, March 22, 2018

Coinbase Glitch Allowed Unlimited Ethereum Balances

On March 21, the San Francisco based exchange Coinbase publicly revealed an ethereum balance glitch that allowed users to manipulate their account balances. Researchers noticed that, by utilizing a smart contract, a person could add as much ethereum as they wanted to their account.

Smart Contract Manipulation Allowed Unlimited Ethereum Balances on Coinbase

Coinbase Glitch Allowed Unlimited Ethereum BalancesJust recently researchers had found a vulnerability within the Coinbase platform that allows a user to add as much ether as they want to their accounts by using a smart contract. The bug was revealed to the public on March 21 but the issue had existed since December of 2017. Coinbase rewarded the Dutch research analysts’ firm, Vicompany with a $10,000 reward after it discovered the glitch.
“The researchers noticed an issue with our ETH receiving code when receiving from a contract. This allowed sending of ETH to Coinbase to be credited even if the underlying contract execution failed,” explains the San Francisco trading platform.  
The issue was fixed by changing the contract handling logic — Analysis of the issue indicated only accidental loss for Coinbase, and no exploitation attempts.

Not the Only Exchange With an Unlimited Coin Glitch

Coinbase Glitch Allowed Unlimited Ethereum BalancesAccording to Vicompany, a malicious actor could manipulate their ether balance by using a smart contract to distribute ether throughout a set of wallets. Vicompany explains that if one of the internal transactions fail all transactions prior would be reversed. However, on the Coinbase interface, the transactions did not revert. The third party researcher states on the disclosure:  
On Coinbase these transactions will not be reversed, meaning someone could add as much ether to their balance as they want.
Coinbase is not the only exchange that has suffered from glitches that allow people to manipulate balances. This past February the Japanese exchange Zaif had a bug that let users purchase BTC for zero dollars. A month prior to the Zaif incident, the company Overstock had an API glitch which allowed users to pay for goods using BCH for a product priced in BTC.
What do you think about the Coinbase bug found last December? Why do you think the exchange disclosed the bug this week? Let us know what you think in the comments below.   

Images via Shutterstock, and Coinbase. 
Source : bitcoin.com

Wednesday, March 21, 2018

Coinbase to Remove Support for Multisig Vaults Within a Month

Coinbase is removing its support for an advanced security feature that it was not advantageous for the company to maintain. Multisig vaults were originally introduced as a way for customers to manage their private keys and control their own security while still using the same Coinbase interface.

No More Coinbase Multisig Vaults

Coinbase to Remove Support for Multisig Vaults Within a MonthSan Francisco-based cryptocurrency exchange Coinbase has announced it will be winding down its support for existing multisig vaults (meaning accounts that require multiple signature to access) on the platform. The last day of support will be on April 19, 2018.
The company already disabled the creation of any new multisig vaults, citing customer feedback and low popularity and usage. Coinbase also explained that as bitcoin forks become more frequent, the complexity of multisig vaults makes it infeasible for it to support multisig withdrawals for each additional forked asset.
For these reasons it has decided to invest its resources elsewhere. “By removing this functionality, engineering time spent on supporting multisig vaults can be reallocated to continued investment in the security and reliability of our platform, which is of critical importance to our customers.”

Your Money, Your Responsibility

Coinbase to Remove Support for Multisig Vaults Within a MonthThe company explains that because this product is user-controlled, customers can move funds with the two keys they already control. This change will only result in Coinbase customers not being able to access the third key that the company controls.
Users of this feature should ensure they have access to their two keys before the change. Otherwise, it is recommend Coinbase customers withdraw all funds from a multisig vault prior to April 19, 2018. After this date, access to the multisig address associated with such a vault will require the use of third-party open-source software not controlled by Coinbase, and this multisig tool does not support group vaults as well.
Whether you are a Coinbase customer or not, the responsibility for the security of your bitcoin holdings rests with you. More information on protecting your crypto wealth can be found in a recent guide from news.Bitcoin.com.
Why do you think Coinbase multisig vaults have seen such low adoption? Share your thoughts in the comments section below!

Images courtesy of Shutterstock.
Source : bitcoin.com

Saturday, March 10, 2018

Hackers Target 400,000 Computers with Mining Malware

More than 400,000 personal computers have been attacked in a large-scale attempt to distribute cryptocurrency mining malware. The hackers used sophisticated trojans to infect PCs mostly in Russia, but also in Turkey, Ukraine, and other countries. The coordinated assault lasted more than 12 hours.

Several Countries Affected, Russia Hit Harder

The complex malicious software has been trying to overcome antivirus defenses for more than 12 hours on March 6. According to Microsoft, the majority of the attacked computers, 73%, were located in Russia, followed by Turkey with 18% and Ukraine – 4%. Other countries have also been affected.
Hackers Target 400,000 Computers with Mining Malware“Windows Defender blocked more than 80,000 instances of several sophisticated trojans that exhibited advanced cross-process injection techniques, persistence mechanisms, and evasion methods”, the research team developing Microsoft’s AV software announced. More than 400,000 users have been targeted, Bleeping Computer reports.
The behavior-based and cloud-powered machine learning models included in Windows Defender detected the trojan attack in its early stage, the researchers said. The threat was identified by the antivirus program, which started blocking further attempts within minutes.
According to the Windows Defender team, the Dofoil malware used in the attack tried to penetrate the explorer.exe process of the operating system and inject malicious code. Then, another explorer.exe was supposed to download and run the cryptocurrency miner masked as a legitimate Windows binary – wuauclt.exe. The antivirus software was able to detect these attempts, as the process was running from a different location on the hard drive.

The Malware Mined Electroneum

Suspicious traffic was generated by the malware, when the coinminer tried to contact its command and control server located on the Namecoin network infrastructure. The malicious software was programmed to mine Electroneum. The cryptocurrency uses “app based mobile mining”, according to its website.
Microsoft claims that Windows 10, 8.1, and Windows 7 computers with installed Windows Defender or Microsoft Security Essentials have been protected automatically. According to Bleeping Computer, other antivirus programs have most likely detected the threat as well. Dofoil has been a known and active malware strain for several years now.
Hackers Target 400,000 Computers with Mining MalwareMalicious scripts have become a popular instrument for hackers trying to steal computing power in order to mine cryptocurrencies. There have been attempts to use popular platforms, like Facebook Messenger and Youtube, to spread mining malware. In multiple reports, cybersecurity firms have warned about attempts to hijack personal computers and even smartphones to mine different coins.
According to a recent study by Kaspersky Lab, hackers are also targeting industrial enterprises, trying to take advantage of their computers and servers. Attacks on automated control systems have increased in the past year. From California-based electric car manufacturer Tesla, to a water purifying plant in Europe, a growing number of companies and institutions have reported attacks, despite their investments in cybersecurity.
Do you think your computer has been targeted by crypto mining malware? Tell us in the comments section below.

Images courtesy of Shutterstock. 
Source : news.bitcoin.com

Tuesday, March 6, 2018

High-Frequency Trading Firm Virtu Threatens Legal Action Against Virtcoin

HFT giant Virtu has been the target of an apparent clone scam, using its likeness to attract possible investors. The company is threatening legal action and has already approached the authorities about the matter. The promotional matrial for the “coin” in question, Virt, is so bizarre it almost looks like a parody of the current state of the market or the result of an ICO whitepaper writing AI gone rogue.

Virtu Clone Scam

High-Frequency Trading Firm Virtu Threatens Legal Action Against VirtCoin
Can you tell the real logo from the clone?
Virtu Financial (NASDAQ:VIRT), one of the largest high-frequency trading firms on Wall Street, has issued a warning to the public on Friday against Virtcoin, explaining it has no relationship, connection, or affiliation to the company and its officers and directors. Additionally, “Virtu has notified the appropriate authorities and intends to commence all necessary legal actions to defend itself from any attempt to infringe on Virtu’s copyrights, trademarks and intellectual property.”
This came after a fake press release was sent out by Virt on Wednesday using images of the Virtu team and trying to link the two entities. The misleading press release even claimed that “Douglas Cifu, Virtu Financial’s chief executive, told Wall Street recently that the company is going to issue the upcoming token VIRT for the trading desk.”

Deep Concern and Support

Judging by the website and whitepaper of the project, Virt appears to be either run by a bunch of Chinese scammers that don’t know basic English and are reliant on auto-translation software, or an entity that is pretending to be illiterate for some reason. For example, the Virt whitepaper opens with this word soup: “Encrypted digital currency is a form of value data based on block chain underlying technology. At present, the most outstanding ones are bitcoin, Wright currency and Ethernet. Digital money is not a legal currency in any country or region through the transaction of data and the function of the transaction medium, the bookkeeping unit and the value storage Therefore, the encrypted digital currency is different from the electronic currency, and the electronic currency is the digital expression of the legal currency, which is used to carry out the electronic transaction of the legal currency.”
The fake press release also ended with this nonsensical endorsement: “The forthcoming VIRT, a trading counter token, is promising. Deutsche Börse, operator of the Frankfurt Stock Exchange, even prepared a $ 60 million financing for Digital Asset Holdings. Elmer Funke Kupper, ASX’s chief executive, also expressed his deep concern and support.”
High-Frequency Trading Firm Virtu Threatens Legal Action Against VirtCoin
Virt whitepaper falsely displaying Virtu management as their “support force”
If whoever is behind Virt is doing this for comedic effect, they might soon wind up with a not-so-hilarious lawsuit on their hands.
Is this an obvious scam or could it be some sort of elaborate prank gone wrong? Share your thoughts in the comments section below!

Images courtesy of Shutterstock.
Source : news.bitcoin.com
#cryptoscammer #virtuscam