Bitcoin wallet devices vulnerable to security hacks, study shows

25 Jan 2018

1

Devices used to manage accounts on the innovative payment system Bitcoin could be improved to provide better protection against hackers, research suggests.

Computer scientists have identified security weak spots in gadgets that manage personal accounts using Bitcoin - a form of digital currency that provides an alternative to conventional money.

They also identified how these wallets - which are popular among the Bitcoin community - might be rectified. Their findings could help technology firms improve how the devices - known as Bitcoin hardware wallets - interact with our PCs.

A team at the University of Edinburgh carried out an in-depth security analysis of the communications system used in popular models of Bitcoin wallet.

They created a simple piece of harmful software, or malware, which was able to intercept messages sent between hardware wallets and computers - where users manage their Bitcoin accounts.

The tests revealed that users' privacy is not protected. They also showed how easy it is to access Bitcoin funds managed by such devices and divert them into a different account.

Based on their findings, researchers proposed a fix for improving the security of such systems. This would encrypt particular messages sent between Bitcoin wallets and computers, making them much more secure.

Their fix could be incorporated into all models of Bitcoin hardware wallet to offer better protection against hacks, the team says. Their study is published in the journal Information Security.

Dr Andriana Gkaniatsou, of the University of Edinburgh's School of Informatics, who led the study, says, "A wallet should protect not only our money, but also our privacy. It was surprising to discover how easy it is to access a user's funds, even when sophisticated hardware is incorporated.

"Unfortunately, there is no silver bullet when it comes to protecting financial digital assets - we need to ensure that all components of the system are equally protected and interact in a secure way."

Latest articles

Carmakers explore energy storage, but claims of major pivot and write-downs are overstated

Carmakers explore energy storage, but claims of major pivot and write-downs are overstated

Government advances Dholera semiconductor hub, but timelines and scale claims need caution

Government advances Dholera semiconductor hub, but timelines and scale claims need caution

South Korea’s AI chip push grows, but 2nm robotics claims remain premature

South Korea’s AI chip push grows, but 2nm robotics claims remain premature

India–Japan chip collaboration grows, but details around Axiro–EdgeCortix deal remain limited

India–Japan chip collaboration grows, but details around Axiro–EdgeCortix deal remain limited

Post-splashdown: What Artemis II taught us about the ‘deep space wall’

Post-splashdown: What Artemis II taught us about the ‘deep space wall’

Carmakers explore energy storage, but claims around Ford and GM pivot remain overstated

Carmakers explore energy storage, but claims around Ford and GM pivot remain overstated

Tesla’s robotics push continues, but Shanghai “Optimus mass production” claims remain unconfirmed

Tesla’s robotics push continues, but Shanghai “Optimus mass production” claims remain unconfirmed

VinFast eyes India growth, but details around VF MPV 7 launch remain unverified

VinFast eyes India growth, but details around VF MPV 7 launch remain unverified

Breaking the engine barrier: HAL and GE move forward on F414 co-production deal

Breaking the engine barrier: HAL and GE move forward on F414 co-production deal