<p><span style="font-weight: 400;">Researchers at Fireblocks <a href="https://www.fireblocks.com/blog/bitgo-wallet-zero-proof-vulnerability">claim</a> in a report they detected a critical vulnerability in BitGo's Threshold Signature Scheme (TSS) wallet type used for multi-party computation (MPC). <br /> </span></p> <p><span style="font-weight: 400;">According to Fireblocks' allegations, the said vulnerability resulted from a missing implementation of mandatory zero-knowledge proofs in the TSS wallet protocol. </span></p> <p>Fireblocks also claimed and <a href="https://www.fireblocks.com/blog/bitgo-wallet-zero-proof-vulnerability">demonstrated</a> in the report that the vulnerability allowed them to extract the private key of a BitGo TSS wallet on the Ethereum mainnet.</p> <p><span style="font-weight: 400;">BitGo and FireBlocks compete in providing custody and wallet services to institutional clients.</span></p> <h2>BitGo's response</h2> <p>BitGo has criticized Fireblocks' finding, <a href="https://blog.bitgo.com/our-response-141b240aef96">calling</a> it a "publicity stunt" that attempts to create fear and damage BitGo's reputation. It claimed that the wallet type in question was still in early access and had only been made available to 20 developers. BitGo added it was pursuing legal remedies against Fireblocks.</p> <p>"None of our clients were using this type of wallet to store their assets. Because the wallet was in an early-access phase, it’s only available to 20 developers who are fully aware of the risks of using it, and several of those 20 developers are BitGo employees and contributors," a BitGo spokesperson said.</p> <p>BitGo claimed that the issue had already been <a href="https://github.com/BitGo/BitGoJS/blob/master/modules/sdk-core/src/bitgo/utils/tss/ecdsa/ecdsa.ts#L31">documented</a> in their open-source code on GitHub and was publicly known before Fireblocks had flagged it.</p> <p><em>The article was updated to add comments from BitGo.</em></p><br /><span class="copyright"><p>© 2023 The Block Crypto, Inc. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.</p> </span>