Fireblocks claims it detected vulnerability, now patched, in competitor BitGo's TSS wallets

Quick Take

  • Fireblocks researchers claim they reported a now-patched vulnerability in competitor BitGo’s wallet software. 
  • Meanwhile, BitGo said the wallet type in question was still in early access and had only been made available to 20 developers. 

Researchers at Fireblocks claim in a report they detected a critical vulnerability in BitGo's Threshold Signature Scheme (TSS) wallet type used for multi-party computation (MPC). 

According to Fireblocks' allegations, the said vulnerability resulted from a missing implementation of mandatory zero-knowledge proofs in the TSS wallet protocol. 

Fireblocks also claimed and demonstrated in the report that the vulnerability allowed them to extract the private key of a BitGo TSS wallet on the Ethereum mainnet.

BitGo and FireBlocks compete in providing custody and wallet services to institutional clients.

BitGo's response

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

BitGo has criticized Fireblocks' finding, calling it a "publicity stunt" that attempts to create fear and damage BitGo's reputation. It claimed that the wallet type in question was still in early access and had only been made available to 20 developers. BitGo added it was pursuing legal remedies against Fireblocks.

"None of our clients were using this type of wallet to store their assets. Because the wallet was in an early-access phase, it’s only available to 20 developers who are fully aware of the risks of using it, and several of those 20 developers are BitGo employees and contributors," a BitGo spokesperson said.

BitGo claimed that the issue had already been documented in their open-source code on GitHub and was publicly known before Fireblocks had flagged it.

The article was updated to add comments from BitGo.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Vishal Chawla is The Block’s crypto ecosystems editor and has spent over six years covering tech protocols, cybersecurity, artificial intelligence and cloud computing. Vishal likes to delve deep into blockchain intricacies to ensure readers are well-informed about the continuously evolving crypto landscape. He is also a staunch advocate for rigorous security practices in the space. Before joining The Block, Vishal held positions at IDG ComputerWorld, CIO, and Crypto Briefing. He can be reached on Twitter at @vishal4c and via email at [email protected]

Editor

To contact the editor of this story:
Mike Millard at
[email protected]