Identifying Key Leakage of Bitcoin Users

Identifying Key Leakage of Bitcoin Users
复制标题

识别比特币用户密钥泄露

DOI:
--
复制
发表时间:
2018
期刊:
International Symposium on Recent Advances in Intrusion Detection
影响因子:
--
通讯作者:
C. Rossow
C. Rossow
中科院分区:
--
文献类型:
--
作者:
Michael Brengel;C. Rossow

文献摘要

被引文献

相似文献

我们研究加密货币背景下的密钥泄漏。首先,我们考虑开源情报平台上发生的显式密钥泄漏问题。为此,我们监控了 2017 年 9 月至 2018 年 3 月期间的 Pastebin 源,以查找暴露的比特币秘密密钥,发现攻击者可能窃取了 22.40 BTC,根据当前汇率,价值约 178,000 美元。然后,我们通过利用加密原语的错误使用来关注隐式密钥泄漏,并扫描比特币区块链以查找 ECDSA 随机数重用。我们系统地概述了攻击者如何使用重复的 r 值来泄漏随机数和秘密密钥,这超出了相同随机数和相同密钥多次结合使用的简单情况。我们的结果表明,ECDSA 随机数重用一直是比特币生态系统中反复出现的问题,并且已经被攻击者利用。事实上,攻击者本可以利用随机数重用来窃取价值约 330 万美元的 412.80 BTC。
We study key leakage in the context of cryptocurrencies. First, we consider the problem of explicit key leakage occurring on open-source intelligence platforms. To do this, we monitor the Pastebin feed from Sep 2017–Mar 2018 to find exposed secret Bitcoin keys, revealing that attackers could have stolen 22.40 BTC worth roughly $178,000 given current exchange rates. Then, we focus on implicit key leakage by exploiting the wrong usage of cryptographic primitives and scan Bitcoin’s blockchain for ECDSA nonce reuse. We systematically outline how an attacker can use duplicate r values to leak nonces and secret keys, which goes beyond the simple case where the same nonce and the same key have been used in conjunction more than once. Our results show that ECDSA nonce reuse has been a recurring problem in the Bitcoin ecosystem and has already been exploited by attackers. In fact, an attacker could have exploited nonce reuse to steal 412.80 BTC worth roughly $3.3 million.