This is how hackers attack your Bitcoin wallet online
For years, researchers have warned of serious problems with Signaling System 7 (SS7) - a set of phone protocols that can allow hackers to listen to personal phone calls and read text messages. Large-scale version, despite the most advanced encryption used by mobile networks.
Created in the 1980s, SS7 is a collection of telephone protocols that accommodates more than 800 telecom operators around the world, including AT&T and Verizon to connect and exchange data, such as Routing calls and texts together, enabling roaming and many other services.
Although many fixes have been released, global mobile networks have always ignored this issue and argue that the exploitation of SS7's weaknesses requires a large technical and financial investment, so user risk is extremely low.
- Ransomware 'Your Windows has been banned' extorting users with a face value of 50 USD Bitcoin
- Guide to digging Bitcoin for beginners
- Are you curious what inside the vast Bitcoin Iceland digging plant looks like?
However, earlier this year, we saw a real attack, the hacker used the design flaw in SS7 to extract the victim's bank account by blocking two-factor authentication codes. (disposable password or OTP authentication code) sent to customers and redirected them to hackers.
The white-hat hackers of Positive Technologies have proven that cyber criminals can exploit the SS7 vulnerability to control online Bitcoin wallets to steal victims' money.
This is how hackers attack Bitcoin wallets and steal money
">
To demonstrate the attack, Positive researchers obtained the Gmail address and phone number of the target, then requested to reset the password for the account, including sending the authorized token once to send to the number. Phone of the target.
Just like in previous SS7 hacks, researchers blocked SMS messages containing 2FA code by exploiting a known design flaw in SS7 and accessing Gmail mailboxes.
Since then, researchers accessing straight to Coinbase accounts have been registered with the compromised Gmail account and created another password for the victim's Coinbase wallet. After that, they logged into their wallets and took all the money in it.
Fortunately, this attack is done by security researchers, not cyber criminals, so there is no damage to the Bitcoin encryption system.
The above is just an example of an SS7 vulnerability attack, however, they are not limited to cryptocurrency wallets. Any service, such as Facebook and Gmail, is based on two-factor authentication.
We need to avoid using 2-factor authentication via SMS messages to receive OTP codes. Instead, it is recommended to rely on encryption keys based on encryption as a second authentication factor.
You should read it
- How to dig bitcoin without wasting electricity
- Discovering the new serious security vulnerability of Bitcoin can cause the whole system to crash
- What is Bitcoin faucet? What is Bitcoin faucet?
- What is Bitcoin? Why is Bitcoin not 'virtual money'?
- What do you need to know when buying Bitcoin or selling Bitcoin?
- Guide to digging Bitcoin for beginners
- Today's Bitcoin price, Bitcoin price update every minute
- How to dig Bitcoin on Android and iOS phones
May be interested
- Bitcoin wallet 'inviolable' used by John McAfee was hacked by a 15-year-old boy to play DOOMrecently, a 15-year-old boy posted a video on twitter showing that the bitfi wallet of the same type as john mcafee's wallet was hacked successfully. even in the video, the boy played the legendary doom game on this 'inviolable' electronic wallet.
- How to create and use Bitcoin Wallet, Ethereum Wallet on Blockchainto store electronic coins, you need to create wallet to store them. so how to create bitcoin wallet and ethereum wallet on blockchain?
- What is Bitcoin? Why is Bitcoin not 'virtual money'?what is bitcoin? why do hackers use it? is bitcoin a virtual currency?
- Bitcoin 'dinosaur' awakens after 10 years of hibernationa bitcoin address dormant since the time of satoshi nakamoto has reawakened after 10 years. a bitcoin wallet containing 687 btc ($43.9 million) transferred its holdings to two different wallets on may 6.
- Vietnamese users can receive money through Google Walletas you know, google wallet is a free payment service that makes buying online easy and fast.
- How to register e-wallet VTC Payvtc pay is an online payment gateway and is an electronic wallet, helping to replace cash to quickly make payment or payment transactions.
- What is '51% attack'? Can Bitcoin completely collapse by a 51% attack?51% attack makes new transactions unable to confirm network congestion, even if an attacker controls the network completely, it can cause the transaction to be reversed.
- Instructions for using Google Wallet for beginnersgoogle wallet is google's mobile payment platform. with this platform, users can turn their smartphone into an electronic wallet to pay anywhere.
- When Bitcoin went everywhere: using NES since 1985 dig Bitcoinwhile it's a commendable building, it's clear that the older 30-year-old processor can't compete with stronger rivals in the race to win valuable bitcoin.
- How do Sony customers protect themselves?the hackers' attack on sony's playstation network (psn) and sony online entertainment (soe) has affected a total of over 100 million accounts.