• News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT
  • Metaverse
  • Analysis
  • Learn
  • Videos
  • Blogs
  • Market Cap
  • Shop
What's Hot

What Is Gwei in Crypto? A Guide to Ethereum Gas Fees

2026-05-09

What Is AML in Crypto? Anti–Money Laundering Explained for Beginners

2026-05-09

What Are Social Tokens in Crypto? How Creators and Communities Use Them

2026-05-08

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram
Crypto Investor News Network
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT

    Bitcoin Just Hit an All-Time High. Nobody Cares

    2025-09-11

    All Eyes on Art: Upcoming Collections to Watch the Week of May 27

    2025-09-11

    Bitcoin Vegas Belongs to the Suits Now

    2025-09-11

    NFC Summit Lisbon Founder on Evolving the Event and Weathering the Market

    2025-09-11

    All Eyes on Art: Upcoming Collections to Watch the Week of June 3

    2025-09-10
  • Metaverse

    Shib: The Metaverse – Part of the Expanding Shiba Inu Ecosystem

    2025-01-03

    Experience to Earn: Everdome’s Metaverse Frontier

    2024-12-30

    Beyond Bots: Meta Motivo and the Dawn of Humanlike Digital Life

    2024-12-13

    Exploring NetVRk: What Is Behind This AI-Driven Virtual Universe?

    2024-10-28

    Council of Europe Highlights Metaverse’s Impact on Privacy and Democracy

    2024-09-05
  • Analysis

    Crypto Exchange Coinbase Lists New DeFi Altcoin Project Built on Base Blockchain

    2023-12-13

    Ethereum Price Bears Keep Pushing, Why Decline Isn’t Over Yet

    2023-12-13

    Trader Bullish on Cosmos (ATOM), Says One Dogecoin Rival Setting Up for Next Leg Up – Here’s His Outlook

    2023-12-13

    AVAX Price Pumps 50% and Dumps 15%, Why Uptrend Is Still Strong

    2023-12-13

    Top Trader Predicts Parabolic Rally for Solana Competitor – Here’s His Upside Target

    2023-12-13
  • Learn

    What Is Gwei in Crypto? A Guide to Ethereum Gas Fees

    2026-05-09

    What Is AML in Crypto? Anti–Money Laundering Explained for Beginners

    2026-05-09

    What Are Social Tokens in Crypto? How Creators and Communities Use Them

    2026-05-08

    All-Time High vs. All-Time Low

    2026-05-08

    Survey and Open Talk – Cryptocurrency News & Trading Tips – Crypto Blog by Changelly

    2026-05-05
  • Videos

    AI’s Brutal 5D Power Play: Crypto’s New Role & The Next $Trillion Winners! 📈🤖

    2026-05-07

    Bitcoin Just Flashed A Rare Shocking Signal…

    2026-05-07

    Trading…The Math of Getting Wiped Out

    2026-05-06

    Bitcoin Is About To Trigger a MASSIVE Short Squeeze

    2026-05-06

    Terra Luna Classic Just Dropped A Zero! Traders Pouring In!

    2026-05-05
  • Blogs
  • Market Cap
  • Shop
Facebook Twitter Instagram TikTok
Crypto Investor News Network
Home»DeFi»Multisig wallets vulnerable to exploitation by Starknet apps, says developer Safeheron
DeFi

Multisig wallets vulnerable to exploitation by Starknet apps, says developer Safeheron

2023-03-09No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Certain multisignature (multisig) wallets can be exploited by Web3 apps that use the Starknet protocol, according to a March 9 press release provided to Cointelegraph by Multi-Party Computation (MPC) wallet developer Safeheron. The vulnerability affects MPC wallets that interact with Starknet apps such as dYdX. According to the press release, Safeheron is working with app developers to patch the vulnerability.

According to Safeheron’s protocol documentation, MPC wallets are sometimes used by financial institutions and Web3 app developers to secure crypto assets they own. Similar to a standard multisig wallet, they require multiple signatures for each transaction. But unlike standard multisigs, they do not require specialized smart contracts to be deployed to the blockchain, nor do they have to be built into the blockchain’s protocol.

Instead, these wallets work by generating “shards” of a private key, with each shard being held by one signer. These shards have to be joined together off-chain in order to produce a signature. Because of this difference, MPC wallets can have lower gas fees than other types of multisigs and can be blockchain agnostic, according to the docs.

MPC wallets are often seen as more secure than single signature wallets, since an attacker can’t generally hack them unless they compromise more than one device.

However, Safeheron claims to have discovered a security flaw that arises when these wallets interact with Starknet-based apps such as dYdX and Fireblocks. When these apps “obtain a stark_key_signature and/or api_key_signature,” they can “bypass the security protection of private keys in MPC wallets,” the company said in its press release. This can allow an attacker to place orders, perform layer 2 transfers, cancel orders, and engage in other unauthorized transactions.

See also  🥊 Top Crypto Based on Developer Data - Wild Showdown 🔥💻

Related: New “zero-value transfer” scam is targeting Ethereum users

Safeheron implied that the vulnerability only leaks the users’ private keys to the wallet provider. Therefore, as long as the wallet provider itself is not dishonest and has not been taken over by an attacker, the user’s funds should be safe. However, it argued that this makes the user dependent on trust in the wallet provider. This can allow attackers to circumvent the wallet’s security by attacking the platform itself, as the company explained:

“The interaction between MPC wallets and dYdX or similar dApps [decentralized applications] that use signature-derived keys undermines the principle of self-custody for MPC wallet platforms. Customers may be able to bypass pre-defined transaction policies, and employees who have left the organization may still retain the capability to operate the dApp.”

The company said that it is working with Web3 app developers Fireblocks, Fordefi, ZenGo, and StarkWare to patch the vulnerability. It has also made dYdX aware of the problem, it said. In mid-March, the company plans to make its protocol open source in an effort to further help app developers patch the vulnerability.

Cointelegraph has attempted to contact dYdX, but has been unable to get a response before publication.

Avihu Levy, Head of Product at StarkWare told Cointelegraph that the company applauds Safeheron’s attempt to raise awareness about the issue and to help provide a fix, stating:

 “It’s great that Safeheron is open-sourcing a protocol focusing on this challenge[…]We encourage developers to address any security challenge that should arise with any integration, however limited its scope. This includes the challenge being discussed now.

Starknet is a layer 2 Ethereum protocol that uses zero-knowledge proofs to secure the network. When a user first connects to a Starknet app, they derive a STARK key using their ordinary Ethereum wallet. It is this process that Safeheron says is resulting in leaked keys for MPC wallets.

See also  Can Swarm Move Tokenization Beyond Hype Into Mainstream DeFi?

Starknet attempted to improve its security and decentralization in February by open-sourcing its prover. 

apps developer exploitation Multisig Safeheron Starknet Vulnerable Wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What Is Composability in DeFi? How Decentralized Apps Work Together

2026-03-09

How Many Crypto Wallets Should You Really Have? A Step-by-Step Guide

2026-03-09

A Beginner’s Guide to Crypto Wallets

2026-01-19

What Is a Multisig Wallet? What It Means and Why It Matters for Security

2026-01-08
Add A Comment

Leave A Reply Cancel Reply

Top Posts
Videos

The Bitcoin Bulls Are Back | New Highs Incoming

2025-01-17

Today, let’s look at the latest news, charts, and metrics on Bitcoin and Crypto. Bitunix…

Bitcoin

Is BTC in early stages of a long-term bull rally? This historically accurate indicator suggests…

2023-04-19

Bitcoin’s reserve risk indicator suggests that the market is on its long-term bullish recovery trend.…

NFT

LaLiga NFT Fantasy Soccer Games Coming to North America

2023-09-14

Gaming startup GameOn has a new deal with LaLiga North America to develop NFT-based fantasy…

Subscribe to Updates

Get the latest news and Update from CINN about Crypto, Metaverse and NFT.

Editors Picks

What Is Gwei in Crypto? A Guide to Ethereum Gas Fees

2026-05-09

What Is AML in Crypto? Anti–Money Laundering Explained for Beginners

2026-05-09

What Are Social Tokens in Crypto? How Creators and Communities Use Them

2026-05-08

All-Time High vs. All-Time Low

2026-05-08
Crypto Investor News Network
Facebook Twitter Instagram TikTok
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Disclouser
© 2026 - All rights are reserved.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 80,754.00
ethereum
Ethereum (ETH) $ 2,328.43
tether
Tether (USDT) $ 0.999813
xrp
XRP (XRP) $ 1.42
bnb
BNB (BNB) $ 648.88
usd-coin
USDC (USDC) $ 0.999722
solana
Solana (SOL) $ 93.51
tron
TRON (TRX) $ 0.349273
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05