• News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT
  • Metaverse
  • Analysis
  • Learn
  • Videos
  • Blogs
  • Market Cap
  • Shop
What's Hot

10 Years of Steadfast Support and Compliance

2025-05-15

Bitcoin Investors…These are the 3 Crypto Projects I am DCAing Into

2025-05-14

Bitcoin’s Bullish Move Sets the Stage for These Must-Watch Crypto Projects

2025-05-13

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram
Crypto Investor News Network
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT

    All Eyes on Art: Upcoming Collections to Watch the Week of February 4

    2025-02-05

    Creator of rabbit AI assistant has hidden NFT past

    2024-05-02

    Ethereum tops daily NFT sales at US$7 mln, ends weakest month of 2024

    2024-05-02

    Top NFT Airdrops and Giveaways for May 2024

    2024-05-02

    Casio Launches NFT Collection Celebrating 50th Anniversary

    2024-05-01
  • Metaverse

    Shib: The Metaverse – Part of the Expanding Shiba Inu Ecosystem

    2025-01-03

    Experience to Earn: Everdome’s Metaverse Frontier

    2024-12-30

    Beyond Bots: Meta Motivo and the Dawn of Humanlike Digital Life

    2024-12-13

    Exploring NetVRk: What Is Behind This AI-Driven Virtual Universe?

    2024-10-28

    Council of Europe Highlights Metaverse’s Impact on Privacy and Democracy

    2024-09-05
  • Analysis

    Crypto Exchange Coinbase Lists New DeFi Altcoin Project Built on Base Blockchain

    2023-12-13

    Ethereum Price Bears Keep Pushing, Why Decline Isn’t Over Yet

    2023-12-13

    Trader Bullish on Cosmos (ATOM), Says One Dogecoin Rival Setting Up for Next Leg Up – Here’s His Outlook

    2023-12-13

    AVAX Price Pumps 50% and Dumps 15%, Why Uptrend Is Still Strong

    2023-12-13

    Top Trader Predicts Parabolic Rally for Solana Competitor – Here’s His Upside Target

    2023-12-13
  • Learn

    10 Years of Steadfast Support and Compliance

    2025-05-15

    What Is Proof-of-Work (PoW) in Blockchain? A Beginner-Friendly Guide

    2025-05-12

    What is Proof-of-Authority (POA) Consensus in Blockchain?

    2025-05-09

    What Is Proof-of-Stake (PoS)? Guide to Blockchain Consensus for Beginners

    2025-05-09

    What is a Layer-1 (L1) Blockchain? L1 Problems & Future

    2025-05-03
  • Videos

    Bitcoin Investors…These are the 3 Crypto Projects I am DCAing Into

    2025-05-14

    Bitcoin’s Bullish Move Sets the Stage for These Must-Watch Crypto Projects

    2025-05-13

    They Told You NOT to Buy the Bitcoin

    2025-05-12

    Bitcoin Nodes, Censorship, and Big Blockheads

    2025-05-12

    💼 The Investing Game Has Changed! 🌐🚨

    2025-05-11
  • Blogs
  • Market Cap
  • Shop
Facebook Twitter Instagram TikTok
Crypto Investor News Network
Home»DeFi»Multisig wallets vulnerable to exploitation by Starknet apps, says developer Safeheron
DeFi

Multisig wallets vulnerable to exploitation by Starknet apps, says developer Safeheron

2023-03-09No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Certain multisignature (multisig) wallets can be exploited by Web3 apps that use the Starknet protocol, according to a March 9 press release provided to Cointelegraph by Multi-Party Computation (MPC) wallet developer Safeheron. The vulnerability affects MPC wallets that interact with Starknet apps such as dYdX. According to the press release, Safeheron is working with app developers to patch the vulnerability.

According to Safeheron’s protocol documentation, MPC wallets are sometimes used by financial institutions and Web3 app developers to secure crypto assets they own. Similar to a standard multisig wallet, they require multiple signatures for each transaction. But unlike standard multisigs, they do not require specialized smart contracts to be deployed to the blockchain, nor do they have to be built into the blockchain’s protocol.

Instead, these wallets work by generating “shards” of a private key, with each shard being held by one signer. These shards have to be joined together off-chain in order to produce a signature. Because of this difference, MPC wallets can have lower gas fees than other types of multisigs and can be blockchain agnostic, according to the docs.

MPC wallets are often seen as more secure than single signature wallets, since an attacker can’t generally hack them unless they compromise more than one device.

However, Safeheron claims to have discovered a security flaw that arises when these wallets interact with Starknet-based apps such as dYdX and Fireblocks. When these apps “obtain a stark_key_signature and/or api_key_signature,” they can “bypass the security protection of private keys in MPC wallets,” the company said in its press release. This can allow an attacker to place orders, perform layer 2 transfers, cancel orders, and engage in other unauthorized transactions.

See also  Debtors saved over $100M using de-pegged stablecoins to repay loans

Related: New “zero-value transfer” scam is targeting Ethereum users

Safeheron implied that the vulnerability only leaks the users’ private keys to the wallet provider. Therefore, as long as the wallet provider itself is not dishonest and has not been taken over by an attacker, the user’s funds should be safe. However, it argued that this makes the user dependent on trust in the wallet provider. This can allow attackers to circumvent the wallet’s security by attacking the platform itself, as the company explained:

“The interaction between MPC wallets and dYdX or similar dApps [decentralized applications] that use signature-derived keys undermines the principle of self-custody for MPC wallet platforms. Customers may be able to bypass pre-defined transaction policies, and employees who have left the organization may still retain the capability to operate the dApp.”

The company said that it is working with Web3 app developers Fireblocks, Fordefi, ZenGo, and StarkWare to patch the vulnerability. It has also made dYdX aware of the problem, it said. In mid-March, the company plans to make its protocol open source in an effort to further help app developers patch the vulnerability.

Cointelegraph has attempted to contact dYdX, but has been unable to get a response before publication.

Avihu Levy, Head of Product at StarkWare told Cointelegraph that the company applauds Safeheron’s attempt to raise awareness about the issue and to help provide a fix, stating:

 “It’s great that Safeheron is open-sourcing a protocol focusing on this challenge[…]We encourage developers to address any security challenge that should arise with any integration, however limited its scope. This includes the challenge being discussed now.

Starknet is a layer 2 Ethereum protocol that uses zero-knowledge proofs to secure the network. When a user first connects to a Starknet app, they derive a STARK key using their ordinary Ethereum wallet. It is this process that Safeheron says is resulting in leaked keys for MPC wallets.

See also  Celo president Rene Reinsberg explains why the protocol is optimizing for mobile

Starknet attempted to improve its security and decentralization in February by open-sourcing its prover. 

apps developer exploitation Multisig Safeheron Starknet Vulnerable Wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

2025-04-22

Top 10 FREE Crypto Apps You NEED For 2025!!

2025-03-07

TOP 6 BEST Crypto Wallets For 2025: Are Your Coins Safe??

2025-01-25

Discover The Holy Grail of Bitcoin Cold Wallets Everyone’s After!

2025-01-08
Add A Comment

Leave A Reply Cancel Reply

Top Posts
Videos

WHY ALTCOIN FOMO STARTS NOW!!!

2025-01-07

The crypto market is where large wealth gains are made! Do you want $30000 in…

Learn About Crypto

Waves (WAVES) Price Prediction 2024 2025 2026 2027

2024-10-27

The Waves platform gathered a lot of controversy at the time of its inception. The…

Videos

Create Your Own Bitcoin Money Glitch

2025-01-30

The crypto market is where large wealth gains are made! . Do you want $30000…

Subscribe to Updates

Get the latest news and Update from CINN about Crypto, Metaverse and NFT.

Editors Picks

10 Years of Steadfast Support and Compliance

2025-05-15

Bitcoin Investors…These are the 3 Crypto Projects I am DCAing Into

2025-05-14

Bitcoin’s Bullish Move Sets the Stage for These Must-Watch Crypto Projects

2025-05-13

What Is Proof-of-Work (PoW) in Blockchain? A Beginner-Friendly Guide

2025-05-12
Crypto Investor News Network
Facebook Twitter Instagram TikTok
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Disclouser
© 2025 - All rights are reserved.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 103,731.79
ethereum
Ethereum (ETH) $ 2,562.99
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.48
bnb
BNB (BNB) $ 657.01
solana
Solana (SOL) $ 172.13
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.226291
cardano
Cardano (ADA) $ 0.781666
tron
TRON (TRX) $ 0.275956