• bitcoinBitcoin (BTC) $ 59,933.00
  • ethereumEthereum (ETH) $ 1,574.99
  • tetherTether (USDT) $ 0.998691
  • bnbBNB (BNB) $ 566.86
  • usd-coinUSDC (USDC) $ 0.999809
  • xrpXRP (XRP) $ 1.05
  • solanaSolana (SOL) $ 71.77
  • tronTRON (TRX) $ 0.320107
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.01
  • hyperliquidHyperliquid (HYPE) $ 64.32
  • dogecoinDogecoin (DOGE) $ 0.075688
  • rainRain (RAIN) $ 0.015686
  • usdsUSDS (USDS) $ 0.999701
  • leo-tokenLEO Token (LEO) $ 9.31
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 417.57
  • labLAB (LAB) $ 19.49
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.177158
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 320.10
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.151349
  • whitebitWhiteBIT Coin (WBT) $ 48.42
  • cardanoCardano (ADA) $ 0.148287
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • chainlinkChainlink (LINK) $ 7.34
  • usd1-wlfiUSD1 (USD1) $ 0.999267
  • daiDai (DAI) $ 0.999613
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998137
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.55
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 198.16
  • litecoinLitecoin (LTC) $ 41.87
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.070711
  • global-dollarGlobal Dollar (USDG) $ 0.999963
  • avalanche-2Avalanche (AVAX) $ 6.58
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.697894
  • paypal-usdPayPal USD (PYUSD) $ 0.999810
  • crypto-com-chainCronos (CRO) $ 0.054819
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • tether-goldTether Gold (XAUT) $ 4,072.06
  • nearNEAR Protocol (NEAR) $ 1.79
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • bittensorBittensor (TAO) $ 213.74
  • pax-goldPAX Gold (PAXG) $ 4,076.75
  • uniswapUniswap (UNI) $ 2.96
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.057820
  • aster-2Aster (ASTER) $ 0.628851
  • worldcoin-wldWorldcoin (WLD) $ 0.466173
  • okbOKB (OKB) $ 75.17
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.316184
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • mantleMantle (MNT) $ 0.437758
  • polkadotPolkadot (DOT) $ 0.850834
  • aaveAave (AAVE) $ 94.84
  • falcon-financeFalcon USD (USDF) $ 0.993207
  • pi-networkPi Network (PI) $ 0.128324
  • usddUSDD (USDD) $ 1.00
  • bfusdBFUSD (BFUSD) $ 0.998341
  • internet-computerInternet Computer (ICP) $ 2.20
  • skySky (SKY) $ 0.049959
  • bitget-tokenBitget Token (BGB) $ 1.64
  • morphoMorpho (MORPHO) $ 1.76
  • ethereum-classicEthereum Classic (ETC) $ 7.23
  • united-stablesUnited Stables (U) $ 0.999899
  • memecoreMemeCore (M) $ 0.772273
  • dexeDeXe (DEXE) $ 21.37
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pepePepe (PEPE) $ 0.000002
  • quant-networkQuant (QNT) $ 67.24
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.03
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • kucoin-sharesKuCoin (KCS) $ 6.77
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • stable-2​​Stable (STABLE) $ 0.037224
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdgoUSDGO (USDGO) $ 1.00
  • cosmosCosmos Hub (ATOM) $ 1.59
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.57
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.13
  • kaspaKaspa (KAS) $ 0.028034
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • jupiter-exchange-solanaJupiter (JUP) $ 0.230646
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.071505
  • wbnbWrapped BNB (WBNB) $ 759.61
  • audieraAudiera (BEAT) $ 2.59
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.082884
  • ethenaEthena (ENA) $ 0.079334
  • usdtbUSDtb (USDTB) $ 0.999679
  • nexoNEXO (NEXO) $ 0.728805
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.726967
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • beldexBeldex (BDX) $ 0.081057
  • justJUST (JST) $ 0.081845
  • gatechain-tokenGate (GT) $ 6.56
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • venice-tokenVenice Token (VVV) $ 13.51
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • ghoGHO (GHO) $ 0.997787
  • adi-tokenADI (ADI) $ 4.77
  • flare-networksFlare (FLR) $ 0.006811
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • filecoinFilecoin (FIL) $ 0.743334
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999795
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.028017
  • usual-usdUsual USD (USD0) $ 0.998757
  • pump-funPump.fun (PUMP) $ 0.001335
  • clbtcclBTC (CLBTC) $ 76,920.00
  • hash-2Provenance Blockchain (HASH) $ 0.009406
  • midnight-3Midnight (NIGHT) $ 0.030539
  • usxUSX (USX) $ 0.999694
  • aptosAptos (APT) $ 0.596608
  • true-usdTrueUSD (TUSD) $ 0.997109
  • injective-protocolInjective (INJ) $ 4.87
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • a7a5A7A5 (A7A5) $ 0.012213
  • arbitrumArbitrum (ARB) $ 0.074022
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • aerodrome-financeAerodrome Finance (AERO) $ 0.474720
  • tbtctBTC (TBTC) $ 70,942.00
  • lighterLighter (LIT) $ 1.82
  • dashDash (DASH) $ 34.19
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.34
  • euro-coinEURC (EURC) $ 1.14
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.70
  • official-trumpOfficial Trump (TRUMP) $ 1.71
  • hastra-primePRIME (PRIME) $ 1.04
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • jito-governance-tokenJito (JTO) $ 0.813473
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.174781
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006190
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • vechainVeChain (VET) $ 0.004477
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • skyaiSkyAI (SKYAI) $ 0.373903
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • sei-networkSei (SEI) $ 0.053273
  • celestiaCelestia (TIA) $ 0.379079
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000064
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997267
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.526057
  • ether-fiEther.fi (ETHFI) $ 0.359484
  • the9bitThe9bit (9BIT) $ 0.042627
  • kite-2Kite (KITE) $ 0.138768
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sun-tokenSun Token (SUN) $ 0.016728
  • blockstackStacks (STX) $ 0.169129
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 131.14
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • spx6900SPX6900 (SPX) $ 0.330712
  • grassGrass (GRASS) $ 0.485657
  • curve-dao-tokenCurve DAO (CRV) $ 0.193079
  • apxusdapxUSD (APXUSD) $ 0.750622
  • velvetVelvet (VELVET) $ 0.676814
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • gnosisGnosis (GNO) $ 104.52
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • ethgas-2ETHGas (GWEI) $ 0.127791
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • plasmaPlasma (XPL) $ 0.103734
  • pyth-networkPyth Network (PYTH) $ 0.034144
  • noonNoon (NOON) $ 0.751949
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • apenftAINFT (NFT) $ 0.00000026
  • fraxLegacy Frax Dollar (FRAX) $ 0.994281
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • build-onBUILDon (B) $ 0.237415
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • olympusOlympus (OHM) $ 15.81
  • tezosTezos (XTZ) $ 0.215479
  • zebec-networkZebec Network (ZBCN) $ 0.002380
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • megausdMegaUSD (USDM) $ 0.999112

Bitcoin bots compete for funds in compromised wallet linked to block reward identifier

0 1


A Bitcoin user lost funds after sending cryptocurrency to a compromised wallet that used a transaction identifier from a coinbase block reward as its private key.

Summary
  • A Bitcoin user sent 0.84 BTC to a compromised wallet whose private key was derived from a block 924,982 coinbase transaction identifier, exposing it to theft.
  • Automated programs monitoring the mempool detected the deposit and competed via replace-by-fee transactions, sometimes paying nearly 100% of the value in fees to claim the funds.
  • Using predictable or publicly available data—like transaction IDs or common word patterns—for private keys enables immediate exploitation, highlighting the critical importance of true entropy in key generation.

The transaction identifier of the Coinbase from block 924,982 served as the private key for the wallet, creating a security vulnerability that triggered automated bot activity, according to cryptocurrency publication Protos.

The incident prompted automated computer programs connected to Bitcoin’s memory pool, or mempool, of pending transactions to compete for the funds. These bots automatically detect deposits into compromised wallets and broadcast replace-by-fee transactions to outbid competing programs’ fees to miners for withdrawal transactions.

In the reported instance, 0.84 BTC was sent and lost to an address with a non-random private key derived from a block’s coinbase identifier, according to blockchain data.

The automated systems employ replace-by-fee mechanisms to incrementally increase transaction fees in competition with other bots. In some cases, child transactions pay up to 99.9% of the transaction value in fees, according to observers monitoring such activity.

Private keys represent the most critical security element for protecting bitcoin holdings. When a private key is exposed or derived from common data patterns, theft typically occurs immediately, according to cryptocurrency security experts.

Many compromised wallets with non-random private keys utilize seed phrases with predictable patterns, including repeated words such as “password,” “bitcoin,” or “abandon,” according to security researchers. Any non-random pattern lacking true entropy can expose a private key and enable automated systems to drain deposits to the corresponding public key.

The incident demonstrates that non-randomness can extend beyond simple word patterns to include public information recorded on the Bitcoin ledger, such as transaction identifiers of block rewards. Failure to introduce mechanical entropy when generating private keys can enable brute-force attacks and compromise fund security, according to cryptography experts.

Hashing a private key via a transaction identifier does not provide sufficient entropy for secure private key storage, the incident illustrates. Miners and other mempool observers can monitor transaction identifiers for non-randomness and attempt to broadcast theft transactions using exposed private keys, according to blockchain security analysts.



Source link

Leave A Reply

Your email address will not be published.