So you're telling me there's a multi-billion dollar bug?
Description
The image is a screenshot of a presentation slide for a talk at the Black Hat security conference. The slide has a dark, abstract background with blue and green wispy patterns. The title of the talk is 'TSSHOCK: Breaking MPC Wallets and Digital Custodians for $BILLION$ Profit'. Below the title, it lists the speakers, date, format, and tracks, which include 'Cryptography' and 'Application Security: Offense'. The body of the slide is a detailed abstract explaining a new 0-day attack named TSSHOCK that breaks the security of Threshold Signature Scheme (TSS) protocols used in Multi-Party Computation (MPC) wallets, allowing attackers to steal billions of dollars worth of cryptocurrency. The original post caption 'Is it even meme?' highlights the surreal, almost unbelievable nature of the vulnerability's massive financial implications, blurring the line between a serious security announcement and dark, industry-shaking humor. It underscores the fragility of complex cryptographic systems and the cat-and-mouse game between builders and breakers in the high-stakes world of digital assets
Comments
14Comment deleted
This isn't your typical off-by-one error. This is an off-by-one-billion-dollars error
Three audits, two zero-knowledge proofs, and one PhD later, TSSHOCK proves the real threat model is a bored co-signer with 40 minutes to spare at Black Hat
The most expensive way to learn that "mathematically secure" and "implementation secure" are two completely different conferences
When your 'thoroughly audited' cryptographic implementation turns out to be a $BILLION treasure map with 'X marks the private key' written in invisible ink that only takes 1-2 signatures to reveal. Turns out homomorphic encryption and zero-knowledge proofs are great at keeping secrets - just not the ones you wanted them to keep. At least the attackers were polite enough to make it look innocent to the other parties; nothing says 'enterprise-grade security' quite like a heist that leaves no trace and passes all your monitoring checks
MPC: Multi-Party Computation, or Massive Profit Compromise - TSHOCK proves even threshold schemes leak when one party's impl is the chokepoint
MPC: split the key so no one can steal it - until one signer runs TSSHOCK, does two rounds, and quietly becomes the quorum while your audit report says “looks good.”
MPC wallets: engineered to eliminate a single point of failure; TSSHOCK reminds us that even with Rust, audits, and ZK slides, we didn’t eliminate the single point of malice
Cryptobros taking the L once again? Comment deleted
it better be a meme Comment deleted
*a humble request for clarification team support* Comment deleted
Homomorphic encryption is really young subfield of cryptography, so no surprise there. HE is bit like a cold fusion, there's been a lot of talk about it's promises but we're still not certain there is a way to make it really practical in the long run. Not without significant tradeoffs at least. Comment deleted
But yeah, the title is rather clickbaitish. Comment deleted
Hahahahaha. So much talk about privacy and security of cryptomoney. Now we see it is not really private nor really secure. Comment deleted
Ehh, from what I gather the impact is quite overstated. Where there's actually significant money at stake SMPC would be one of security layers in place. Comment deleted