Skip to content
DevMeme
4850 of 7590
Blockchain Post #5310 · source on Telegram

So you're telling me there's a multi-billion dollar bug?

Description

The image is a screenshot of a presentation slide for a talk at the Black Hat security conference. The slide has a dark, abstract background with blue and green wispy patterns. The title of the talk is 'TSSHOCK: Breaking MPC Wallets and Digital Custodians for $BILLION$ Profit'. Below the title, it lists the speakers, date, format, and tracks, which include 'Cryptography' and 'Application Security: Offense'. The body of the slide is a detailed abstract explaining a new 0-day attack named TSSHOCK that breaks the security of Threshold Signature Scheme (TSS) protocols used in Multi-Party Computation (MPC) wallets, allowing attackers to steal billions of dollars worth of cryptocurrency. The original post caption 'Is it even meme?' highlights the surreal, almost unbelievable nature of the vulnerability's massive financial implications, blurring the line between a serious security announcement and dark, industry-shaking humor. It underscores the fragility of complex cryptographic systems and the cat-and-mouse game between builders and breakers in the high-stakes world of digital assets

Comments

14
Anonymous ★ Top Pick This isn't your typical off-by-one error. This is an off-by-one-billion-dollars error
  1. Anonymous ★ Top Pick

    This isn't your typical off-by-one error. This is an off-by-one-billion-dollars error

  2. Anonymous

    Three audits, two zero-knowledge proofs, and one PhD later, TSSHOCK proves the real threat model is a bored co-signer with 40 minutes to spare at Black Hat

  3. Anonymous

    The most expensive way to learn that "mathematically secure" and "implementation secure" are two completely different conferences

  4. Anonymous

    When your 'thoroughly audited' cryptographic implementation turns out to be a $BILLION treasure map with 'X marks the private key' written in invisible ink that only takes 1-2 signatures to reveal. Turns out homomorphic encryption and zero-knowledge proofs are great at keeping secrets - just not the ones you wanted them to keep. At least the attackers were polite enough to make it look innocent to the other parties; nothing says 'enterprise-grade security' quite like a heist that leaves no trace and passes all your monitoring checks

  5. Anonymous

    MPC: Multi-Party Computation, or Massive Profit Compromise - TSHOCK proves even threshold schemes leak when one party's impl is the chokepoint

  6. Anonymous

    MPC: split the key so no one can steal it - until one signer runs TSSHOCK, does two rounds, and quietly becomes the quorum while your audit report says “looks good.”

  7. Anonymous

    MPC wallets: engineered to eliminate a single point of failure; TSSHOCK reminds us that even with Rust, audits, and ZK slides, we didn’t eliminate the single point of malice

  8. @YaroST12 3y

    Cryptobros taking the L once again?

  9. @callofvoid0 3y

    it better be a meme

  10. @FunnyGuyU 3y

    *a humble request for clarification team support*

  11. @CcxCZ 3y

    Homomorphic encryption is really young subfield of cryptography, so no surprise there. HE is bit like a cold fusion, there's been a lot of talk about it's promises but we're still not certain there is a way to make it really practical in the long run. Not without significant tradeoffs at least.

  12. @CcxCZ 3y

    But yeah, the title is rather clickbaitish.

  13. @Agent1378 3y

    Hahahahaha. So much talk about privacy and security of cryptomoney. Now we see it is not really private nor really secure.

    1. @CcxCZ 3y

      Ehh, from what I gather the impact is quite overstated. Where there's actually significant money at stake SMPC would be one of security layers in place.

Use J and K for navigation