BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
FOLLOW
BlockNews
  • Crypto
  • Finance
  • Politics
  • Memecoins
  • NFT
  • Technology
  • Opinion
No Result
View All Result
BlockNews

Research Team Discovers a Zero-Day $500 Million Vulnerability in Tron Multisig Accounts

by BlockNews Team
June 1, 2023
in Business, Crypto, Media, Technology
A A
Research Team Discovers a Zero-Day $500 Million Vulnerability in Tron Multisig Accounts
1
SHARES
Share on TwitterShare on Reddit
  • The researchers at dWallet Labs reported that Tron verifies signatures instead of signers.
  • They revealed that the vulnerability could have affected the $500 million assets stored in Tron multisig accounts
  • 0d had once made a report about the vulnerability to Tron in February, and Tron had it fixed after a few days.

In an age where scammers and cybercriminals are roaming around in the Web3 space and looking for an easy score, researchers, investigators, and security firms have made it their job to discover vulnerabilities (ranging from critical to minimal harm) within the Web3 ecosystem.

On May 30, the research team at dWallet Labs—a blockchain cybersecurity company—announced that it had discovered a vulnerability in Tron Multisig, which could put the digital assets worth $500 million and stored on accounts on Tron at risk.

According to 0d—the research team—there was a discovery of a critical zero-day vulnerability on the Tron network. This vulnerability could enable any signer with a Multisig account to overcome the multi-sig security provided by Tron, irrespective of the number of signers stated in the account.

“Verifiers cannot distinguish between randomly chosen nonces and deterministic ones,” 0d said.

How Does This Work?

Multisignature wallets allow for joint custody of accounts, providing users with different keys, which would all be required whenever they needed access to approve transactions.

According to dWallet Labs, Tron checks for the uniqueness of signatures and does not verify the signer of the accounts. Therefore, each signature created through a nonce would be regarded as a credible vote and permit anyone possessing the signatures a double vote.

This could have been a chance for anyone wandering upon Tron’s vulnerability to jeopardize the security of the $500 million of assets stored on the platform since the verifier could not identify whether the deterministic process created the random signature or was utterly unexpected.

“We can bypass the multisig verification process by signing the same message with non-deterministic nonces of our choice,” 0d said.

Doing so would have granted the research team permission to create various valid signatures for the same message by the same private key.

Thus, anyone with malicious intentions could conduct several transactions in all multi-sig wallets, which they are privy to, despite the thresholds in place.

0d stated that it had reported this vulnerability issue to Tron in February through the bounty program, and the company had responded swiftly, providing a fix a few days later. As a result of this report, 0d was given a bounty reward for discovering a high-severity vulnerability through Tron’s bounty program.

Tron’s solution in fixing the vulnerability was commended as simple and efficient. Rather than compare the signatures against the list of signatures, the verifiers now compare the signed address against the list of addresses.

Conclusion

Tron Multisig was saved from what would have been a catastrophic incident should any attacker have discovered 0d; the dWallet Labs’ research team reported the high-severity vulnerability within the network. Tron Multisig has since fixed the vulnerability and launched an updated version.

Tags: cryptoMultisigTechnologyTron
TweetShareShare

DON'T MISS THESE! HOT OFF THE PRESS

JRNY CLUB Announces $JRNY Token and EARN Platform
Breaking News

JRNY CLUB Announces $JRNY Token and EARN Platform

May 7, 2025
Everything You Need to Know About Doodles Upcoming DOOD Token
Crypto

Everything You Need to Know About Doodles Upcoming DOOD Token

May 7, 2025
Mark Cuban Slams Trump’s Crypto Ventures as Self-Serving Disaster: Is This True?
Crypto

Mark Cuban Slams Trump’s Crypto Ventures as Self-Serving Disaster: Is This True?

May 7, 2025
U.S. Aims to Become Premier Hub for Digital Asset Innovation, Says Bessent
Crypto

U.S. Aims to Become Premier Hub for Digital Asset Innovation, Says Bessent

May 7, 2025
Analysts Predict Solana’s POPCAT Could Double Amid Surging Memecoin Interest: Here is Why
Crypto

Analysts Predict Solana’s POPCAT Could Double Amid Surging Memecoin Interest: Here is Why

May 7, 2025
Google Stock Tumbles Over 9% Amid Apple’s AI Search Plans: Is This a Buying Opportunity?
Business

Google Stock Tumbles Over 9% Amid Apple’s AI Search Plans: Is This a Buying Opportunity?

May 7, 2025
Load More

Related News

JRNY CLUB Announces $JRNY Token and EARN Platform

JRNY CLUB Announces $JRNY Token and EARN Platform

May 7, 2025
Everything You Need to Know About Doodles Upcoming DOOD Token

Everything You Need to Know About Doodles Upcoming DOOD Token

May 7, 2025
Federal Reserve Holds Steady as Trump Tariffs Threaten Economic Stability: The Hard Truth Exposed

Federal Reserve Holds Steady as Trump Tariffs Threaten Economic Stability: The Hard Truth Exposed

May 7, 2025
Mark Cuban Slams Trump’s Crypto Ventures as Self-Serving Disaster: Is This True?

Mark Cuban Slams Trump’s Crypto Ventures as Self-Serving Disaster: Is This True?

May 7, 2025
Federal Reserve Holds Rates Steady Amid Tariff Uncertainty: Trump Disappointment Grows

Federal Reserve Holds Rates Steady Amid Tariff Uncertainty: Trump Disappointment Grows

May 7, 2025
Discord Twitter Youtube TikTok Instagram

BLOCKNEWS.COM

BlockNews

BlockNews.com is your premier source for real-time cryptocurrency, blockchain, and financial market news.

Our mission is to deliver accurate, timely, and insightful information to help both seasoned investors and newcomers navigate the evolving digital economy.

With in-depth analysis, exclusive insights, and up-to-date news, BlockNews.com keeps you informed on the latest trends in crypto, DeFi, NFTs, tech, and beyond.

Stay ahead of the herd with BlockNews.com

RESOURCES

  • About
  • Newsletter
  • Advertise
  • Terms and Conditions
  • Privacy Policy

POPULAR TOPICS

$ADA $XRP AI Avalanche Binance Bitcoin Bitcoin ETF blackrock Blockchain BTC Business Cardano China Coinbase crypto cryptocurrency Crypto Exchange Crypto Regulation DeFi Dogecoin Donald Trump Elon Musk ETF eth ethereum Federal Reserve FTX Gary Gensler grayscale Memecoin metaverse Microstrategy NFT NFTs PEPE ripple sec Shiba Inu Solana Stablecoin Technology twitter US Web3 xrp

GET QUICKER UPDATES ON X

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.

No Result
View All Result
  • Home
  • Crypto
  • Memecoins
  • Technology
  • Politics
  • Finance
  • NFT
  • DeFi
  • Opinion

© 2022-2025 BlockNews.com - Crypto and NFT news website by Aiur Labs.