Broken Proofs of Solvency in Blockchain Custodial Wallets and Exchanges

6Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Since the Mt. Gox Bitcoin exchange collapse in 2014, a number of custodial cryptocurrency wallets offer a form of financial solvency proofs to bolster their users’ confidence. We identified that despite recent academic works that highlight potential security and privacy vulnerabilities in popular auditability protocols, a number of high-profile exchanges implement these proofs incorrectly, thus defeating their initial purpose. In this paper we provide an overview of broken liability proof systems used in production today and suggest fixes, in the hope of closing the gap between theory and practice. Surprisingly, many of these exploitable attacks are due to a) weak cryptographic operations, for instance SHA1 hashing or hash-output truncation to 8 bytes, b) lack of data binding, such as wrong Merkle tree inputs and misuse of public bulletin boards, and c) lack of user-ID uniqueness guarantees.

Cite

CITATION STYLE

APA

Chalkias, K., Chatzigiannis, P., & Ji, Y. (2023). Broken Proofs of Solvency in Blockchain Custodial Wallets and Exchanges. In Lecture Notes in Computer Science (Vol. 13412 LNCS, pp. 106–117). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-031-32415-4_9

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free