TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hacker Redirects Traffic From 19 Internet Providers to Steal Bitcoins

171 pointsby muneebalmost 11 years ago

10 comments

mrbalmost 11 years ago
I work in InfoSec and it is mind-boggling to see the sophistication levels of some of the Bitcoin heists, like this BGP incident. When was the last time you saw a BGP attack? 99.9% of real-world attacks don&#x27;t even bother targetting such a core routing service. Another example: in March 2012, internal Linode management infrastructure was compromised to steal 47k BTC: <a href="http://blog.zorinaq.com/?e=67" rel="nofollow">http:&#x2F;&#x2F;blog.zorinaq.com&#x2F;?e=67</a> <a href="http://www.theregister.co.uk/2012/03/02/linode_bitcoin_heist/" rel="nofollow">http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2012&#x2F;03&#x2F;02&#x2F;linode_bitcoin_heist...</a> This means attackers had effectively root access to any Linode&#x27;s customers&#x27; VM! When was the last time you saw an entire cloud provider environment being compromised?<p>I like to see it as ISPs and cloud providers increasing their security and patching vulnerabilities thanks to Bitcoin&#x27;s growing adoption :)
评论 #8151054 未加载
评论 #8150828 未加载
评论 #8150814 未加载
评论 #8150866 未加载
评论 #8153240 未加载
评论 #8150870 未加载
kmodalmost 11 years ago
The finger-pointing at BGP is red herring: the problem is that the stratum protocol has zero authentication. If you can intercept those streams, you can trivially ask anyone to start mining for you instead. This could also have been done using DNS poisoning, ISP-side intercepts, or anything else in the standard bag of tricks. <a href="http://blog.kevmod.com/category/bitcoin/" rel="nofollow">http:&#x2F;&#x2F;blog.kevmod.com&#x2F;category&#x2F;bitcoin&#x2F;</a>
评论 #8150970 未加载
smutticusalmost 11 years ago
Here is the link to the original research.<p><a href="http://www.secureworks.com/cyber-threat-intelligence/threats/bgp-hijacking-for-cryptocurrency-profit/" rel="nofollow">http:&#x2F;&#x2F;www.secureworks.com&#x2F;cyber-threat-intelligence&#x2F;threats...</a>
评论 #8151069 未加载
mickayzalmost 11 years ago
The lack of auth and encryption is only part of the problem with Stratum&#x27;s implementation. At Toorcamp 2014 I presented about the vulnerabilities discovered when looking into common miners and their impact on the network. More details available in the associated white paper:<p><a href="http://www.dejavusecurity.com/blog/2014/7/15/bitcoin-research-whitepaper-announcement" rel="nofollow">http:&#x2F;&#x2F;www.dejavusecurity.com&#x2F;blog&#x2F;2014&#x2F;7&#x2F;15&#x2F;bitcoin-researc...</a>
0x0almost 11 years ago
Could this be prevented by adding some TLS to the mining control channels?
评论 #8150729 未加载
rdlalmost 11 years ago
It&#x27;s mind boggling to me that this wasn&#x27;t done a year or two ago.<p>If bitcoin were genuinely anonymous (it isn&#x27;t, because it&#x27;s highly linkable, even if essentially pseudonymous), it would probably be vastly more dangerous in this way -- there would be billions of dollars spent on exploiting security outside bitcoin++ to steal bitcoin++.
评论 #8152507 未加载
gluczywoalmost 11 years ago
Nobody has pointed it out so far. Since it is an attack on IP routing, it could be prevented by using SSL for the Stratum protocol used by mining pools.
评论 #8152184 未加载
driverdanalmost 11 years ago
I know a number of people who got hit by this type of reconnect attack. I suspect I may have been hit by it for short periods of time. Most of the big altcoin pools were targeted. Soon after most miner software was modified to disable this Stratum feature but there are still plenty of other issues with the Stratum protocol as highlighted by other comments.
scott_karanaalmost 11 years ago
Wow. Not sure why they don&#x27;t name-and-shame the ISP, but that&#x27;s really ridiculous.
评论 #8151014 未加载
评论 #8155223 未加载
评论 #8151057 未加载
评论 #8152360 未加载
nchellurialmost 11 years ago
Link is a 404 for me.
评论 #8150797 未加载