Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Crypto’s Historic May 2026 Inside the CLARITY Act, Trump EO & Fed Shift
    Crypto’s Historic May 2026: Inside the CLARITY Act, Trump EO & Fed Shift
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    The Web3 Job Scam Draining Crypto Wallets Worldwide
    The Web3 Job Scam Draining Crypto Wallets Worldwide
    BlackRock Tokenized Treasury Filings 2026 The RWA Boom Goes Institutional
    BlackRock Tokenized Treasury Filings 2026: The RWA Boom Goes Institutional
    Bitcoin Pizza Day: How 10,000 BTC Turned into real money
    Bitcoin Pizza Day: How 10,000 BTC Turned Monopoly Money Into Real Money
  • Opinion
    OpinionShow More
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

BitGo Patches Vulnerability in its TSS wallet

The vulnerability was found last year in December, and BitGo fixed it by releasing a patch.

Written By:
Rajpalsinh

Last updated: March 18, 2023 12:14 PM
Published 2023-03-18
Share
Last updated: March 18, 2023 12:14 PM
Published 2023-03-18
BitGo Patches Vulnerability in its TSS wallet

Crypto wallet BitGo recently patched up its TSS protocols after observing certain vulnerabilities. Bitgo had recently released Ethereum and ERC-20 Threshold Signature Scheme (TSS) wallets, that were infected by critical bugs.

The bug bound in the smart contract of BitGo was so critical that if exploited, it could potentially compromise the private key access of exchanges, banks, businesses, and users of the platform.

According to Fireblocks, the vulnerability was present in BitGo’s TSS (Threshold Signature Scheme) protocol. It said in a blog post, “Attackers can bypass all security measures, gain access, and steal all the funds from the wallet” by exploiting the bug.

The vulnerability, called “Zero Proof” was found in the protocol’s SDK “BitGoJS”, which is used by their client to interact with the BitGo API through Java Script. Attackers could breach the code with very little effort and gain control of the private key. 

After tracking down the bug, the Fireblocks cryptography research team shared the details with BitGo on Dec 5, and so BitGo took immediate action. The platform suspended the affected service on Dec 10, 2022.

The Fireblocks’ cryptography research team claimed to have discovered the vulnerability in the self-managed Ethereum (ECDSA) wallet implementation of BitGo in December. The flaw, which could have led to secret shares like private keys theft, was later addressed by the digital asset trust company.

However, BitGo denied the assertion that Fireblock was the initial entity to discover a vulnerability. The flaw had already been identified and recorded on BitGo’s open-source code, available on GitHub. Typically, software developers release early versions of their open-source code to gather feedback and pinpoint defects, and BitGo followed the same approach.

Additionally, all impacted wallets were owned by 20 BitGo-affiliated developers who were testing the wallets during the early stages before their complete deployment. No assets or private keys belonging to any clients were compromised, as they were not authorized to use wallets during this early stage.

BitGo asserts to have filtered out the vulnerability by releasing a patch in February, and has nothing to do with “Fireblocks’s unethical disclosure process”, stated in a personal conversation with Crypto Times.

Fireblocks also explained a technical overview of how one could exploit the vulnerabilities and drain funds held in a user’s wallet.

Although Fireblocks claimed that it had followed a “coordinated disclosure” process between its research team and BitGo’s security team, BitGo strongly refuted Fireblocks’ characterization of events.

BitGo published a blog post and accused Fireblocks of “turning a known gap into a publicity stunt,” and said, “This is not how coordinated disclosures are supposed to work.”

Also Read: Euler Finance Witnesses Flash Loan Attack, Largest Hack of 2023

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Rajpal Singh - Former Crypto Journalist at The Crypto Times
By Rajpalsinh
Meet Rajpalsinh, a Content Writer at The Crypto Times, where his magical hands, with over 2 years of experience, transform the cryptic world of crypto into laughably simple tales.

Latest News

Circle Prepares USDC for Quantum Era With New Roadmap
Circle Prepares USDC for Quantum Era With New Roadmap
XRP Fee Burns Drop 35% as XRP Ledger Activity Drops
XRP Fee Burns Drop 35% as XRP Ledger Activity Drops
Saturn Adopts Chainlink CCIP to Scale Bitcoin-Backed Digital Credit
Saturn Adopts Chainlink CCIP to Scale Bitcoin-Backed Digital Credit
BitFi Unveils Public Sale as BFI Governance Token Nears Launch
BitFi Unveils Public Sale as BFI Governance Token Nears Launch
Solana Founder Signals Support for New SOL Burn Mechanism Proposal
Solana Founder Signals Support for New SOL Burn Mechanism Proposal

Find Us on Socials

You may also like

Crypto Market Today BNB Outperforms at $700 as BTC Holds $73K

Crypto Market Today: BNB Outperforms at $700 as BTC Holds $73K

Indian Police Probes ₹1.61 Crore Cryptocurrency Investment Fraud

Indian Police Probes ₹1.61 Crore Cryptocurrency Investment Fraud

Circle Blocks Zama Confidential USDC Contract Freezing $12.6M in User Funds

Circle Blocks Zama Confidential USDC Contract Freezing $12.6M in User Funds

$143M Gone BTC and ETH ETFs Extend Subdued Institutional Demand

$143M Gone: BTC and ETH ETFs Extend Subdued Institutional Demand

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information