

others
HashEx Security Alert – A Single Signature Could Drain Your Wallet – Crypto News
HodlX Guest Post Submit Your Post
Zero days without incidents in the DeFi space. This time the vulnerability was discovered in a widely used ‘elliptic library.’
What makes matters worse
its exploitation could lead to hackers taking control of users’ private keys and draining wallets.All through a simple fraudulent message signed by a user. Is this a critical issue?
The first thing to consider is the fact that libraries like elliptic provide developers with ready-made code components.
This means that instead of writing the code from scratch and checking it as they go, developers just borrow the elements they need.
While it’s considered to be a safer practice, since the libraries are continuously used and tested, this also increases the risks if one vulnerability gets through.
Elliptic library is used extensively across the JavaScript ecosystem. It powers cryptographic functions in many well-known blockchain projects, web applications and security systems.
According to NPM statistics, the package containing the error is downloaded approximately 12–13 million times weekly, with over 3,000 projects directly listing it as a dependency.
This broad usage implies that the vulnerability potentially affects a vast number of applications
especially cryptocurrency wallets, blockchain nodes and electronic signature systems as well as any service relying on ECDSA signatures through elliptic, especially when handling externally provided input.This vulnerability allows remote attackers to fully compromise sensitive data without proper authorization.
That’s why the issue received an extremely high severity rating
approximately nine out of 10 on the CVSS scale.It’s important to point out that exploiting this vulnerability requires a very specific sequence of actions and the victim must sign arbitrary data provided by the attacker.
That means that some projects may remain safe, for example, if an application only signs predetermined internal messages.
Still, many users don’t pay as much attention when signing messages via crypto wallets as they do when signing a transaction.
Whenever a Web 3.0 site asks users to sign terms of service, users often neglect to read them.
Similarly, users might quickly sign a message for an airdrop without fully understanding the implications.
Technical details
The problem comes from not handling errors properly during the creation of ECDSA (Elliptic Curve Digital Signature Algorithm) signatures.
ECDSA is commonly used to confirm that messages, like blockchain transactions, are genuine.
To create a signature, you need a secret key
only the owner knows it and a unique random number called a ‘nonce.’If the same nonce is used more than once for different messages, someone could figure out the secret key using math.
Normally, attackers can’t figure out the private key from one or two signatures because each one uses a unique random number (nonce).
But the elliptic library has a flaw
f it gets an odd type of input (like a special string instead of the expected format), it could create two signatures with the same nonce for different messages.This mistake could reveal the private key, which should never happen in proper ECDSA use.
To exploit this vulnerability, an attacker needs two things.
- A valid message and its signature from the user for instance, from any previous interactions
- The user to sign a second message explicitly created to exploit the vulnerability
With these two signatures, the attacker can compute the user’s private key, gaining full access to funds and actions associated with it. Detailed information is available in the GitHub Security Advisory.
Exploitation scenarios
Attackers may exploit this vulnerability through various methods, including the following.
- Phishing attacks that direct users to fake websites and request message signatures
- Malicious DApps (decentralized applications) disguised as harmless services, such as signing terms of use or participating in airdrops
- Social engineering convincing users to sign seemingly harmless messages
- Compromising servers’ private keys that sign messages from users
A particularly concerning aspect is users’ generally lax attitude toward signing messages compared to transactions.
Crypto projects frequently ask users to sign terms of service or airdrop participation messages, potentially making exploitation easier.
So, think about it
would you sign a message to claim free tokens? What if that signature could cost you your entire crypto balance?Recommendations
Users must promptly update all applications and wallets that utilize the elliptic library for signatures to the latest secure version.
Exercise caution when signing messages, particularly from unfamiliar or suspicious sources.
Developers of wallets and applications should verify their elliptic library version.
If any users could be affected by the vulnerable version, developers must inform them about the urgent need for updating.
Gleb Zykov is the co-founder and CTO of HashEx Blockchain Security. He has more than 14 years of experience in the IT industry and over eight years in internet security, as well as a strong technical background in blockchain technology (Bitcoin, Ethereum and EVM-based blockchains).
Follow Us on Twitter Facebook Telegram
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any loses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
Generated Image: DALLE3
-
Blockchain1 week ago
The CFO and Treasurer’s Guide to Digital Assets – Crypto News
-
Cryptocurrency3 days ago
Pi Community Highlights Pi Coin’s Slow Growth As ‘Strategic’ – Crypto News
-
Cryptocurrency7 days ago
Solana Price Upside Prevails After Securing Key Support, $127 In Focus – Crypto News
-
Business1 week ago
Ethereum Whales Sell On Rise, Will This ETH Price Bounce Sustain? – Crypto News
-
Blockchain7 days ago
How to mine Bitcoin at home in 2025: A realistic guide – Crypto News
-
Blockchain6 days ago
CZ claps back against ‘baseless’ US plea deal allegations – Crypto News
-
Business1 week ago
Crypto Liquidations Hit $573 Million as BTC, ETH Sees rebound – Crypto News
-
Technology7 days ago
Microsoft’s Greatest Hits and Epic Fails: A 50-Year Wild Ride – Crypto News
-
Cryptocurrency1 week ago
BTC Risks Further Downside if it Fails to Reclaim This Resistance – Crypto News
-
Business1 week ago
US Senate Confirms Pro-Crypto Paul Atkins As SEC Chair – Crypto News
-
Cryptocurrency1 week ago
OpenAI Countersues Elon Musk, Accuses Billionaire of ‘Bad-Faith Tactics’ – Crypto News
-
Blockchain1 week ago
Bitpanda secures third MiCA license in home jurisdiction of Austria – Crypto News
-
Metaverse1 week ago
Amul girl to Nirma: Viral AI video brings classic Indian mascots to life, users stir debate over ethics – Crypto News
-
Blockchain1 week ago
BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LEO, LINK, AVAX – Crypto News
-
Cryptocurrency1 week ago
DOGE Price Moves as Dogecoin Whales Go on Buying Spree – Crypto News
-
Technology1 week ago
Dogecoin Price Gearing for A 3X Rally Amid DOGE Whale Accumulation – Crypto News
-
Technology7 days ago
How to transcribe and translate YouTube videos for free using Gemini 2.5 Pro? Check our step-by-step guide – Crypto News
-
others7 days ago
Binance Issues Important Update On 10 Crypto, Here’s All – Crypto News
-
Cryptocurrency7 days ago
Professor Coin: What’s Driving Cryptocurrency Adoption Around the World – Crypto News
-
others6 days ago
Ripple Community Remains Disappointed With Hinman Report, What’s Next? – Crypto News
-
others6 days ago
Mexican Peso ends week strong as USD plunges on China tariff retaliation – Crypto News
-
Cryptocurrency6 days ago
Shiba Inu [SHIB] price prediction – A 70% rally next after 900%+ burn rate hike? – Crypto News
-
Metaverse6 days ago
Forget DeepSeek. Large language models are getting cheaper still – Crypto News
-
Technology6 days ago
Apple ramps up India production amid China uncertainty, assembles $22 billion worth iPhones in a year – Crypto News
-
Blockchain4 days ago
On-Chain Clues Suggest Bitcoin Bounce Might Be a False Signal—Here’s What to Know – Crypto News
-
Blockchain2 days ago
Bitcoin online chatter flips bullish as price chops at $85K: Santiment – Crypto News
-
Business2 days ago
Cardano (ADA) and Dogecoin (DOGE) Eye For Bullish Recovery – Crypto News
-
Technology1 day ago
Expert Predicts Pi Network Price Volatility After Shady Activity On Banxa – Crypto News
-
Blockchain1 week ago
Investors Looking To Buy Bitcoin? – Crypto News
-
Cryptocurrency1 week ago
Galaxy’s imminent US listing reflects SEC change – Crypto News
-
others1 week ago
Crypto Products See $240,000,000 in Outflows Likely in Response to US Tariff Threats: CoinShares – Crypto News
-
Technology1 week ago
Best water purifiers in India April 2025: Which one saves maintenance costs while providing pure, safe drinking water? – Crypto News
-
Technology1 week ago
What It Means for NFT Traders – Crypto News
-
Blockchain1 week ago
SEC drops suit against Helium for alleged securities violations – Crypto News
-
Blockchain1 week ago
NY attorney general urges Congress to keep pensions crypto-free — ‘No intrinsic value’ – Crypto News
-
Technology1 week ago
iQOO Z10 5G, Z10x 5G launched in India, price starts at ₹13,499. Check full price, specs and more – Crypto News
-
Metaverse1 week ago
Google launches Gemini 2.5 Flash—Ideal for chatbots, assistants and instant summarisation – Crypto News
-
Business1 week ago
Cosmos Debuts Eureka to Bridge Ethereum – Crypto News
-
Blockchain1 week ago
Breakout To $1,800 With These Two Supply Zones – Crypto News
-
others1 week ago
GBP advance lags core peers – Scotiabank – Crypto News
-
others1 week ago
Russia Consumer Price Index (MoM) down to 0.65% in March from previous 0.8% – Crypto News
-
Blockchain7 days ago
Ethereum Capitulation Nearing Its End? Key On-Chain Metric Reveals Insights – Crypto News
-
Cryptocurrency7 days ago
Fusaka fork takes shape as Pectra enters final stretch – Crypto News
-
others7 days ago
There is more work to do on inflation – Crypto News
-
Business7 days ago
Bankless Cofounder David Hoffman Reveals Strategy To Improve Ethereum Price Performance – Crypto News
-
Blockchain7 days ago
XRP Price To Hit $45? Here’s What Happens If It Mimics 2017 And 2021 Rallies – Crypto News
-
Cryptocurrency6 days ago
Bitcoin – Here’s what’s next after sellers near exhaustion levels – Crypto News
-
others6 days ago
On-Chain Indicator Suggests Ethereum (ETH) Could Be Undervalued, According to Crypto Analyst – Crypto News
-
Technology6 days ago
Price drop on 43 inch TVs: Grab the best deals on Samsung, Sony, Xiaomi and more, up to 57% off – Crypto News
-
others6 days ago
Dow Jones recovers ground to post one of its best weeks in years – Crypto News