{"id":31409,"date":"2017-02-20T15:48:06","date_gmt":"2017-02-20T20:48:06","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/a-single-typo-let-hackers-steal-400000-from-a-bitcoin-rival-aol-news.php"},"modified":"2017-02-20T15:48:06","modified_gmt":"2017-02-20T20:48:06","slug":"a-single-typo-let-hackers-steal-400000-from-a-bitcoin-rival-aol-news","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/cryptography\/a-single-typo-let-hackers-steal-400000-from-a-bitcoin-rival-aol-news.php","title":{"rendered":"A single typo let hackers steal $400000 from a bitcoin rival &#8211; AOL News"},"content":{"rendered":"<p><p>    Typos aren't just a headache  they can sometimes have very    costly consequences.  <\/p>\n<p>    On Friday, digital currency Zcoin announced that a    typographical error had let an unidentified attacker make a    profit of around $400,000 (320,000).  <\/p>\n<p>    Zcoin is similar to Bitcoin  it's a digital currency powered    by cryptography, and without any single central bank. It's    based on Zerocoin, a software protocol that was developed to to    provide its users with \"complete financial    privacy and anonymity.\"  <\/p>\n<p>    But in implementing it, the Zcoin made a single screw-up.    \"Yesterday, our team found a bug in our implementation of    Zerocoin,\" Zcoin    community manager Reuben Yap wrote in a blog post on    Friday. \"A typographical error on a single additional    character in code allowed an attacker to create Zerocoin spend    transactions without a corresponding mint.\"  <\/p>\n<p>    In other words, they got a single letter wrong in their code     and this let a hacker steal coins by cashing out from single    transactions multiple times.  <\/p>\n<p>    Yap emphasises that there's nothing wrong with Zcoin's    cryptography  it was just the typo that was the problem. \"The    exploit happened due to the bug in the code and not from any    weakness in the cryptography. The bug from the typo error    allowed the attacker to reuse his existing valid proofs to    generate additional Zerocoin spend transactions,\" he wrote.  <\/p>\n<p>    In short: It's human error, they argue, rather than any fatal    flaw in the Zcoin project.  <\/p>\n<p>    The still-unidentified attacker was able to steal around    370,000 Zcoins  around $680,000-worth    (546,000) at current exchange rates, according to    CoinMarketCap. Almost all of these have already been sold    on, netting the attacker a profit of around 410 bitcoin     $437,000 (351,000)      according to Zcoin.  <\/p>\n<p>    The attacker evaded detection for weeks by slowly making    payments and withdrawals. \"From what we can see, the attacker    (or attackers) is very sophisticated and from our    investigations, he (or she) did many things to camouflage his    tracks through the generation of lots of exchange accounts and    carefully spread out deposits and withdrawals over several    weeks,\" Yap wrote.  <\/p>\n<p>    \"We estimate the attacker has created about 370,000 Zcoins    which has been almost completely sold except for about 20,000+    Zcoin and absorbed on the market with a profit of around 410    BTC. In other words, the damage has already been mostly    absorbed by the markets.\"  <\/p>\n<p>    Get the latest Bitcoin price here.  <\/p>\n<p>    More from AOL.com:    After a local college went Bigfoot hunting, a    state senator introduced a bill nobody would have ever thought    necessary    Texas woman claims Popeyes served her    flesh-eating worms    Man spotted swimming dangerously close to    lava  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.aol.com\/article\/news\/2017\/02\/20\/a-single-typo-let-hackers-steal-400-000-from-a-bitcoin-rival\/21717749\/\" title=\"A single typo let hackers steal $400000 from a bitcoin rival - AOL News\">A single typo let hackers steal $400000 from a bitcoin rival - AOL News<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Typos aren't just a headache they can sometimes have very costly consequences. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1600],"tags":[],"class_list":["post-31409","post","type-post","status-publish","format-standard","hentry","category-cryptography"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/31409"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=31409"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/31409\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=31409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=31409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=31409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}