Dark Skippy:如何用 2 个签名破解你的硬件钱包私钥?

币界网Опубліковано о 2024-08-16Востаннє оновлено о 2024-08-16

币界网报道:

作者:OneKey 中文来源:X,@OneKeyCN

近期,海外加密安全圈炸锅了!又一个改进的硬件钱包破解手段被披露,速度更快、效率更高。难道黑客和白帽们也在搞“奥运”?

在这篇文章中,OneKey 将用尽量简单的语言为你解释这一切。让我们一起来潜入这个话题吧。

1. 黑客是如何破解硬件钱包的?

  1. 刷入恶意固件:攻击者将恶意固件刷到你的硬件钱包上。

  2. 发送交易:黑客使用这个带有恶意固件的硬件钱包发送比特币交易。恶意固件会将你的助记词通过低随机性签名的方式“嵌入”到这笔交易中,而这笔交易会公开存储在区块链上。

  3. 提取助记词:攻击者在区块链上找到你的交易,运行特殊算法,从中提取出你的比特币助记词。

  4. 盗取比特币:拿到助记词后,攻击者就能访问并盗走你的比特币。

2. 这个攻击算法的原理是什么?

要理解这个算法,你需要对 BTC 转账有些了解。如果你不是那种爱刨根问底的好奇宝宝,可以直接跳到下一部分,了解如何避免被攻击。

在进行比特币转账前,你需要准备交易数据,包括交易的输入(即你要花费的比特币来源)和输出(你要将比特币转到哪里)。随后,通过哈希算法计算出消息哈希值,这是需要签名的数据摘要,可理解为“浓缩的交易数据”。

关键步骤:签名

接下来是重头戏:你需要对这个交易数据进行签名。以椭圆曲线数字签名算法(ECDSA)为例,你需要结合一个内部随机数 k 来生成签名结果。

随机数 k 的引入是为了确保每次签名的唯一性和安全性。如果每次使用相同的随机数 k,即便你签署的消息(交易)不同,生成的签名可能会出现规律,从而被攻击者通过数学分析破解你的私钥。

因此,每次都使用一个不可预测的随机数 k,可以确保每次生成的签名都是独一无二的,即使对同一个消息进行多次签名,结果也会不同。

最后,矿工会验证并将交易打包广播到区块链。

黑客如何利用弱随机数攻击?

虽然无法直接从加密芯片上读取私钥,但如果黑客能修改你的固件里的随机算法,使随机数 k 不再随机,那么通过几次签名后,便可以通过链上广播的信息反推出你的私钥。

在 Dark Skippy 中,黑客将这个需求降低到只需 2 个签名(对于 12 个助记词)或 4 个签名(对于 24 个助记词)即可破解私钥。这比以往的方法更高效。

3. 如何避免被攻击?

这类攻击成功的关键在于:黑客成功拿到了用户的硬件钱包,并植入了恶意固件。

所以,建议采取以下防护措施:

1. 确保硬件钱包的安全

  • 防供应链攻击:确保硬件钱包从出厂、运输直到你的手里,未被第三方碰过。现在多家硬件钱包品牌,包括 OneKey,都有多层防拆封设计,确保如果有拆封痕迹能够立即发现。

  • 录像开箱:建议您从收到货开始全程录像开箱,作为售后依据。

  • 保管好钱包:开始使用后,确保硬件钱包不会被他人接触,以防被恶意修改。

2. 确保固件代码的安全

  • 从官网渠道下载更新:确保你从官方渠道下载固件更新。

  • 做好校验工作:不同厂商的措施不一。以 OneKey 为例,我们的软件和硬件代码是开源的,并通过了知名安全机构的审计。OneKey 最新硬件采用多颗军工级保密 EAL 6+ 芯片,机器和 App 会自动校验固件,非官方固件的签名会被检测到并硬抹除助记词数据。

4. 总结

无论如何,如果硬件钱包一旦丢失或落入黑客手中,建议立即启用备份助记词,尽快转移资产,确保万无一失。相比助记词触网存储和钓鱼攻击,这个风险仍然较小。

Пов'язані матеріали

Valuation Rout of Old Titans: The Demise of a Generation's Asset Valuation Framework

"The Old Titans' Valuation Collapse: The Death of an Era's Valuation Framework" Between Alibaba's 2014 NYSE debut at $93.89 and its 2026 price of ~$95, twelve years have passed with zero price appreciation. This stagnation symbolizes a wholesale valuation reset for an entire generation of Chinese internet assets. Companies like Tencent, Pinduoduo, Meituan, Bilibili, and Kuaishou have seen catastrophic declines of 80-98% from their peaks. The core question arises: what framework now prices these companies, or has the framework itself expired? The valuation logic for Chinese internet stocks followed a clear "anchor-setting and anchor-removing" process. From 2014-2017, the dominant narrative was "US comparable discounting" – applying a growth premium and governance discount to US peers' multiples. This anchor loosened with the 2018 US-China trade war and the VIE structure risk, then was violently uprooted by the 2020-2021 regulatory crackdowns (Ant Group, Didi, anti-monopoly fines). The 2022 delisting panic and subsequent 2025-2026 geopolitical shocks (US military lists, AI espionage accusations) completed the demolition. The old "US对标打折" model is dead. However, this is not solely a China story. A structural mirror exists in US "old titan" stocks ("老登股"). In 2026, even Microsoft – with robust fundamentals – saw its PE compress from a 34x median to 22x, its worst performer status among the "Magnificent Seven" driven by a $190 billion annual AI capex crushing free cash flow. The core dilemma is universal: legacy platform giants, whether Alibaba or Microsoft, are spending colossal sums to chase an AI paradigm that may颠覆 their own high-margin, user/subscription-based business models. They have shifted from "companies defining the future" to "companies needing to prove they won't be淘汰ed by the future." This phenomenon of a dying valuation坐标系 has a historical precedent: post-1989 Japan. After its bubble burst, the "Japan premium" narrative ("most efficient manufacturing + perpetual growth") collapsed. A 25-year valuation vacuum ensued until Warren Buffett provided a new language in the 2010s: "low valuation + high dividend + governance reform." China's internet sector is now in a similar vacuum six years into its reset. While different from Japan's deflationary context, the parallel is clear: the old macro assumption of "deep integration with global capital" is falsified, but a new pricing framework is absent. Potential "new languages" for Chinese internet valuations are contradictory. AI transformation requires gutting profitable core businesses (e.g., Alibaba's ad-driven e-commerce) for an unproven consumption-based model, risking a Microsoft-like cash flow crunch. Alternatively, shareholder returns (buybacks/dividends) could build a floor, following Buffett's Japanese playbook, but current scales are insufficient to form a standalone anchor. The current state mirrors mid-1990s Japan: the old framework is dead, the new one unborn. The market waits in a vacuum for a重新定义ing force – a person, event, or proven business model shift – to answer "why buy." This may only be the middle phase of a prolonged re-rating.

marsbit5 хв тому

Valuation Rout of Old Titans: The Demise of a Generation's Asset Valuation Framework

marsbit5 хв тому

STRC Trading at Significant Discount, mNAV Falls Below Break-Even, Strategy's Valuation Logic Has Been Rewritten

Title: STRC Deeply Discounted, mNAV Falls Below Break-even, Strategy's Valuation Logic Redefined The recent volatility in MSTR and STRC highlights the need to reassess the core business model of Bitcoin reserve companies. These entities function more like leveraged, single-asset banks rather than software/tech firms. Consequently, they should be valued using banking metrics, not based on their total Bitcoin holdings. The key valuation metric is mNAV (market net asset value), akin to a price-to-book ratio. It compares the company's market capitalization to the equity value of its Bitcoin holdings after deducting all senior debt and preferred equity (like STRC). As of June 24, Strategy's mNAV was 1.10x. The focus should be on "net Bitcoin per share" (the Bitcoin claim per share after senior claims) and its growth rate, equivalent to a bank's book value and return on assets. Given STRC's 19% discount to its $100 par value (yielding 14.2%), issuing new MSTR equity at the current price to buy more Bitcoin is inefficient. It slightly dilutes the widely watched "total Bitcoin per share" metric while providing minimal improvement to the more critical "net Bitcoin per share." The article analyzes four potential uses for $1 billion in new equity: 1. **Buy Bitcoin:** Least effective. Improves net Bitcoin per share only marginally while diluting total Bitcoin per share. 2. **Repurchase STRC:** Most effective for balance sheet repair. The discount creates immediate value, increasing net Bitcoin per share by 1.0%, reducing debt burden, and lowering future dividend obligations. 3. **Boost Cash Reserves:** Dramatically improves the "cash coverage ratio" for STRC dividends from 9.8 months to 16.8 months, a crucial liquidity metric in a tightening funding environment. 4. **50/50 Split (STRC buyback & cash):** A balanced approach improving all key metrics. Strategy's own Q1 report indicates its internal break-even mNAV for profitable equity issuance to buy Bitcoin is 1.22x. With the current mNAV at 1.10x, such a move would be value-destructive. The core assumptions of its previous expansion model—issuing STRC at par and maintaining ample dividend coverage—have broken down. The recommended path is to use new capital to optimize core financial health: repurchasing discounted STRC and/or bolstering cash reserves. This would repair the balance sheet, signal liquidity strength, support STRC's price, lower its yield, and potentially reopen the par-value issuance channel. The current STRC discount represents a low-cost capital opportunity to restart this positive cycle. Bitcoin reserve companies must be evaluated as banks, focusing on book value, leverage, and liquidity resilience.

Foresight News6 хв тому

STRC Trading at Significant Discount, mNAV Falls Below Break-Even, Strategy's Valuation Logic Has Been Rewritten

Foresight News6 хв тому

South Korean Institutions' Crypto Race: Dual Explosion of Stablecoins and RWA

**Summary: South Korea's Institutional Crypto Race: Stablecoins and RWA Take Off** South Korea is undergoing a structural shift in its crypto ecosystem, moving beyond its historical role as a major retail trading hub. Major financial institutions and internet platforms are now building institutional-grade blockchain infrastructure, with stablecoins and Real-World Asset (RWA) tokenization as the primary drivers. The push for a regulated Korean won stablecoin market is a major policy and corporate focus. This is driven partly by an estimated $115 billion outflow into dollar stablecoins like USDC, threatening the domestic financial system. Banks (e.g., KB Financial, Hana), payment giants (e.g., Shinhan Card, BC Card), and internet super-apps (KakaoPay, NAVER Pay) are all conducting pilots. The goal is to anchor future digital finance to the Korean won and local regulations. In RWA, South Korea is advancing rapidly within regulatory sandboxes, focusing on unique domestic assets beyond typical global templates like US Treasuries. Projects involve tokenizing ships (with Hyundai Heavy Industries), defense supply chain assets, and K-pop intellectual property, alongside more conventional assets. A legal framework is set for 2027, and platforms like NXT are preparing for regulated trading. Key opportunities for crypto-native projects lie in providing the underlying technology these traditional institutions lack: global distribution channels for tokenized assets, cross-chain liquidity solutions, and enabling infrastructure tools (e.g., for asset packaging and management). Partnerships, such as Solana with Shinhan Card or LayerZero with the Korea Gold Exchange, exemplify this proactive approach. Crucially, user access is being shaped by consumer platforms. NAVER's planned acquisition of Upbit's operator Dunamu and Kakao's development of a unified wallet aim to seamlessly integrate crypto with everyday payments for tens of millions of users. The race is now about which protocols and projects will become the foundational standards as regulation solidifies and institutional adoption accelerates.

Foresight News1 год тому

South Korean Institutions' Crypto Race: Dual Explosion of Stablecoins and RWA

Foresight News1 год тому

Торгівля

Спот
活动图片