Blockchain_Blockchain Technology - yuyjo.com
No Result
View All Result
  • Home
  • Latest
  • Market
  • Cryptocurrency
  • NFT
  • Crypto Exchange
  • Digital currency
  • Metaverse
Blockchain_Blockchain Technology - yuyjo.com
  • Home
  • Latest
  • Market
  • Cryptocurrency
  • NFT
  • Crypto Exchange
  • Digital currency
  • Metaverse
No Result
View All Result
Blockchain_Blockchain Technology - yuyjo.com
No Result
View All Result
Advertisements

Security Vulnerability in Tron Puts Thousands of Wallets at Risk of Hijacking

Madonna by Madonna
01/22/2025
blank

A newly discovered security flaw in Tron’s blockchain has compromised over 14,500 wallets, putting millions of dollars in digital assets at risk. The vulnerability, linked to the UpdateAccountPermission feature, has already led to the hacking of 2,130 wallets, with nearly $31.5 million stolen in the final quarter of 2024.

Advertisements

Rather than stealing funds outright, hackers exploit the flaw by taking control of affected wallets and blocking the legitimate owners from making transactions. As a result, victims are locked out of their accounts, but they may unknowingly continue adding more funds to the compromised wallets, which only benefits the attackers.

Advertisements

The Exploit Behind the Flaw

The UpdateAccountPermission feature is designed to enhance account security by incorporating multisig-like functionality. It allows users to assign specific roles to keys and establish transaction approval thresholds. For example, a threshold might require two keys with equal weight to approve a transaction, improving security by preventing unauthorized access.

Advertisements

However, this system becomes a potential weakness if an attacker gains access to the owner’s private key. Once compromised, the attacker can add their key to the account and manipulate the system to meet the required approval threshold, effectively locking the rightful owner out of their own funds while still allowing new deposits.

Advertisements

Mykhailo Tiutin from AMLBot explained, “Wallets do not have any kind of notifications or information to say that somebody has added another key to your wallet. There is absolutely no indication that your wallet is gone until you send an outgoing transaction yourself.”

The Consequences and Lack of Recovery

Once a wallet is hijacked, victims are unable to access their funds without the attacker’s private key. As security expert Sattvik Kansal, co-founder of Rome Protocol, pointed out, this breach is particularly concerning because the affected user cannot recover their funds on their own.

UpdateAccountPermission: A Double-Edged Sword

While the UpdateAccountPermission feature is designed to enhance security by enabling shared control over wallets—ideal for businesses, decentralized organizations, and individual users—it also comes with inherent risks. Multiple signatures for transactions provide added protection against unauthorized access, but the feature can be exploited if an attacker gains access to a private key.

A Broader Issue Across Blockchains

The exploitation of blockchain functions is not limited to Tron. Ethereum has also seen its fair share of attacks, with attackers exploiting features like “approve” and “permit” on decentralized finance platforms. A recent Scam Sniffer report revealed that phishing scams across multiple blockchains, excluding Tron, led to $9.38 million in losses in November 2024, with Ethereum accounting for nearly $7 million of that total.

How to Protect Your Wallet from Exploits

To safeguard against silent wallet hijackers, security experts recommend regularly reviewing account permissions and understanding Tron’s permission system. The most critical measure, however, is securing private keys and avoiding sharing them with untrusted parties. In some cases, victims’ private keys were exposed during smart contract testing, leading to the vulnerability.

Additionally, experts suggest limiting the amount of Tron (TRX) in wallets, particularly for USDT transactions, as this can make wallets harder for attackers to exploit. Using wallets that do not require burning TRX for USDT transactions is also recommended.

As the crypto community grapples with these vulnerabilities, proactive security practices are crucial to protecting digital assets from increasingly sophisticated attacks.

Related topics:

Rep. Guy Reschenthaler Reveals Holdings in Bitcoin, XRP, and Solana

XRP vs SEC: Expert Discusses Potential Outcome Post-January 20

Reliance Jio Introduces Jiocoin in Blockchain-Based Rewards Program

Tags: BitcoinEthereum
Previous Post

BNB Chain Unveils AI Agent Solution to Empower Developers

Next Post

SEC Establishes Task Force to Regulate Crypto Assets

Madonna

Madonna

Madonna, the esteemed author of our blockchain website, is a recognized authority in the field. With a wealth of experience and expertise, she brings a profound understanding of blockchain technology. Her professional insights and commitment to excellence make her a trusted source for navigating the complexities of the blockchain industry.

Related Posts

Anthropic CEO Advocates for AI Transparency, Opposes Trump Bill’s Decade – long State Regulatory Freeze
Cryptocurrency

Anthropic CEO Advocates for AI Transparency, Opposes Trump Bill’s Decade – long State Regulatory Freeze

06/06/2025
Coinbase Data Breach Escalates as Victims Receive Physical Scam Mail
Cryptocurrency

Coinbase Data Breach Escalates as Victims Receive Physical Scam Mail

06/06/2025
VerifiedX Introduces Vault Accounts, Revolutionizing Bitcoin Security
Cryptocurrency

VerifiedX Introduces Vault Accounts, Revolutionizing Bitcoin Security

06/06/2025
Circle Makes Wall Street Debut, Becoming the First Major Stablecoin Issuer on NYSE
Cryptocurrency

Circle Makes Wall Street Debut, Becoming the First Major Stablecoin Issuer on NYSE

06/06/2025
Hong Kong Prepares to Legalize Bitcoin and Crypto – Derivatives in Bid for Web3 Leadership
Cryptocurrency

Hong Kong Prepares to Legalize Bitcoin and Crypto – Derivatives in Bid for Web3 Leadership

06/06/2025
Ethereum’s Price Surges 90% After Key Indicator Signals Bullish Trend
Cryptocurrency

Ethereum’s Price Surges 90% After Key Indicator Signals Bullish Trend

06/06/2025
Next Post
Odell Beckham Jr. Leads NFL Stars’ Bitcoin Charge

SEC Establishes Task Force to Regulate Crypto Assets

Pepe Coin Price Declines as Smart Money Exits: Rally in Doubt

WhiteBIT TR Partners with Misyon Bank Amid Turkey's Evolving Crypto Landscape

Bitcoin Price Retreats After Rally, Crypto Market in Flux

Trump Grants Full Pardon to Ross Ulbricht, Slams Life Sentence as ‘Ridiculous’

Recent Posts

US President Trump: The final agreement with Japan must be approved, but we haven’t reached a final agreement yet

James Wynn: Unwilling to return empty-handed, he will plunder the small assets in the old wallet to make a comeback

06/06/2025
The short position floating profit of Abraxas Capital has exceeded 55 million US dollars

The short position floating profit of Abraxas Capital has exceeded 55 million US dollars

06/06/2025
In May, the trading volume of global decentralized exchanges reached 474.1 billion US dollars, second only to that of January this year

Cryptocurrency advocacy groups urge lawmakers to incorporate a bill to protect software developers into market structure legislation

06/06/2025
The U.S. spot Bitcoin ETF saw a net outflow of 614.02 million U.S. dollars yesterday

Trump Media Technology Group submitted Form S-3, raising a total of approximately 2.3 billion US dollars

06/06/2025
Anthropic CEO Advocates for AI Transparency, Opposes Trump Bill’s Decade – long State Regulatory Freeze

Anthropic CEO Advocates for AI Transparency, Opposes Trump Bill’s Decade – long State Regulatory Freeze

06/06/2025
Coinbase Data Breach Escalates as Victims Receive Physical Scam Mail

Coinbase Data Breach Escalates as Victims Receive Physical Scam Mail

06/06/2025
Blockchain_Blockchain Technology - yuyjo.com

Yuyjo is a blockchain portal. Its main columns include Cryptocurrency, NFT, Crypto exchange, Digital currency, Metaverse and other columns. 【Contact us: [email protected]】

Recent News

  • James Wynn: Unwilling to return empty-handed, he will plunder the small assets in the old wallet to make a comeback 06/06/2025
  • The short position floating profit of Abraxas Capital has exceeded 55 million US dollars 06/06/2025
  • Cryptocurrency advocacy groups urge lawmakers to incorporate a bill to protect software developers into market structure legislation 06/06/2025

TAGS

APENFT Binance Binance Futures Bitcoin CBDC Coinbase Coinbase Account Coinbase Wallet Digital Coin Digital Dollar Digital Rupee Digital Yuan Ethereum Facebook Metaverse Gemini Kraken NFT Coin NFT Collection OKCoin
No Result
View All Result
  • Home
  • Latest
  • Market
  • Crypto Exchange