MultiversX Tracker is Live!

I remembered Vultisig's AMAs here, then the recent wallet exploits sent me back to look at why their approach is different

All Cryptocurrencies

by COINS NEWS 9 Views

Some of you might remember Vultisig running an AMA on this sub a while back. Theirs stuck with me, because the pitch stood out: a seedless wallet & MPC tech. It was one of the more interesting security designs I'd seen posted here. The last couple weeks of wallet news brought it straight back to mind, because the things that just went wrong for other wallets are the exact things Vultisig is built to avoid.

Two stories set it off. Late July, a firmware bug in Coldcard caused some units to generate seeds with weak randomness, and attackers reconstructed those seeds remotely and drained them. TRM Labs put it around 1,816 BTC, over $116M. Then the data-leak side of the space kept getting hit. Ledger's 2020 breach exposed roughly a million emails and 272,000 records with names, phone numbers, and home addresses, which got dumped publicly and turned into phishing, extortion, even physical threats at people's homes. More recently a Trezor shipping provider got breached too (their own wallets and infrastructure were fine, it was a third-party fulfillment partner). Different companies but the same two failure modes: a compromised seed, and leaked customer data used to phish you, or worse.

Here is what made me think of Vultisig specifically. Both of those failures need a target that Vultisig does not give them. It is a seedless MPC wallet: instead of one seed phrase or one private key, your key is split into encrypted shares across your own devices (vault shares), and every transaction needs a threshold of them to sign. No single device moves funds alone, and there is no seed phrase in the setup at all. So the Coldcard-style attack has no seed to reconstruct, and a phishing email has no 24 words to ask you for.

The data-leak part is even more basic. Ledger and Trezor have to ship you a physical device, so somebody has to store your name, address, phone, and email, and that is the database that leaks. Vultisig is a free app you download. Nothing gets shipped, so there is no address book to breach, and they say they do not collect user data in the first place. You cannot leak what you never collected.

I am not going to claim any wallet is unhackable, and MPC has its own tradeoffs worth understanding before you move anything. Keep your hardware wallet if it is working for you. The point is that the two things that keep costing people, one bad seed and one leaked customer list, are designed out of this one. Yet again, it goes to show this sub contains great information.

submitted by /u/TimmyXBT
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments