Hack Alert : Users exposing private keys in memo while transfer !

Words
557
Reading
3 min
Listen
Play
9y

The Problem

The issue of users unknowingly exposing their private keys in memo while transferring their funds is a problem that has been time and again exposed by developers. The issue was raised by noisy@noisy in a very famous article (6 months ago):

We just hacked 11 accounts on Steemit! ~$21 749 in STEEM and SBD is under our control. But we are good guys 馃槆 So...

Then again the same problem was pointed out by popular steemit user Jerry Banfield, 2 months ago, in his article titled : I Found $63,278 of Private Keys on Steemit.com in 10 Minutes!

The private keys of user get exposed unknowingly as the users transfer their steem/SBD using the transfer option on steemit.

image.png

In the memo field, users tend to enter their private memo keys. Some users have exposed even their master passwords in the memo field.

How I accessed the exposed private keys:

It was really easy to query the steem database for exposed private keys using SteemData.

@Furion has provided an awesome tutorial on using SteemData titled: Getting started with SteemData.
I used RoboMongo as a cross-platform GUI utility for playing around with SteemData.

Accessing master passwords

I used the following simple query to get master passwords exposed on steem blockchain:

db.getCollection('AccountOperations').find({'memo': /^P5/})

This query yields 28 results. These are 28 independent transactions after the last hard fork where the private keys got exposed. I checked the length of these keys using https://www.lettercount.com/. (Yes, the password length is 52 ). I checked this by repeatedly generating new passwords using generate new password option in steemit.
image.png

The passwords have now been changed. That's a good thing. I will partially reveal only few of the account name and passwords anyway so that you know I am not bluffing. Anyways you can acess the other names by the query mentioned previously.

Account NamePrivate KeyTransaction idTimestamp
scigar@scigarP5HrWfmKXXXXX5293f4c83846a2c4b50c1bf2c52381f260b9a06c2017-06-03 23:17:57.000Z
steemboad@steemboadP5JJYBFXXXXX70069c982e98e7917fe13093f63266d2f995c9122017-11-12 09:15:54.000Z
fittrex@fittrexP5Kk17eRvytzXXXXXb18ac26c09f88c1e4211e30a6094a41f2b9654402017-10-13 00:32:00.000Z
herman2141@herman2141P5JJYBFNwYrn1m9ZFHHGXXXX70069c982e98e7917fe13093f63266d2f995c9122017-11-12 09:15:54.000Z
prosperous@prosperousP5KDF2BRMQcCVcRDHuzT6iy2oNshZw1JqyMfSuV4QXXXXXf3d62cba41df96db0f55be9a0f0752cb5a4d6eab2017-06-15 00:48:21.000Z

Accessing private memo/posting keys.

Hundreds, if not thousands of private memo keys have been exposed publicly in the blockchain transaction memos. Since these are publicly available, I will mention some them. They can be used to login to the accounts although any other action like posting/voting requires private posting keys.

I used the query mentioned below:

db.getCollection('AccountOperations').find({'memo': /^5/})

Then I checked which keys contained 51 characters. This gave me private memo keys or private posting keys of a large number of accounts. Some of them I will disclose below. I sincerely request these account owners to reset their passwords.

Account NamePrivate KeyTransaction idTimestamp
bestjt@bestjt5K1deWWcqGecvzsfNWDSPGZHTwXXXXXXXed26183ec4284c568e30c6fc2ce190db1dc144382017-11-16 17:23:48.000Z
beoped@beoped5KU12e2JPyh31iz5bYLKXVCAi4y79366gPku2keEwJ1XXXX3d562b3acebab7936da253e3671f71b0b4d83cf62017-11-16 14:00:36.000Z
ccoindigger@ccoindigger5K1UyjjZiVpUH2mAFdnChfZH2fEFte2qk8EVfCVDXXXXXX3cb3e6fe46733f9dd2be60453594be429deaf2bd2017-11-09 21:35:24.000Z
caspell@caspell5Ka2iTeUpzWYSYdF8wcw2pkf2tsMGr7QeTLsi7qC4GxmXXXXXXde2df1c7fde1dc8bb5ac2093f9a865293e81605a2017-11-15 03:06:57.000Z
cryptocryptov@cryptocryptov5Jqu16YDY83QKWWnwDinwmKhxK51DuCjdduXXXXXac39c483bd8cb7f21672a48f3fd9b5dde64c08612017-11-16 05:16:06.000Z

Hundreds of other private memo keys have also been exposed. It is a sincere request to all users to not enter their private keys as memos. Please spread awareness about this issue so that the problem can be resolved. As of now, the memo keys don't really do much. But in future, they may perform important functions as steem blockchain evolves.

Last 10 days Data Analysis:

Analysing last 10 days data for date-wise number of transactions exposing private keys we find the following pattern:

image.png

Thank You and take care.



Posted on Utopian.io - Rewarding Open Source Contributors

Hack Alert : Users exposing private keys in memo while transfer ! | Ecency