Private Key Recovery Combination Attacks: On Extreme Fragility of Popular Bitcoin Key Management, Wallet and Cold Storage Solutions in Presence of Poor RNG Events.
Nicolas T. Courtois, Pinar Emirdag, Filippo Valsorda · 2014
Abstract. In this paper we study the question of key management and practical operational security in bitcoin digital currency storage systems. We study the security two most used bitcoin HD Wallet key management solutions (e.g. in BIP032 and in earlier systems). These systems have ex-tensive audit capabilities but this property comes at a very high price. They are excessively fragile. One small security incident in a remote corner of the system and everything collapses, all private keys can be re-covered and ALL bitcoins within the remit of the system can be stolen. Privilege escalation attacks on HD Wallet solutions are not new. In this paper we take it much further. We propose new more advanced combi-nation attacks in which the security of keys hold in cold storage can be compromised without executing any software exploit on the cold sys-tem, but through security incidents at operation such as bad random number or related random events. In our new attacks all bitcoins over whole large security domains can be