|

Bitcoin SV multisig mechanism gets hacked, user loses nearly $100,000

  • A BSV user reports that he has lost nearly $100,000 due to a multisig script bug.
  • BSV/USD shows little reaction to the news, continues moving inside the $150-$180 range.

The hackers exploited Bitcoin SV network vulnerability to steal the assets of a user. The Chinese media outlets report that at least one user lost 600 BSV, $97,000, due to the hack attack.

How the assets were stolen

The cryptocurrency user, aka aaron67, wrote in his blog post that the multisig solution implemented by Electrum SV contained a critical mistake that cost him 600 BSV.

The incident happened at around 2.00 am on November 6, when the user withdrew 6 UTXO (Unspent Transaction Output) with multisig, worth 100 BSV each. Later on the same day, he attempted another withdrawal of an extra 6 UTXO and an hour later, the hacker used the exploit to transfer all the money to the address 1LcKTzSzpMAwH4bzymGSkbhY2EBpmT7n5J. 

BSV transactions

BSV transactions

The co-founder of Blockstream, Gregory Maxwell, explained that Bitcoin SV developers ripped out the existing multisig mechanism P2SH and had to progress their own scheme. Thus, they came up with the idea of Electrum SV, also known as accumulator multisig.

This script looks similar to a P2PKH (Pay to Pubkey Hash) algorithm that adds up the number of passes and compares them to a threshold. In fact, the script used the 'less than or equal' parameter instead of 'greater than or equal' number of signatures in a multisig. 

The result is that these scripts had no security at all and could just be spent by a scriptsig that pushes a couple of zeros. Because the only sane usage is when you provide exactly the threshold number of signatures (why would you waste fees providing too many signatures?!?) they presumably only ever tested the 'orequals' path and didn't notice that it didn't work with too many signatures as intended but did work with too few signatures (such as none at all). 

A famous cryptographer, Adam Back, believes that this bug affects only BSV as the standard P2SH multisig was removed and replaced by a buggy home-brew solution after the fork.

BSV is locked in a range

Meanwhile, at the time of writing, Bitcoin SV is changing hands at $164. The coin with the current market capitalization of $3 billion has gained nearly 2% on a day-to-day basis amid the recovery from the recent low of $146 hit on November 4.  The coin has been locked in a range of $150-$180 since the beginning of September.

IntoTheBlock's data on In/Out of the Money Around Price (IOMAP) shows that there is strong resistance between the current price and $169 as nearly 100,000 addresses are holding 764 million coins there. This formidable supply wall can trigger a sharp downside correction if prices rebound strongly enough. 

Once it is out of the way, the next big cluster of addresses around $181, which roughly coincides with the upper border of the recent consolidation channel, will come into focus.

BSV's IOMP data

BSV's IOMAP data

On the other hand, the way to the south is less cluttered with the supply areas. Nearly 135,000 addresses holding over 500,000 coins create local support on approach to $160. If it gives way, the sell-off may gain traction. The IOMAP cohorts show that the next significant supply level sits around $155 and coincides with the lower barrier of the consolidation channel.

BSV/USD daily chart

BSV/USD daily chart

On the daily chart, the above-mentioned resistance of $181 is reinforced by EMA100 and the Bollinger Bands upper line. Meanwhile, the lower line of the BB confirms the support zone in the approach to $155 level.

Author

Tanya Abrosimova

Tanya Abrosimova

Independent Analyst

 

More from Tanya Abrosimova
Share:

Editor's Picks

Ripple technical weakness persists as selling intensifies toward $1.00

Ripple grinds lower, trading around $1.10 at the time of writing on Wednesday. The sticky bearish outlook mirrors the broader crypto market, with major coins such as Bitcoin and Ethereum facing weak demand as investors de-risk.

Crypto Today: Bitcoin, Ethereum, XRP face downside pressure amid investor de-risking

Major crypto assets trade under intense headwinds on Wednesday, as market participants navigate complex geopolitical and macroeconomic environments. Bitcoin has slipped toward $61,000 after its recent rebound was sold near $64,000, leaving buyers exhausted.

Bitcoin Price Forecast: Sticky inflation fears threaten deeper sell-off in BTC

Bitcoin extends its decline on Wednesday, trading below $61,500 at the time of writing as renewed US-Iran tensions keep the risk sentiment capped. In addition, persistent capital outflows from US-listed spot Exchange Traded Funds continue to fuel selling pressure on BTC.

Pi Network extends decline as CEX outflows fail to offset bearish pressure

Pi Network edges lower on Wednesday, extending its third consecutive day of losses. The technical outlook for PI is largely bearish, with a risk of a steeper correction below $0.1184.

Bitcoin: After the bloodbath, everyone looks at $60,000
Bitcoin (BTC) hovers above $62,000 at the time of writing on Friday, weighed down by growing risk-off sentiment due to persistent geopolitical tensions in the Middle East and sticky macroeconomic uncertainty. The institutional sell-off continued to wreak havoc on capital flows, with spot Bitcoin Exchange-Traded Funds (ETFs) recording billions in outflows.