/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Fireblocks discloses BitForge, a set of zero-day flaws affecting widely used crypto wallets; Coinbase, Binance, and Zengo have patched their BitForge flaws

Tom Mitchelhill / Cointelegraph :

Cointelegraph Tom Mitchelhill

Context & Ripple Effects

BitForge extends a recurring record of wallet-security disclosures: researchers previously identified double-spending weaknesses in several major wallet applications, while protocol projects have also had to remediate severe wallet-related defects.

The immediate distinction here is that Fireblocks disclosed the issue set and Coinbase, Binance, and Zengo had already patched their affected flaws. That makes remediation speed and disclosure handling central to how wallet providers are judged.

First-order effects

  • Coinbase, Binance, and Zengo have closed the BitForge flaws identified by Fireblocks, reducing exposure in the affected wallet implementations.
  • Fireblocks’ disclosure puts the affected providers’ security review and patch-management processes under direct scrutiny.

Second-order effects

  • Other wallet providers face pressure to review comparable implementation paths and communicate whether they are affected, since prior research has shown wallet flaws can span multiple products.
  • For exchanges and wallet services, security response becomes a customer-trust differentiator alongside custody and trading features.

Third-order effects

  • Repeated disclosures could make independent security research, coordinated disclosure, and demonstrable patch discipline more important requirements for wallet providers seeking institutional and retail trust.
  • If such flaws remain recurrent, the sector’s history of serious crypto-wallet defects will reinforce the gap between crypto products’ financial role and the security assurances users expect of financial infrastructure.

The trend: Crypto wallet services are being pushed toward more mature vulnerability disclosure and remediation practices as security failures become a core legitimacy test.

Discussion

  • @cz_binance @cz_binance on x
    This issue was present in the TSS Library Binance open-sourced, which has been fixed. Thanks to Fireblocks for uncovering it! No @Binance user funds affected. Even MPC custody solutions have risks. Stay #SAFU! 🙏
  • @fireblockshq @fireblockshq on x
    1/ The Fireblocks research team has uncovered BitForge, a set of vulnerabilities in some of the most widely adopted MPC protocols, that allow an attacker to retrieve a private key from a single device. Read on → https://www.fireblocks.com/... [image]
  • @fireblockshq @fireblockshq on x
    2/ As part of our ongoing efforts to advance MPC security, we conducted responsible disclosure of the vulnerabilities to 15+ digital asset wallet providers & projects. The MPC-CMP & MPC-CMPGG protocols implemented by Fireblocks are unaffected & our customers' funds remain secure.