• News/
  • https://www.theregister.com/2024/03/19/crypto_wallet_providers_urged_to/

Crypto wallet providers urged to rethink security as criminals drain them of millions

The Register
·
Connor Jones
·
Published Mar 19, 2024
·
Updated

Infosec researchers are noting rising cryptocurrency attacks and have encouraged wallet security providers to up their collective game. Check Point specifically cites the growth of attacks that abuse Ethereum's CREATE2 opcode, dubbing it a "critical issue in the blockchain community" that's seeing millions of dollars worth of assets being drained from victims' wallets. Introduced in 2019, CREATE2 is seen as a significant advancement for Ethereum, allowing for more efficient deployments of smart contracts – the technology that validates transactions on the blockchain. CREATE2 is also the function that's being exploited by attackers to drain tokens from victims' wallets. One of its key capabilities is being able to deploy smart contracts to pre-determined addresses, making the entire process more predictable for the blockchain when dealing with multiple contract interactions across the ecosystem of decentralized applications. By pre-determined, it means that an attacker can create temporary, single-use addresses to receive a victim's assets. New addresses can be used for each attack, and this is crucial because wallet security providers rely on previously held data to flag potentially malicious transactions. If the address has no dodgy history, it's likely the transaction will evade these detections. The fact that attackers can set up a contract before deploying it (before it even exists), using a wallet address that doesn't have a history of malicious activity, means that if t...

Read full article

Affected Software

1 affected component
Ethereum CREATE2

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the increasing number of attacks on cryptocurrency wallets and urges providers to enhance their security measures.

2

What security implications are discussed?

The article highlights that criminals are draining millions from crypto wallets, indicating a significant security risk to users.

3

What products or software are affected?

The affected software mentioned in the article is Ethereum's CREATE2, which is being exploited in these attacks.

4

Who is calling for improved security in cryptocurrency wallets?

Infosec researchers, specifically from Check Point, are calling for enhanced security measures among crypto wallet providers.

5

What trend in cryptocurrency attacks is highlighted?

The article cites a rise in attacks that leverage vulnerabilities in Ethereum's CREATE2 feature.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203