Bitcoin SV has a serious security vulnerability in its multi-signature addresses that allows the loss of its users' stored funds.

Well-known developer and co-founder of Blockstream, Gregory Maxwell, posted on his Reddit account the results from an investigation he conducted on the Wallets multi-signature from Bitcoin SV, which details how various bugs and security vulnerabilities are allowing users to lose their funds. Maxwell, who on Reddit shows himself as the user u/nullc, points out that the bifurcation of the cryptocurrency Bitcoin SV (BSV) from Bitcoin Cash (BCH), caused several of the technical characteristics of Bitcoin (BTC) y Bitcoin Cash (BCH) be destroyed, which is currently causing serious security flaws and the possible loss of user funds. 

“Bitcoin SV (BSV) forked from Bitcoin Cash (BCH)… In doing so, it destroyed some of Bitcoin’s key features; now, it’s worse.”

As the developer explains, Bitcoin SV multi-signature contracts no longer guarantee security for its users, and are currently causing the loss of all BSV tokens. Likewise, Maxwell also points out that, so far, the funds of real users have not been affected by the discovered critical bug, except for Shou who reported the loss of 600 BSV. 

It may interest you: Windows, iOS, Samsung and Google products hacked in Chinese Tianfu Cup competition

The origin of the problem

Apparently, when Bitcoin SV forked from Bitcoin Cash, the cryptocurrency developers removed the feature P2SH (Pay to Script Hash), a special type of address for Bitcoin transactions that allows multi-signatures, from the BSV source code, and replaced it with a «pirated and weak version» call «multisig accumulator» which uses addresses with a format similar to those P2PKH (Pay to Public Key Hash). In addition, Maxwell points out that when making these changes, the developers used a number of signatures «less than or equal to» instead of «greater than or equal to», which resulted in the current exploit.

“It seems to me that greater than or less than equal was used instead of less than or equal for their final comparison, probably due to the author's confusion about the order of the elements in the stack.” 

The result is that these scripts do not have good security, so the funds can be easily spent by a script with a smaller number of valid signatures. According to Maxwell, the developers did not perform proper testing, nor did they verify that their product works with enough signatures, as intended. 

Lack of basic evidence

Maxwell's assessment is that; The developers only tested whether multisig transactions would work with the number of signatures required to send the transactions, not with a larger or smaller number of signatures.. Thus, the critical error causes spending on a transaction to fail if more than the minimum required number of signatures are used, and also allows theft of funds if fewer, or even none, signatures are used. 

The developer also claims that if basic tests and checks had been carried out, the problem would have been fixed from the start. Maxwell claims that this critical error may be an accidental failure and not something intentional or premeditated by the developers. 

Safety recommendations

First of all, Maxwell points out that users should be aware and be sufficiently safe when using custom scripts, since these types of “custom cryptographic protocols” must be designed with the same care as any of the other existing and known cryptographic protocols, and that users should be aware in order to avoid falling victim to “obvious scams” ​​or vulnerabilities that risk the security of their funds. 

On the other hand, the developers of Electrum SV, the wallet used by Aaron Zhou, posted a warning to users on their Twitter account, stressing that they should not change the script type of their wallets, and in particular, not change to “accumulator multisig”, as this may result in the loss of all funds. 

600 BSV lost due to this exploit

Roger taylor, developer of Electrum VS, published a article where it is reported that a user lost a large amount of BSV tokens, due to the change of the script type of his multi-signature wallet to the "accumulator multisig" script, which resulted in the theft of which Aaron Zhou was a victim, with which lost 600 BSV in an attack that exploited this weakness. 

Taylor reports that the “multisig accumulator” feature is currently disabled by default in Electrum SV version 1.3.7. Finally, the developers remind us of the importance of security when implementing or improving code. In the case of Bitcoin SV, the changes made to the cryptocurrency’s code were made to allow for fast transactions, criticizing the “slow and conservative” development of Bitcoin. Now, unfortunately, many can see that fast development does not necessarily mean security; many times serious mistakes like this can be made, sacrificing security for speed. 

Continue reading: User loses 1.400 BTC stored in an Electrum wallet during phishing attack