Fireblocks’ cryptography research team has disclosed that it discovered a cluster of zero‑day vulnerabilities in implementations of multi‑party computation (MPC) wallet protocols used across the digital asset industry. In a coordinated disclosure campaign, the company privately notified 16 affected wallet providers and open‑source projects and worked with them to develop and deploy patches before publicly detailing the issues. To reduce the risk of exploitation during the remediation window, Fireblocks and some media coverage have avoided naming all affected vendors, only confirming that its own MPC wallets are not impacted. The flaws, collectively referred to as BitForge, stem from incorrect or incomplete implementations of MPC protocols such as GG‑18, GG‑20 and Lindell17, including missing zero‑knowledge proofs and deviations from published academic specifications. In the worst cases, an attacker with privileged or man‑in‑the‑middle access could silently extract private keys and fully drain wallets, in some implementations in as few as 16 signing operations. Following a roughly 90‑day responsible disclosure period, major providers that were publicly identified in earlier reporting — including Coinbase WaaS, Zengo and Binance’s TSS library — have shipped fixes, and no user fund losses have been reported. The incident underscores how subtle cryptographic implementation bugs in MPC wallets can create systemic risk across multiple services and has prompted calls for more rigorous protocol adherence, formal verification, and independent security review of wallet infrastructure.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

Loading related coverage…

Comments

Loading comments…