Share this article

Researchers Find Flaws in Security Protocols Developed by Major Crypto Exchanges

Private key protocols for some crypto exchanges have been implemented with bugs that could have been exploited by a well-placed malicious party, researchers say.

Updated May 9, 2023, 3:10 a.m. Published Aug 10, 2020, 3:39 p.m.
(Shutterstock)
(Shutterstock)

Cryptocurrency exchanges holding user funds have risked falling into numerous security pitfalls by failing to ensure security protocols are properly implemented, according to new research.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

  • Speaking to Wired for an article Sunday, Jean-Philippe Aumasson, the co-founder exchange security firm Taurus Group, said he and his team, along with Omer Shlomovits from crypto wallet maker ZenGo, had uncovered three significant vulnerabilities in the way some custodial exchanges hold user funds.
  • While private crypto wallets usually have just one private key for the holder, exchanges go a step further and split keys up into different components – a distributed key scheme – so no one entity has complete control over the main wallet.
  • That generally improves security but, as Taurus Group found, the new attack vectors stemmed from splitting private keys up partly because they assumed key holders, entities responsible for part of the key, would not be malicious.
  • Some vectors come from the refresh function that enhances privacy by replacing key components so a third party can't slowly work out a full private key.
  • In one example, from open-source software from an exchange the researchers refused to identify, a malicious key holder could change, or threaten to change, part of the component so the full private key is lost – preventing the exchange from accessing funds again.
  • Arguably the biggest vulnerability came from a key-generation protocol from Binance where the key holder pretended to be the protocol itself, assigning other key holders the random values they need to verify their identity.
  • Armed with that information, a hacker could compromise the system from the moment it was set up, giving them access to the rest of the private key and allowing them to drain wallet funds.
  • Binance fixed the problem in March and said it recommends users go through the key-generation procedure only if they are concerned one of the holders could be malicious.
  • Both Aumasson and Shlomovits said the research highlighted just how easy it was for vulnerabilities to appear in ostensibly secure mechanisms.

See also: Crypto Firm Hacked for $1.4M Admits It Will Struggle to Reimburse Users

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

French Banking Giant BPCE to Roll Out Crypto Trading for 2M Retail Clients

(CoinDesk)

The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq.

What to know:

  • French banking group BPCE will start offering crypto trading services to 2 million retail customers through its Banque Populaire and Caisse d’Épargne apps, with plans to expand to 12 million customers by 2026.
  • The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq, with a €2.99 monthly fee and 1.5% transaction commission.
  • The move follows similar initiatives by other European banks, such as BBVA, Santander, and Raiffeisen Bank, which have already started offering crypto trading services to their customers.