Close Menu
  • Home
  • News
  • Business
  • Bitcoin
  • Ethereum
  • Eurozone
  • Monero
  • Markets
  • Technology
What's Hot

Today's Stock Market: Live Update

May 15, 2025

Wealthy millennials spend thousands on their monthly subscriptions for Jaguar Land Rover, as flexibility becomes the latest luxury

May 15, 2025

Ethereum Foundation launches “1 trillion dollar security” plan

May 15, 2025
Facebook X (Twitter) Instagram
  • Home
  • About World of Tech News
  • Advertise With Us
  • Contact us
  • DMCA (Digital Millennium Copyright Act) Notice
  • Privacy Policy
  • Terms of Use
Facebook X (Twitter) Instagram
DecenTralized Rebel
  • Home
  • News

    Ethereum Foundation launches “1 trillion dollar security” plan

    May 15, 2025

    “We have a big balance sheet.”

    May 15, 2025

    French minister to meet the crypto company after a violent inviting attempt in Paris

    May 14, 2025

    S&P 500, tariff relief boosts tech stock while the Dow slips

    May 14, 2025

    XRP takes a real step into defi with flare facet upgrades

    May 14, 2025
  • Business

    Wealthy millennials spend thousands on their monthly subscriptions for Jaguar Land Rover, as flexibility becomes the latest luxury

    May 15, 2025

    Qatar orders up to 210 Boeing Jets during Trump Visit

    May 14, 2025

    The last mall in Europe? Hamburg marks the end of the era as Westfield turns to Saudi Arabia for the next retail boom

    May 14, 2025

    Thames water executives receive bonuses from £3 billion emergency loans

    May 13, 2025

    Stripe billionaire Collison Brothers says he will solve the “two-body problems” faced by remote working couples

    May 13, 2025
  • Bitcoin

    Japan's “Micro Strategy” Metaplanet Post Record Quarterly Number, currently owning over $700 million in Bitcoin

    May 14, 2025

    21 capital has secured $459 million in Bitcoin

    May 14, 2025

    XRP is seeing updated trader activity as the market absorbs sales pressure

    May 14, 2025

    As Binance CEO says BTC “Reading Pack”, Bitcoin shruggs from our CPI victory

    May 13, 2025

    When Bitcoin Holdings rises to 2,011 BTC, Exodus records Q1 revenue

    May 12, 2025
  • Ethereum

    The Ethereum Foundation aims to secure the future with its trillion dollar security initiative

    May 14, 2025

    Trillion Dollar Security Initiative Announcement

    May 14, 2025

    Despite increasing market efficiency, crypto liquidity lags behind traditional finance – S&P Global

    May 13, 2025

    Ethereum surpasses Bitcoin in a surprise rally above $2,500

    May 12, 2025

    BlackRock meets the SEC Crypto Task Force to discuss tokenization and ETP rules

    May 9, 2025
  • Eurozone

    AI Bias by Design: What the Claude Prompt Leak Reveals for Investment Professionals

    May 14, 2025

    How to modify the course when you simply can't stay on the course

    May 12, 2025

    How client investment goals reflect risk behavior and hidden bias

    May 12, 2025

    US Money Reserve – How Gold's recent series of record highs are compared to past runs, according to the Investment Watch Blog

    May 11, 2025

    In the midst of noise, active management quietly reinvents itself

    May 7, 2025
  • Monero

    Standard chartered bank signing partnership with Digital Asset Broker Falconx

    May 14, 2025

    These five cryptography numbers have wiped out, died, or fooled us all.

    May 14, 2025

    Jack Mullers' 21 capitals and Tether bought 4,812 bitcoin for $458,700,000

    May 13, 2025

    Vaneck launched its first RWA tokenization fund

    May 13, 2025

    Coinbase will become the first bitcoin and crypto company to join the S&P 500

    May 12, 2025
  • Markets

    Today's Stock Market: Live Update

    May 15, 2025

    Today's Stock Market: Live Update

    May 14, 2025

    Can Britons fill the labor gap caused by immigration crackdowns?

    May 14, 2025

    Trump speaks after $600 billion in Saudi Arabia investment is announced

    May 13, 2025

    Investment Bank lifts China's growth outlook after a surprise trade agreement with us

    May 13, 2025
  • Technology

    Luminar billionaire founder followed ethical research on behalf of CEO

    May 14, 2025

    Violent threats to US judges are surged online

    May 14, 2025

    Join TechCrunch Session: AI with this new limited time discount

    May 13, 2025

    The VPN company has cancelled all lifetime subscriptions and claims they didn't know about them

    May 13, 2025

    The latest startup in up.labs-porsche wants to be car retail plaid

    May 13, 2025
DecenTralized Rebel
Home » Can Apple chips be exploited to steal cryptocurrencies?Here's what you need to know
News

Can Apple chips be exploited to steal cryptocurrencies?Here's what you need to know

adminBy adminMarch 26, 2024No Comments6 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Apple Mac computers and iPad tablets may be affected by a serious vulnerability that could expose encryption keys and passwords on certain devices.

A flaw in Apple's M-series chips could be exploited by hackers to steal cryptographic keys, such as those that protect cryptocurrency wallets, through malware attacks, according to researchers from various universities.

And while the risk of an actual exploit may be low, it's not negligible if you're holding large amounts of cryptocurrency in potentially vulnerable software wallets on your Mac. We will briefly discuss the situation based on what has been reported and disclosed so far.

What is the problem?

researcher announced last week They discovered a critical vulnerability within Apple's M-series chips used in Macs and iPads. This vulnerability could allow an attacker to access cryptographically secure keys and code.

The problem comes down to a technology called “prefetch,” which speeds up interactions with devices through Apple's own M-series chips. The device aims to speed up interactions by monitoring the most common activities and keeping data at hand using prefetch functionality. However, it appears that the technique could be misused.

Researchers say it is possible to create an app that successfully “tricks” a processor into caching some of the prefetched data, which the app can access and use to reconstruct encryption keys. ing. That's a potentially big problem.

Who is at risk?

If your Mac or iPad is equipped with an Apple M-series processor (M1, M2, or M3), your device may be affected by this vulnerability. The M1 processor arrived in MacBook Air, MacBook Pro, and Mac Mini in late 2020, and has since expanded to Mac desktops and iPad tablets.

M2 processors and current M3 processors are also susceptible across computers and tablets, with the M2 chip apple vision pro headset. However, on the M3 chip, the data memory-dependent prefetchers affected by this vulnerability “have a special bit that developers can call to disable this functionality.” ars technica There is some performance impact as a result, but it has been reported.

What if I have an older Mac or iPad?

If you have an older Mac with an Intel processor that Apple used for years before developing its own silicon, you're good to go. Intel chips are not affected.

Similarly, if you have an iPad (old or new) that uses one of Apple's A-series chips, which are also found in Apple's iPhones, there appears to be no risk. Only M1, M2, and M3 chips are vulnerable by design. Apple's A14, A15, and A16 chips found in recent iPhones and iPads are indeed variants of the M-series chips, but as of this writing, research reports and media reports do not suggest they are vulnerable. Not mentioned.

What can we do about it?

what can be done you What do you do to fix the problem? Unfortunately nothing. This is a chip-level vulnerability that involves the proprietary architecture of Apple's chips. That means it's not something Apple can fix with a patch. What app developers can do is implement fixes that avoid this vulnerability, but this comes with an obvious performance trade-off, so such apps may feel even slower when updated. there is.

What you can do to remove the risk, of course, is to remove any cryptocurrency wallets you own from vulnerable Apple devices. Move to another device, such as a Windows PC, iPhone, or Android phone. Don't wait for catastrophe to happen.

Errata Security CEO Robert Graham is just that. Said zero day Writer Kim Zetter tells readers: Remove your cryptocurrency wallet from your device, at least for now. “There are people who are trying to do this right now. [attack] And I think I'm working on that,” he told the blog.

Can my cryptocurrency be stolen?

Devices with M1-M3 chips do have vulnerabilities, but hackers can't always flip a switch and steal your funds. Typically, malware needs to be installed on the device, and then the attacker needs to use exploited software to obtain the private keys and access the associated wallets.

Apple's macOS too Highly resistant to malware, because you have to manually allow such apps to be installed on your device. Macs block unsigned third-party software by default. Still, if you're the adventurous type and are installing apps from “unknown” developers, you should take precautions if you're using a potentially vulnerable M-chip device .

According to , this type of attack can also be performed on a shared cloud server that holds the keys, so this is also a potential attack vector. zero day. It is also possible to perform this type of attack on a website through JavaScript code. This is much more effective at impacting the average user and does not require the user to install anything. But that's only theoretical for now.

According to Zero Day, the vulnerability could also be used to decrypt the contents of web browser cookies, giving an attacker access to things like email accounts and allowing users to access sensitive accounts. You may be able to log in.

What about hardware wallets?

Current reporting on this vulnerability indicates that hardware wallets such as Ledger and Trezor are not at risk, as the private key must be on an Apple device with an M1-M3 chip to be affected. It seems that. That said, it's probably not a bad idea to avoid connecting your hardware wallet to vulnerable devices, just in case.

What about centralized exchanges?

Centralized exchanges like Coinbase store your funds in custodial wallets and do not have your private keys on your device, so they are not directly at risk. However, if you have saved her Coinbase account password in a cryptographically secure password manager on a vulnerable Apple device, you can change the password or do not have Please update within the manager. A cane to keep you from falling.

Additionally, as mentioned above, an attacker could theoretically use this vulnerability to decipher account passwords from browser cookies.

How serious is this really?

While there is no doubt that this is a serious vulnerability, it seems highly unlikely to affect the average cryptocurrency user. Depending on the type of encryption that is broken by this vulnerability, it can take as little as about an hour to gradually retrieve enough data from the cache to reconstruct the key, or as long as he It may take up to 10 hours.

That doesn't mean it's impossible or that it can't happen to you, but it's not a quick-fix drive-by attack. You should take precautions to avoid exposure, but if the reports are accurate, we don't believe this poses a widespread threat to the average user.

Edited by Guillermo Jimenez



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Ethereum Foundation launches “1 trillion dollar security” plan

May 15, 2025

“We have a big balance sheet.”

May 15, 2025

French minister to meet the crypto company after a violent inviting attempt in Paris

May 14, 2025

S&P 500, tariff relief boosts tech stock while the Dow slips

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Bitcoin

Japan's “Micro Strategy” Metaplanet Post Record Quarterly Number, currently owning over $700 million in Bitcoin

May 14, 2025

21 capital has secured $459 million in Bitcoin

May 14, 2025

XRP is seeing updated trader activity as the market absorbs sales pressure

May 14, 2025

As Binance CEO says BTC “Reading Pack”, Bitcoin shruggs from our CPI victory

May 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Welcome to World of Tech News, your premier source for comprehensive and up-to-date information about Bitcoin, cryptocurrencies, blockchain technology, and the exciting world of digital assets. We are dedicated to providing insightful content, news, analysis, and resources to keep you informed and engaged in the rapidly evolving crypto space.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

The Ethereum Foundation aims to secure the future with its trillion dollar security initiative

May 14, 2025

Trillion Dollar Security Initiative Announcement

May 14, 2025

Despite increasing market efficiency, crypto liquidity lags behind traditional finance – S&P Global

May 13, 2025
Get Informed

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About World of Tech News
  • Advertise With Us
  • Contact us
  • DMCA (Digital Millennium Copyright Act) Notice
  • Privacy Policy
  • Terms of Use
© 2025 decentralizedrebel. Designed by decentralizedrebel.

Type above and press Enter to search. Press Esc to cancel.