Other
" Disclosure of Security Vulnerabilities in Atomic Wallet, Audited by Least Authority"
Primary Source ↗Incident Details
Atomic Wallet is a cryptocurrency wallet that claims to have more than 3 million downloads and advertises that “we provide users with the exceptional safety of their funds”. However, an April 2021 audit by the Least Authority security firm “found that the design and implementation of the Atomic Wallet system does not sufficiently demonstrate considerations for security and places current users of the wallet at significant risk.” When the Atomic Wallet team returned to the auditing firm in November to show them they’d addressed the issues, Least Authority found that “a significant number of issues and suggestions remain unresolved and that the implementation in its current state continues to be a security risk for users”. After the Atomic Wallet team continued to ignore issues raised by the Least Authority team, the security researchers took the last-ditch step of publicly disclosing that there are serious issues with the platform, and recommending that the software not be used. The researchers did not disclose the specific issues they had found, in hopes of avoiding malicious actors exploiting the outstanding bugs.
Technical Details
- Initial Attack Vector
- Software bug / unintentional loss
- Vendor / Product
- Atomic Wallet vulnerabilities
Timeline
- 2022-02-10 Breach occurred
- 2022-02-10 Publicly disclosed