08 Sep 2018

The unhackable Bitfi bounty

Bitfi is a company which claimed to be the world’s first unhackable crypto currency wallet.  It offered $250k to those able to conduct a successful attack which the specific scenario of “Somebody steals your device – Can they get your money or not?”

In a video, Saleem Rashid has shown how he sets a secret phrase and salt.  Afterward, he ran an exploit showing he was able to extract the keys from the device.  Andrew Tierney of Pen Test Partners, was able to verify the attack.   At that point, Bifi closed the bounty program.

Bill Powell, VP of Operations, then clarified that the wallet is only successfully attacked if the hacker gets the coins.

Saleem “Unhackable” Rashid aka @spudowiar has recently stated “Bill Powell of @Bitfi6 discussing the single assumption upon which the entirety of @Bitfi6's ridiculous UNHACKABLE claim lies could you even IMAGINE if this assumption was proved false?”

]]>