Using weak seed phrases means instant loss of funds on the Bitcoin network.

The concept of a blockchain "dark forest" has been popularized recently by Ethereum and the existence of front-running bots that will copy any profitable transaction pending for submission.

The bots are able to assess if any given transaction that just entered the mempool can be replicated, and they will immediately publish their own copy with a much higher gas fee, which virtually guarantees that they will be the first to claim it. The term "dark forest" is inspired from a sci-fi novel and indicates a place where detection means instant death — or in this case loss of funds.

In Ethereum, this usually happens with public smart contracts that for some reason came in control of funds. Dan Robinson from Paradigm Capital demonstrated one such case with money mistakenly sent to a contract address. These types of bots also threw a wrench into Bancor’s vulnerability mitigation plan in June.

Bitcoin (BTC) does not have smart contracts to front-run, but a post by BitMEX Research highlights how a similar event occurs when one uses brainwallets.

A brainwallet is the term for a private key that is only stored as a memory in a person’s brain, meaning that no physical backups exist. This approach is generally discouraged because relying on a person's memory to store a complex alphanumeric string is not ideal.

A potential solution to this is creating a wallet from an easy to remember phrase. This is what the analysts did by generating a seed phrase from extracts of famous literary works, including the Bitcoin whitepaper.

Unfortunately, in some cases the BTC put into these wallets was swept away even before the transaction to fund them was confirmed. This was the case with simple seed words like “Call me Ishmael” from Herman Melville’s Moby Dick. Other longer and more complex excerpts were still swept within a day, with the Bitcoin whitepaper’s “The network is robust in its unstructured simplicity” lasting the longest.

The analysts concluded that addresses generated from these types of complex, but public-domain seed words are fully compromised and are constantly being monitored.

As Cointelegraph reported earlier, blockchain makes it hard to use any type of password-based generation mechanism. Passwords on traditional platforms are mostly protected by the fact that they’re stored on a secret database. The attackers must interact with it to make guesses, but the server will usually issue rate limit denials. Furthermore, having to make a web request to make a guess is already many times slower than hashing through locally-stored combinations.

Blockchain private keys can instead be pre-generated from massive dictionary databases, making attackers the effective owners of those addresses. There are ways to mitigate these vulnerabilities by using salt — random bits of data added to throw off brute force attempts. But the fundamental issue of brainwallets is that any address that is sufficiently resistant to brute forcing will likely be difficult to remember reliably.

There are many stories of people losing their BTC by forgetting a private key they stored in their brain, with one notable loss of $13 million reported in 2019 — though some believe it was fake. Ethereum is likely subjected to the same type of private key brute forcing, with millions of dollars in Ether (ETH) being reportedly stolen in the past.


Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers.

Join Telegram

Recommended content


Recommended Content

Editors’ Picks

Celebrity meme coins controversy continues amid Pump.fun revenue dominance

Celebrity meme coins controversy continues amid Pump.fun revenue dominance

Pump.fun outperformed the Ethereum blockchain on Tuesday after raking in $1.99 million. Following this achievement, a meme coin based on actress Sydney Sweeney was the subject of controversy after its developers dumped their bags on investors.

More Meme Coins News

PEPE's on-chain metrics indicate potential rally after weeks of silence

PEPE's on-chain metrics indicate potential rally after weeks of silence

PEPE has struggled to see any significant price move after reaching an all-time high in May. Increased adoption rate and low MVRV ratio indicate a bullish run may be on the horizon. A single PEPE outflow from Binance worth $14.7 million gives credence to signs of bullish expectation.

More Pepe News

Ethereum has failed to overcome key resistance despite bullish sentiment surrounding ETH ETF

Ethereum has failed to overcome key resistance despite bullish sentiment surrounding ETH ETF

Ethereum (ETH) is down more than 1.4% on Tuesday following another ETH sale from the Ethereum Foundation. Meanwhile, crypto exchange Gemini's recent report reveals that ETH ETF could see about $5 billion in net inflows within six months of launch.

More Ethereum News

Crypto community blasts Polkadot following report of treasury spending

Crypto community blasts Polkadot following report of treasury spending

Polkadot reports $87 million of treasury spending during H1. Crypto community members expressed harsh feelings toward the DOT team's high spending. DOT is up more than 2% in the past 24 hours but risks correction following the report.

More Polkadot News

Bitcoin: BTC price correction could end in July, according to seasonal data

Bitcoin: BTC price correction could end in July, according to seasonal data

Bitcoin (BTC) price appears poised for a decline this week, influenced by slight outflows in US spot ETFs, selling activity among BTC miners, and a combined transfer of 4,690.28 BTC to centralized exchanges by the US and German governments.

Read full analysis

BTC

ETH

XRP