If I Had a Million Cryptos: Cryptowallet Application Analysis and a Trojan Proof-of-Concept

Détails

ID Serval
serval:BIB_143C1ADA1869
Type
Actes de conférence (partie): contribution originale à la littérature scientifique, publiée à l'occasion de conférences scientifiques, dans un ouvrage de compte-rendu (proceedings), ou dans l'édition spéciale d'un journal reconnu (conference proceedings).
Collection
Publications
Titre
If I Had a Million Cryptos: Cryptowallet Application Analysis and a Trojan Proof-of-Concept
Titre de la conférence
Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
Auteur⸱e⸱s
Haigh Trevor, Breitinger Frank, Baggili Ibrahim
Editeur
Springer International Publishing
Adresse
Cham
ISBN
9783030054861
9783030054878
ISSN
1867-8211
1867-822X
Statut éditorial
Publié
Date de publication
2019
Editeur⸱rice scientifique
Breitinger Frank, Baggili Ibrahim
Pages
45-65
Langue
anglais
Résumé
Cryptocurrencies have gained wide adoption by enthusiasts and investors. In this work, we examine seven different Android cryptowallet applications for forensic artifacts, but we also assess their security against tampering and reverse engineering. Some of the biggest benefits of cryptocurrency is its security and relative anonymity. For this reason it is vital that wallet applications share the same properties. Our work, however, indicates that this is not the case. Five of the seven applications we tested do not implement basic security measures against reverse engineering. Three of the applications stored sensitive information, like wallet private keys, insecurely and one was able to be decrypted with some effort. One of the applications did not require root access to retrieve the data. We were also able to implement a proof-of-concept trojan which exemplifies how a malicious actor may exploit the lack of security in these applications and exfiltrate user data and cryptocurrency.
Mots-clé
Cryptowallet, Cryptocurrency, Bitcoin, Coinbase, Android
Création de la notice
06/05/2021 12:01
Dernière modification de la notice
06/05/2021 12:17
Données d'usage