now after BitcoinEXpress (BCX) claimed he could take down Monero and it would have no future -
I have found very specific exploits in CN that have not been fixed that would be successful on XMR. Most are what I call annoyance attacks, that would be fixed and the coin would probably survive, but one is a coin killer. In XMR there exist a flaw involving the keyrings that under the right conditions will allow an attacker to steal your wallets and hijack your addresses. To fix this, anonymity will need to be sacrificed. These exploits are why two top exchanges who have asked for my opinion have not added XMR.
- answers of some of the most respected individuals in cryptocurrency have
debunked his accusations and FUD spreading as a complete lie and 100% baseless (please note that jl777 is a scammer but because respected in the community I post his comment too)
Hahem am I the only one that think BCX's findings are worrisome?
Claiming to have something and providing evidence thereof are two different things.
If you have an exploit for a (genuine, not-scammy) FOSS project, not releasing it *at least* to the developers is unconscionable - you aren't hurting a corporation or a bunch of fat cats, you're hurting a small group of developers who work - unpaid - on a software development project for the presumed betterment of everyone. You're hurting altruists who are giving of themselves for little or no reward, but I guess there are people who are so ethically imbalanced that they don't even consider this.
At a minimum some technical details about it would be nice.
Are we affected of what ? He didn't say anything concrete. Atm it looks like classic FUD, because i can't see any other goal behind this post.
But still, it always possible to have flaws - with this post or without it, we should keep attention carefully.
yep, I think the same, I also find funny that the "coin killer" exploit harms Monero anonymity, sounds like the perfect FUD, either way I hope he will work with the dev team for a win win scenario, instead of more hate.
how it is possible for a locally encrypted wallet to be compromised is beyond me.
conveniently he says there is a workaround to this unlikely result that just happens to require losing the anonymity
however, it also seems unlikely that losing anonymity will solve any wallet stealing
without any specifics,
this is artful FUD, especially with the "under the right conditions" part
It might almost be possible to prove that a local wallet cannot be stolen externally via the blockchain unless the encryption of the wallet is cracked and that the wallet contents are somehow able to be transferred to the attacker! I can see the theoretical possibility of unspent funds being spent without the wallet, which is what happened to XCP. Still for someone to be making such claims, he is either the top cryptonote dev in the world or it is FUD
There isnt an API call that allows the transmission of your wallet is there? Without this and also the ability to crack the encryption of the wallet, this is not very convincing FUD to me. It has nice tech terms to scare non-tech peoples, but unless his "right conditions" includes a computer that is infected with a keylogger the claims seem quite impossible. I await to be corrected with some actual specifics on even the theoretical method of wallet stealing that is possible without an already compromised computer. In that case, all coins, bitcoin included, are victim to the same exploit.
I know of an exploit for USD (or any currency) that allows all your accounts to be drained under the right conditions.
James
TL;DR: There is no exploit, BCX has lied to dump the price and buy a position as a whale in Monero. What a low attempt and all credibility of the guy is lost now