January 25, 2026

Capitalizations Index – B ∞/21M

McAfee’s Unhackable Bitfi Wallet Hacked Again, Security Researchers Await Bounty

Mcafee’s unhackable bitfi wallet hacked again, security researchers await bounty

McAfee’s Unhackable Bitfi Wallet Hacked Again, Security Researchers Await Bounty


John mcafee
Advertisement

On the home page of hardware wallet Bitfi’s website, it is hard to miss these words attributed to the company’s chairman, John McAfee: “The world’s first un-hackable storage for cryptocurrency & digital assets.”

Mcafee’s unhackable bitfi wallet hacked again, security researchers await bounty

But for the umpteenth time, the security of the hardware wallet has been severely compromised. In the most recent incident according to Hard Fork, security researchers at Pen Test Partners were able to send signed transactions using Bitfi thereby fulfilling a vital requirement for the hardware wallet’s bounty program.

“Well, that’s a transaction made with a MitMed Bitfi, with the phrase and seed being sent to a remote machine,” Andrew Tierney, a security consultant at Pen Test Partners, wrote on Twitter. “That sounds a lot like Bounty 2 to me.”

Three Conditions

Compared to Bitfi’s initial bounty which was offering a prize of US$250,000 the second bounty was relatively meager at only US$10,000. To claim the second bounty the rules include among others modifying the hardware wallet’s firmware and then connecting to the Bitfi dashboard. The final condition to be met involves ensuring that the secret phrase of the user or their private keys are transmitted to a third party while ensuring that the Bitfi dashboard continues functioning normally.

Per Tierney, the team was able to significantly modify the firmware and consequently intercept communications between the hardware device and the wallet. And to prove that the device was still connected to the dashboard and working perfectly the researchers displayed messages on the screen.

Team Effort

According to Tierney, hacking the hardware wallet involved teamwork with various individuals and entities making varying contributions.

As CCN recently reported, the device was rooted (gaining administrator or privileged access) at the beginning of this month by an information security expert who subsequently found a suite of apps that included GPS and Wi-Fi trackers. This was viewed as a serious security issue since the tracking apps were discovered to be connecting to various web services include the Chinese online search giant Baidu.

Less than ten days later 15-year old Saleem Rashid, a hacking prodigy, was able to install Doom gaming application on the device and play it. This raised concerns that by having weak or non-existent tamper protections, malicious actors could easily install malware leaving it vulnerable to manipulation. Additionally, there were concerns that with root access the device could be easily reprogrammed.

Bitfi’s response to the whole saga resulted in a series of missteps and bad publicity. As a result, the firm recently won the Pwnie Award for the Lamest Vendor Response during the BlackHat USA conference that was held in Las Vegas, Nevada.

Featured image from Flickr/NullSession.

Follow us on Telegram or subscribe to our newsletter here.
Join CCN’s crypto community for $9.99 per month, click here.
Want exclusive analysis and crypto insights from Hacked.com? Click here.
Open Positions at CCN: Full Time and Part Time Journalists Wanted.

Advertisement


Published at Tue, 14 Aug 2018 13:22:40 +0000

bitcoin Wallets

Previous Article

Charles Hoskinson Discussing Cardano, ETC, ZenCash and the Cryptocurrency Industry as Whole!

Next Article

Kleerup with Lykke Li – Until we bleed (HQ)

You might be interested in …

The Crypto Show: Terry Brock BrockOnBlockchains & Danny's Cannabis Adventure

On tonight’s episode of “The Crypto Show” we interview internationally renowned speaker, author, and liberty and cryptocurrency advocate Terry Brock.

We discuss Terry’s background and how he became a speaker and liberty lover and how people can more effectively spread the message of liberty by using simple techniques that recognize and accommodate human psychology. Terry gives us his opinion on the future of bitcoin and the block-size issue as well as his opinion on Dash, Ethereum, and other altcoins. Terry also updates us on his new educational website brockonblockchain.com.

Danny is still in San Francisco due to auto issues, but it has given him the opportunity to attend NCIA Cannabis Business Summit & Expo. Where 200+ companies are represented, and Danny has made many connections to promote Dash and bitcoin adoption. He should be on the road again tomorrow after he attends the last day of the conference. He will be attending the Red Pill Conference next week.

Sponsored by: Dash, CryptoCompare Bitmain and Defense Distributed

Links

https://www.amazon.com/dp/1119365597/ref=cm_sw_r_sms_c_api_IQPczbQHWJKP8

TheCryptoShow

FreeRoss

Social Media

The Crypto Show on Facebook

@TheCryptoShow

@The_Crypto_Show

@the_crypto_show instagram

The Crypto Show YouTube

Tip with Crypto

BTC: 139R6K7fxTYaFf2aXTid84Le1ayqMVvSCq

Dash: XqDeHnokQocBpvffsa2dWz8mX7oTKpoKzc

LTC: LUTJtk4QqXLiDkK8pDKK3jM73VVwbp7oSr

Doge: DQBJ7PSpFzUTwpBrny46Kug4BW8AGtq1YQ

LTBC: 1CevFxMT6srBtTkWx2qrNaJmjtgxbo7pBA