Executive brief
The Dfinity agent-js library is used to manage cryptographic identities and access canisters (smart contracts) on the Internet Computer blockchain. A recent code change broke the secure random key generation feature in the Ed25519KeyIdentity.generate function, causing it to use a predictable seed instead of random bytes when no seed is explicitly provided. An attacker who discovers this can potentially steal funds from accounts or take control of canisters protected by these weak keys.
Technical details
The vulnerability is a cryptographic key generation weakness (CWE-330, CWE-321) in the Ed25519KeyIdentity.generate function. When the function is called without a seed parameter, it should generate a cryptographically secure random 32-byte seed; however, a recent code change broke the conditional logic and caused the function to use a hardcoded or otherwise insecure seed instead. This affects versions 0.20.0-beta.0 through 1.0.0 of both @dfinity/identity and @dfinity/auth-client packages. An attacker with network access can use the predictable key material to forge identities and gain unauthorized access to canisters or accounts. The vulnerability has been patched in version 1.0.1 and users should immediately upgrade. No active exploitation in the wild has been reported.
Affected products
- Dfinity agent-js >=0.20.0-beta.0, <1.0.1
- Dfinity identity >=0.20.0-beta.0, <1.0.1
- Dfinity auth-client >=0.20.0-beta.0, <1.0.1
Timeline
- 2024-02-21: disclosed
- 2024-02-21: patched: Version 1.0.1 released with fix