• bitcoinBitcoin (BTC) $ 106,835.00
  • ethereumEthereum (ETH) $ 3,887.19
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,097.33
  • xrpXRP (XRP) $ 2.36
  • solanaSolana (SOL) $ 185.93
  • usd-coinUSDC (USDC) $ 0.999900
  • staked-etherLido Staked Ether (STETH) $ 3,885.54
  • tronTRON (TRX) $ 0.314328
  • dogecoinDogecoin (DOGE) $ 0.189160
  • cardanoCardano (ADA) $ 0.635226
  • wrapped-stethWrapped stETH (WSTETH) $ 4,729.12
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,194.47
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,886.00
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.01
  • ethena-usdeEthena USDe (USDE) $ 0.999460
  • chainlinkChainlink (LINK) $ 16.84
  • wrapped-eethWrapped eETH (WEETH) $ 4,202.52
  • stellarStellar (XLM) $ 0.316957
  • hyperliquidHyperliquid (HYPE) $ 36.14
  • bitcoin-cashBitcoin Cash (BCH) $ 465.63
  • suiSui (SUI) $ 2.49
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • wethWETH (WETH) $ 3,889.20
  • leo-tokenLEO Token (LEO) $ 9.40
  • avalanche-2Avalanche (AVAX) $ 20.11
  • usdsUSDS (USDS) $ 1.00
  • usdt0USDT0 (USDT0) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 106,856.00
  • litecoinLitecoin (LTC) $ 91.77
  • hedera-hashgraphHedera (HBAR) $ 0.165173
  • whitebitWhiteBIT Coin (WBT) $ 40.96
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • moneroMonero (XMR) $ 309.06
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • the-open-networkToncoin (TON) $ 2.14
  • mantleMantle (MNT) $ 1.61
  • crypto-com-chainCronos (CRO) $ 0.144049
  • daiDai (DAI) $ 0.998875
  • polkadotPolkadot (DOT) $ 2.93
  • bittensorBittensor (TAO) $ 393.04
  • uniswapUniswap (UNI) $ 6.03
  • zcashZcash (ZEC) $ 219.83
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.129765
  • okbOKB (OKB) $ 168.29
  • ethenaEthena (ENA) $ 0.468835
  • memecoreMemeCore (M) $ 1.93
  • aaveAave (AAVE) $ 213.30
  • bitget-tokenBitget Token (BGB) $ 4.64
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pepePepe (PEPE) $ 0.000007
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 229.94
  • susdssUSDS (SUSDS) $ 1.07
  • c1usdCurrency One USD (C1USD) $ 1.00
  • aster-2Aster (ASTER) $ 1.18
  • ethereum-classicEthereum Classic (ETC) $ 15.40
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,888.86
  • aptosAptos (APT) $ 3.21
  • ondo-financeOndo (ONDO) $ 0.711203
  • falcon-financeFalcon USD (USDF) $ 0.993712
  • chainopera-aiChainOpera AI (COAI) $ 11.25
  • tether-goldTether Gold (XAUT) $ 4,260.41
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.36
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.188193
  • worldcoin-wldWorldcoin (WLD) $ 0.889611
  • gatechain-tokenGate (GT) $ 15.85
  • htx-daoHTX DAO (HTX) $ 0.000002
  • usdtbUSDtb (USDTB) $ 0.999854
  • hash-2Provenance Blockchain (HASH) $ 0.036030
  • kucoin-sharesKuCoin (KCS) $ 13.79
  • story-2Story (IP) $ 5.50
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,452.46
  • binance-staked-solBinance Staked SOL (BNSOL) $ 200.25
  • arbitrumArbitrum (ARB) $ 0.308695
  • bfusdBFUSD (BFUSD) $ 0.999981
  • pi-networkPi Network (PI) $ 0.203641
  • internet-computerInternet Computer (ICP) $ 3.05
  • algorandAlgorand (ALGO) $ 0.179725
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,104.85
  • cosmosCosmos Hub (ATOM) $ 3.18
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,104.48
  • vechainVeChain (VET) $ 0.017096
  • wbnbWrapped BNB (WBNB) $ 1,098.52
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,178.77
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 36.11
  • skySky (SKY) $ 0.058913
  • pump-funPump.fun (PUMP) $ 0.003872
  • pax-goldPAX Gold (PAXG) $ 4,261.16
  • kaspaKaspa (KAS) $ 0.050259
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.021313
  • flare-networksFlare (FLR) $ 0.017534
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 106,751.00
  • render-tokenRender (RENDER) $ 2.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,125.55
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • sei-networkSei (SEI) $ 0.191677
  • official-trumpOfficial Trump (TRUMP) $ 5.89
  • nexoNEXO (NEXO) $ 1.17
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999859
  • bonkBonk (BONK) $ 0.000014
  • jupiter-exchange-solanaJupiter (JUP) $ 0.341414
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 106,432.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.060285
  • filecoinFilecoin (FIL) $ 1.49
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997726
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.87
  • morphoMorpho (MORPHO) $ 1.86
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,189.30
  • immutable-xImmutable (IMX) $ 0.496097
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 212.80
  • global-dollarGlobal Dollar (USDG) $ 0.999997
  • spx6900SPX6900 (SPX) $ 0.952621
  • fasttokenFasttoken (FTN) $ 2.02
  • ripple-usdRipple USD (RLUSD) $ 0.999939
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 106,998.00
  • injective-protocolInjective (INJ) $ 8.45
  • clbtcclBTC (CLBTC) $ 106,759.00
  • celestiaCelestia (TIA) $ 1.00
  • doublezeroDoubleZero (2Z) $ 0.229978
  • ousgOUSG (OUSG) $ 112.98
  • lido-daoLido DAO (LDO) $ 0.873697
  • msolMarinade Staked SOL (MSOL) $ 247.77
  • rna-2RNA (SN117) $ 4,708.96
  • blockstackStacks (STX) $ 0.422273
  • optimismOptimism (OP) $ 0.424886
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,733.36
  • curve-dao-tokenCurve DAO (CRV) $ 0.526085
  • plasmaPlasma (XPL) $ 0.412567
  • aerodrome-financeAerodrome Finance (AERO) $ 0.778903
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,889.65
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998774
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.86
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.260232
  • the-graphThe Graph (GRT) $ 0.062584
  • sonic-3Sonic (S) $ 0.173037
  • pyth-networkPyth Network (PYTH) $ 0.111176
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,888.89
  • flokiFLOKI (FLOKI) $ 0.000065
  • tbtctBTC (TBTC) $ 106,590.00
  • tezosTezos (XTZ) $ 0.587169
  • kaiaKaia (KAIA) $ 0.103128
  • ether-fiEther.fi (ETHFI) $ 1.07
  • gtethGTETH (GTETH) $ 3,889.10
  • stader-ethxStader ETHx (ETHX) $ 4,167.06
  • usdaiUSDai (USDAI) $ 1.03
  • beldexBeldex (BDX) $ 0.078700
  • newton-projectAB (AB) $ 0.007115
  • saros-financeSaros (SAROS) $ 0.221724
  • iotaIOTA (IOTA) $ 0.139635
  • conflux-tokenConflux (CFX) $ 0.109787
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.34
  • usual-usdUsual USD (USD0) $ 0.998160
  • pendlePendle (PENDLE) $ 3.23
  • theta-tokenTheta Network (THETA) $ 0.544191
  • myx-financeMYX Finance (MYX) $ 2.85
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,273.48
  • dashDash (DASH) $ 43.09
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999919
  • swethSwell Ethereum (SWETH) $ 4,278.00
  • dogwifcoindogwifhat (WIF) $ 0.517444
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.26
  • galaGALA (GALA) $ 0.010914
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 106,945.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.757921
  • the-sandboxThe Sandbox (SAND) $ 0.202941
  • true-usdTrueUSD (TUSD) $ 0.996863
  • bittorrentBitTorrent (BTT) $ 0.00000050
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999902
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.189058
  • jasmycoinJasmyCoin (JASMY) $ 0.009971
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.70
  • swissborgSwissBorg (BORG) $ 0.485050
  • raydiumRaydium (RAY) $ 1.77
  • havvenSynthetix (SNX) $ 1.37
  • starknetStarknet (STRK) $ 0.109287
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,185.89
  • usddUSDD (USDD) $ 1.00
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,191.23
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,884.65
  • vaultaVaulta (A) $ 0.285283
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,161.24
  • sun-tokenSun Token (SUN) $ 0.022960
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.13
  • zoraZora (ZORA) $ 0.097625
  • bitcoin-svBitcoin SV (BSV) $ 21.88
  • decentralandDecentraland (MANA) $ 0.227167
  • flowFlow (FLOW) $ 0.268929
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,885.34
  • jito-governance-tokenJito (JTO) $ 1.08
  • frax-etherFrax Ether (FRXETH) $ 3,858.93
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • syrupMaple Finance (SYRUP) $ 0.370250
  • apenftAPENFT (NFT) $ 0.00000041
  • aethirAethir (ATH) $ 0.028243

Over 120,000 Bitcoin private keys were exposed through a flaw in Libbitcoin Explorer’s random-number generator

0 2

Over 120,000 Bitcoin private keys were exposed through a flaw in Libbitcoin Explorer’s random-number generator

A newly uncovered vulnerability in a widely used open-source Bitcoin library has led to the exposure of more than 120,000 private keys, according to a report by crypto wallet provider OneKey.

The flaw was traced back to the Libbitcoin Explorer (bx) 3.x series, which allowed attackers to predict wallet private keys generated through insecure random number methods.

According to OneKey’s insight published on X late Friday, Libbitcoin Explorer (bx) 3.x is a command-line utility long used to create Bitcoin wallets offline. The software uses the Mersenne Twister-32 pseudo-random number generator (PRNG), which seeds randomness using only the system time.

The seed space was limited to 2³² possible values, which helped hackers easily predict the random numbers and brute-force wallet private keys. Anyone aware of when a wallet was generated could reconstruct the same sequence of random numbers and, in turn, derive the private key to access an address’s funds.

OneKey analysis on the extent of affected wallets

According to the crypto wallet service provider, the issue has been confirmed to affect several wallet implementations that integrated Libbitcoin Explorer or its dependent components, including Trust Wallet Extension versions 0.0.172 through 0.0.183, and Trust Wallet Core versions up to 3.1.1, bar the patched 3.1.1 release.

OneKey, citing an analysis by security researchers, discovered that the security flaw arose from the PRNG’s dependence on predictable entropy. Attackers could reproduce identical private keys for wallets generated at specific timestamps.

The small seed space and predictable nature of the Mersenne Twister-32 algorithm made it feasible for malicious actors to automate the process and compromise several wallets.

OneKey explained that the flaw may have contributed to previous mysterious fund losses in incidents like the “Milk Sad” case, where victims reported seeing their wallets drained, despite using air-gapped systems for security.

The ‘Milk Sad’ connection did not affect OneKey wallets

The Milk Sad investigation, which began earlier this year, revealed that victims had generated their wallets on air-gapped Linux laptops using commands in Libbitcoin Explorer. In each case, users relied on bx to produce their 24-word BIP39 mnemonic phrases in the belief that the tool made the randomness sufficient.

One command sequence used during wallet generation was bx seed -b 256 | bx mnemonic-new. It generated 256 bits of entropy, which were then converted into a 24-word mnemonic phrase. Due to the flawed random number generator, the supposedly secure mnemonics were in fact predictable.

Although the Milk Sad victims created their wallets years apart, investigators found each used the same version of Libbitcoin Explorer, which unknowingly generated weak private keys.

In its report, OneKey stated that the vulnerability in Libbitcoin Explorer does not compromise the security of mnemonic or private keys in its wallets. The company’s investigation confirmed that its devices and software use a cryptographically secure RNG that meets international security standards.

“All new-generation hardware wallets have Secure Elements (SE) with built-in True Random Number Generators (TRNGs) for key creation. The components are hardware-based and hold EAL6+ certification, levels of security that are recognized globally,” the hardware and cold wallet company confirmed.

Software wallet vulnerability assessment

OneKey also conducted an assessment of its software products, noting that the Desktop and Browser Extension versions utilize a Chromium-based WebAssembly (WASM) PRNG interface.

The interface operating system uses a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG) as the entropy source, which is the same standard used in modern browsers and secure software systems.

OneKey said its Android and iOS wallets have system-level CSPRNG APIs built into the operating systems themselves. The wallet service’s security team reiterated that the randomness quality in wallet generation directly depends on the integrity of the device and software environment.

“If the operating system, browser kernel, or device hardware is compromised, the entropy source could be weakened,” it wrote.

The firm has advised users to choose hardware wallets if they plan to store coins for the long term, to minimize the risk of exposure. It also warned them not to import mnemonic phrases generated by software wallets into hardware wallets.

Source

Leave A Reply

Your email address will not be published.