The post Over 120,000 Bitcoin private keys were exposed through a flaw in Libbitcoin Explorer’s random-number generator appeared on BitcoinEthereumNews.com. A newly uncovered vulnerability in a widely used open-source Bitcoin library has led to the exposure of more than 120,000 private keys, according to a report by crypto wallet provider OneKey. The flaw was traced back to the Libbitcoin Explorer (bx) 3.x series, which allowed attackers to predict wallet private keys generated through insecure random number methods. According to OneKey’s insight published on X late Friday, Libbitcoin Explorer (bx) 3.x is a command-line utility long used to create Bitcoin wallets offline. The software uses the Mersenne Twister-32 pseudo-random number generator (PRNG), which seeds randomness using only the system time.  The seed space was limited to 2³² possible values, which helped hackers easily predict the random numbers and brute-force wallet private keys. Anyone aware of when a wallet was generated could reconstruct the same sequence of random numbers and, in turn, derive the private key to access an address’s funds.  OneKey analysis on the extent of affected wallets According to the crypto wallet service provider, the issue has been confirmed to affect several wallet implementations that integrated Libbitcoin Explorer or its dependent components, including Trust Wallet Extension versions 0.0.172 through 0.0.183, and Trust Wallet Core versions up to 3.1.1, bar the patched 3.1.1 release. OneKey, citing an analysis by security researchers, discovered that the security flaw arose from the PRNG’s dependence on predictable entropy. Attackers could reproduce identical private keys for wallets generated at specific timestamps.  The small seed space and predictable nature of the Mersenne Twister-32 algorithm made it feasible for malicious actors to automate the process and compromise several wallets. OneKey explained that the flaw may have contributed to previous mysterious fund losses in incidents like the “Milk Sad” case, where victims reported seeing their wallets drained, despite using air-gapped systems for security. The ‘Milk Sad’ connection did not affect OneKey wallets… The post Over 120,000 Bitcoin private keys were exposed through a flaw in Libbitcoin Explorer’s random-number generator appeared on BitcoinEthereumNews.com. A newly uncovered vulnerability in a widely used open-source Bitcoin library has led to the exposure of more than 120,000 private keys, according to a report by crypto wallet provider OneKey. The flaw was traced back to the Libbitcoin Explorer (bx) 3.x series, which allowed attackers to predict wallet private keys generated through insecure random number methods. According to OneKey’s insight published on X late Friday, Libbitcoin Explorer (bx) 3.x is a command-line utility long used to create Bitcoin wallets offline. The software uses the Mersenne Twister-32 pseudo-random number generator (PRNG), which seeds randomness using only the system time.  The seed space was limited to 2³² possible values, which helped hackers easily predict the random numbers and brute-force wallet private keys. Anyone aware of when a wallet was generated could reconstruct the same sequence of random numbers and, in turn, derive the private key to access an address’s funds.  OneKey analysis on the extent of affected wallets According to the crypto wallet service provider, the issue has been confirmed to affect several wallet implementations that integrated Libbitcoin Explorer or its dependent components, including Trust Wallet Extension versions 0.0.172 through 0.0.183, and Trust Wallet Core versions up to 3.1.1, bar the patched 3.1.1 release. OneKey, citing an analysis by security researchers, discovered that the security flaw arose from the PRNG’s dependence on predictable entropy. Attackers could reproduce identical private keys for wallets generated at specific timestamps.  The small seed space and predictable nature of the Mersenne Twister-32 algorithm made it feasible for malicious actors to automate the process and compromise several wallets. OneKey explained that the flaw may have contributed to previous mysterious fund losses in incidents like the “Milk Sad” case, where victims reported seeing their wallets drained, despite using air-gapped systems for security. The ‘Milk Sad’ connection did not affect OneKey wallets…

Over 120,000 Bitcoin private keys were exposed through a flaw in Libbitcoin Explorer’s random-number generator

A newly uncovered vulnerability in a widely used open-source Bitcoin library has led to the exposure of more than 120,000 private keys, according to a report by crypto wallet provider OneKey.

The flaw was traced back to the Libbitcoin Explorer (bx) 3.x series, which allowed attackers to predict wallet private keys generated through insecure random number methods.

According to OneKey’s insight published on X late Friday, Libbitcoin Explorer (bx) 3.x is a command-line utility long used to create Bitcoin wallets offline. The software uses the Mersenne Twister-32 pseudo-random number generator (PRNG), which seeds randomness using only the system time. 

The seed space was limited to 2³² possible values, which helped hackers easily predict the random numbers and brute-force wallet private keys. Anyone aware of when a wallet was generated could reconstruct the same sequence of random numbers and, in turn, derive the private key to access an address’s funds. 

OneKey analysis on the extent of affected wallets

According to the crypto wallet service provider, the issue has been confirmed to affect several wallet implementations that integrated Libbitcoin Explorer or its dependent components, including Trust Wallet Extension versions 0.0.172 through 0.0.183, and Trust Wallet Core versions up to 3.1.1, bar the patched 3.1.1 release.

OneKey, citing an analysis by security researchers, discovered that the security flaw arose from the PRNG’s dependence on predictable entropy. Attackers could reproduce identical private keys for wallets generated at specific timestamps. 

The small seed space and predictable nature of the Mersenne Twister-32 algorithm made it feasible for malicious actors to automate the process and compromise several wallets.

OneKey explained that the flaw may have contributed to previous mysterious fund losses in incidents like the “Milk Sad” case, where victims reported seeing their wallets drained, despite using air-gapped systems for security.

The ‘Milk Sad’ connection did not affect OneKey wallets

The Milk Sad investigation, which began earlier this year, revealed that victims had generated their wallets on air-gapped Linux laptops using commands in Libbitcoin Explorer. In each case, users relied on bx to produce their 24-word BIP39 mnemonic phrases in the belief that the tool made the randomness sufficient.

One command sequence used during wallet generation was bx seed -b 256 | bx mnemonic-new. It generated 256 bits of entropy, which were then converted into a 24-word mnemonic phrase. Due to the flawed random number generator, the supposedly secure mnemonics were in fact predictable.

Although the Milk Sad victims created their wallets years apart, investigators found each used the same version of Libbitcoin Explorer, which unknowingly generated weak private keys.

In its report, OneKey stated that the vulnerability in Libbitcoin Explorer does not compromise the security of mnemonic or private keys in its wallets. The company’s investigation confirmed that its devices and software use a cryptographically secure RNG that meets international security standards.

“All new-generation hardware wallets have Secure Elements (SE) with built-in True Random Number Generators (TRNGs) for key creation. The components are hardware-based and hold EAL6+ certification, levels of security that are recognized globally,” the hardware and cold wallet company confirmed.

Software wallet vulnerability assessment

OneKey also conducted an assessment of its software products, noting that the Desktop and Browser Extension versions utilize a Chromium-based WebAssembly (WASM) PRNG interface. 

The interface operating system uses a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG) as the entropy source, which is the same standard used in modern browsers and secure software systems.

OneKey said its Android and iOS wallets have system-level CSPRNG APIs built into the operating systems themselves. The wallet service’s security team reiterated that the randomness quality in wallet generation directly depends on the integrity of the device and software environment. 

“If the operating system, browser kernel, or device hardware is compromised, the entropy source could be weakened,” it wrote.

The firm has advised users to choose hardware wallets if they plan to store coins for the long term, to minimize the risk of exposure. It also warned them not to import mnemonic phrases generated by software wallets into hardware wallets. 

If you’re reading this, you’re already ahead. Stay there with our newsletter.

Source: https://www.cryptopolitan.com/120k-bitcoin-private-keys-cracked-in-a-new-hack/

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date

Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date

The post Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date appeared on BitcoinEthereumNews.com. Jonah Wren Phillips in “Bring Her Back.” A24 Bring Her Back, a new A24 horror movie from the filmmakers of the smash hit Talk to Me, is coming soon to HBO Max. Bring Her Back opened in theaters on May 30 before debuting on digital streaming via premium video on demand on July 1. The official logline for Bring Her Back reads, “A brother and sister uncover a terrifying ritual at the secluded home of their new foster mother.” Forbes‘South Park’ Season 27 Updated Release Schedule: When Do New Episodes Come Out?By Tim Lammers Directed by twin brothers Danny Philippou and Michael Philippou, Bring Her Back stars Billy Barratt, Sora Wong, Jonah Wren Philips, Sally–Anne Upton, Stephen Philips, Mischa Heywood and Sally Hawkins. Warner Bros. Discovery announced on Wednesday that Bring Her Back will arrive on streaming on HBO Max on Friday, Oct. 3, and on HBO linear on Saturday, Oct. 4, at 8 p.m. ET. Prior to the debut of Bring Her Back on HBO on Oct. 4, the cable outlet will air the Philippou brothers’ 2022 horror hit Talk to Me. ForbesHit Horror Thriller ’28 Years Later’ Is New On Netflix This WeekBy Tim Lammers For viewers who don’t have HBO Max, the streaming platform offers three tiers: The ad-based tier costs $9.99 per month, while an ad-free tier is $16.99 per month. Additionally, an ad-free tier with 4K Ultra HD programming costs $20.99 per month. The Success Of ‘Talk To Me’ Weighed On The Minds Of Philippou Brothers While Making ‘Bring Her Back’ During the film’s theatrical run, Bring Her Back earned $19.3 million domestically and nearly $19.8 million internationally for a worldwide box office tally of $39.1 million. Bring Her Back had a production budget of $17 million before prints and advertising, according to The Numbers.…
Share
BitcoinEthereumNews2025/09/18 09:23
XRP Hits ‘Extreme Fear’ Levels - Why This Is Secretly Bullish

XRP Hits ‘Extreme Fear’ Levels - Why This Is Secretly Bullish

Ripple’s native token XRP is still battling out with the bears at the $1.90 territory on Friday afternoon. The support-turned-resistance at $1.90 is particularly
Share
Coinstats2026/01/24 03:25
Is Hyperliquid the new frontier for innovation?

Is Hyperliquid the new frontier for innovation?

The post Is Hyperliquid the new frontier for innovation? appeared on BitcoinEthereumNews.com. This is a segment from the 0xResearch newsletter. To read full editions, subscribe. One of the key things I like to track in crypto is a subjective criterion I call “where are new interesting developments and proposals taking place.” There are plenty of dashboards and analytics sites for this, the most popular being the Electric Capital site. The issue is that it still shows Polkadot as having a lot of developers. (At Blockworks we solved the noise problem with active users; maybe we can try the same for active developers.) Because of this noise, I prefer to track two simple observations: What is the velocity of new products launching, and how much mindshare are these products capturing? Are many people getting nerdsniped into discussing the novelties and intricacies of the chain? A related point is the caliber of people being attracted to new ecosystems. For example, over the past few years, Solana (and Ethereum) attracted the majority of talent. Talent generally goes where: It can solve interesting problems or create interesting projects. It can make a lot of money. In a podcast I did with Icebergy about a year ago, we discussed how crypto still wasn’t attracting talent at the levels AI was, despite offering faster exits and more money. AI was (and probably still is) more interesting to most talent and seen as more prestigious. After FTX, crypto lost a lot of credibility and has only recently started recovering as larger institutional players re-entered. Apart from FTX, crypto has also been criticized for being full of low-effort forks and limited utility products. This dynamic isn’t unique to crypto though. Many AI companies are also just building wrappers around GPT, which is as uninteresting as some projects in crypto. Anyway, to the point: Historically, Solana has captured the majority of…
Share
BitcoinEthereumNews2025/09/18 08:13