PANews reported on October 17 that according to OneKey’s Chinese Twitter account, regarding the random number vulnerability involved in the recent “Milk Sad incident,” the OneKey team clarified that the vulnerability does not affect the security of the mnemonics and private keys of OneKey’s software and hardware wallets. The vulnerability stems from Libbitcoin Explorer (bx) 3.x, which uses a pseudo-random number generator based on the system time and the Mersenne Twister-32 algorithm. With a seed space of only 2³² bits, attackers can predict or brute-force the private key. This vulnerability affects some older versions of Trust Wallet and all products using bx 3.x or older versions of Trust Wallet Core. OneKey stated that its hardware wallet utilizes an EAL6+ security chip with a built-in TRNG true random number generator; older devices have also passed SP800-22 and FIPS140-2 entropy testing; while its software wallet utilizes a system-level CSPRNG entropy source to generate random numbers, complying with cryptographic standards. The team emphasized that users are advised to use hardware wallets to manage their assets and not import mnemonics generated by software wallets into hardware wallets to ensure maximum security.PANews reported on October 17 that according to OneKey’s Chinese Twitter account, regarding the random number vulnerability involved in the recent “Milk Sad incident,” the OneKey team clarified that the vulnerability does not affect the security of the mnemonics and private keys of OneKey’s software and hardware wallets. The vulnerability stems from Libbitcoin Explorer (bx) 3.x, which uses a pseudo-random number generator based on the system time and the Mersenne Twister-32 algorithm. With a seed space of only 2³² bits, attackers can predict or brute-force the private key. This vulnerability affects some older versions of Trust Wallet and all products using bx 3.x or older versions of Trust Wallet Core. OneKey stated that its hardware wallet utilizes an EAL6+ security chip with a built-in TRNG true random number generator; older devices have also passed SP800-22 and FIPS140-2 entropy testing; while its software wallet utilizes a system-level CSPRNG entropy source to generate random numbers, complying with cryptographic standards. The team emphasized that users are advised to use hardware wallets to manage their assets and not import mnemonics generated by software wallets into hardware wallets to ensure maximum security.

OneKey responds to the Milk Sad incident: Confirmed vulnerability does not affect the security of its software and hardware wallets

2025/10/17 22:27
1분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

PANews reported on October 17 that according to OneKey’s Chinese Twitter account, regarding the random number vulnerability involved in the recent “Milk Sad incident,” the OneKey team clarified that the vulnerability does not affect the security of the mnemonics and private keys of OneKey’s software and hardware wallets.

The vulnerability stems from Libbitcoin Explorer (bx) 3.x, which uses a pseudo-random number generator based on the system time and the Mersenne Twister-32 algorithm. With a seed space of only 2³² bits, attackers can predict or brute-force the private key. This vulnerability affects some older versions of Trust Wallet and all products using bx 3.x or older versions of Trust Wallet Core.

OneKey stated that its hardware wallet utilizes an EAL6+ security chip with a built-in TRNG true random number generator; older devices have also passed SP800-22 and FIPS140-2 entropy testing; while its software wallet utilizes a system-level CSPRNG entropy source to generate random numbers, complying with cryptographic standards. The team emphasized that users are advised to use hardware wallets to manage their assets and not import mnemonics generated by software wallets into hardware wallets to ensure maximum security.

시장 기회
Notcoin 로고
Notcoin 가격(NOT)
$0.0003924
$0.0003924$0.0003924
-4.87%
USD
Notcoin (NOT) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!