Buy Crypto

OneKey Wallet Flaw Exposes 120K Bitcoin Keys to Hackers

Date:

Share post:

OneKey Wallet Vulnerability Affects Bitcoin Private Keys

OneKey, a cryptocurrency self-custody wallet, revealed a security flaw affecting up to 120,000 Bitcoin private keys. The issue comes from the Libbitcoin Explorer (bx) 3.x library. Several wallets used this library to generate private keys. The flaw was found after the Milk Sad incident. It exposes wallets to brute-force attacks due to a weak random-number algorithm.

OneKey’s report states the problem is linked to bx’s use of the Mersenne Twister-32 algorithm. This algorithm generated random numbers using only the system time as a seed. This limited randomness to 2³² possible values. Attackers could predict wallet keys by testing all seeds within days.

OneKey confirmed on X that the vulnerability does not affect the mnemonic or private key security of any OneKey hardware or software wallet.

OneKey’s Security Testing and Recommendations

OneKey tested its mnemonic generation on macOS, Windows, Android, and iOS. All platforms use cryptographically secure random number generators. These generators meet NIST SP 800-22 and FIPS 140-2 standards. The browser version uses Chrome’s built-in security tool for randomness. Android and iOS apps rely on secure systems within each phone’s operating system.

Each OneKey hardware wallet has a dedicated chip that generates random numbers inside the device. This reduces tampering risks. Older models also use secure systems that meet global standards. OneKey advises users not to transfer recovery phrases from software wallets to hardware wallets. Weaker randomness in software wallets could make private keys easier to guess.

Malware Hidden in Blockchain Smart Contracts

Security experts from Cisco Talos and Google discovered a North Korean hacking group called Famous Chollima hiding malware in blockchain smart contracts. The group uses a method called “EtherHiding” to embed harmful code. They mainly target job seekers with fake interviews to steal crypto and personal data.

This case highlights the importance of true randomness when creating wallet keys. Hardware wallets that generate keys internally make it harder for hackers to guess them.

Marcel
Marcelhttps://cryptonewspub.com/
Marcel is the enthusiastic owner and editor-in-chief of CryptoNewsPub, the go-to source for the latest news, sharp analyses, and groundbreaking insights into the world of cryptocurrency and blockchain. With his passion for decentralization and innovation, he makes complex developments clear and accessible to both novice crypto enthusiasts and seasoned traders. Marcel’s articles inspire, inform, and empower you to embrace the digital financial revolution with confidence.

Related articles

Dolomite Integrates Chainlink CCIP to Boost DeFi Security

Dolomite Partners with Chainlink to Enhance DeFi Platform Dolomite, a Decentralized Finance (DeFi) platform, is integrating Chainlink’s Cross-Chain Interoperability...

Bitwise Launches Solana Staking ETF with Strong $69M Inflow

Bitwise Launches Solana Staking ETF in the U.S. The Bitwise Solana Staking ETF (BSOL) debuted this week on U.S....

Gauntlet Launches USDC Prime Vault on Optimism for Safe DeFi

Gauntlet Launches USDC Prime Vault on Optimism Mainnet Gauntlet, a platform specializing in risk management for decentralized finance (DeFi),...

Ethereum Price Forecast ETH Tests 100 Day EMA as Fusaka Launches on Hoodi Testnet

Ethereum Fusaka Upgrade Launches on Hoodi Testnet The Ethereum Fusaka upgrade went live on the Hoodi testnet without issues....