Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Senate Clears 10-Day FISA Stopgap After House Revolt Sinks Longer Deal

April 19, 2026

SEC removes huge pattern day trader barrier to allow retail investors to day trade Bitcoin with just $2k margin

April 19, 2026

Cregis Shines at Paris Blockchain Week 2026, Accelerating European Expansion

April 19, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Wallets and Exchanges»Newly discovered Bitcoin wallet loophole let hackers steal $900K — SlowMist
Wallets and Exchanges

Newly discovered Bitcoin wallet loophole let hackers steal $900K — SlowMist

August 10, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A newly discovered vulnerability in the Libbitcoin Explorer 3.x library has allowed over $900,000 to be stolen from Bitcoin users, according to a report from blockchain security firm SlowMist. The vulnerability can also affect users of Ethereum, Ripple, Dogecoin, Solana, Litecoin, Bitcoin Cash and Zcash who use Libbitcoin to generate accounts.

SlowMist Security Alert

Recently, #Distrust discovered a severe vulnerability affecting cryptocurrency wallets using the #Libbitcoin Explorer 3.x versions. This vulnerability allows attackers to access wallet private keys by exploiting the Mersenne Twister pseudo-random…

— SlowMist (@SlowMist_Team) August 10, 2023

Libbitcoin is a Bitcoin wallet implementation that developers and validators sometimes use to create Bitcoin (BTC) and other cryptocurrency accounts. According to its official website, it is used by “Airbitz (mobile wallet), Bitprim (developer interface), Blockchain Commons (decentralized wallet identity), Cancoin (decentralized exchange)” and other applications. SlowMist did not specify which applications that use Libbitcoin, if any, are affected by the vulnerability.

SlowMist identified cybersecurity team “Distrust” as the team that originally discovered the loophole, which is called the “Milk Sad” vulnerability. It was reported to the CEV cybersecurity vulnerability database on Aug. 7.

According to the post, the Libbitcoin Explorer has a faulty key generation mechanism, allowing private keys to be guessed by attackers. As a result, attackers exploited this vulnerability to steal over $900,000 worth of crypto as of Aug. 10.

SlowMist emphasized that one attack in particular siphoned away over 9.7441 BTC (approximately $278,318). The firm claims to have “blocked” the address, implying that the team has contacted exchanges to prevent the attacker from cashing out the funds. The team also stated that it will be monitoring the address in case funds are moved elsewhere.

See also  U.S. Congressman Demands Hostage Status For Binance Exec Imprisoned In Nigeria

Four members of the Distrust team, along with eight freelance security consultants who claim to have helped discover the vulnerability, have set up an informational website explaining the vulnerability. They explained that the loophole is created when users employ the “bx seed” command to generate a wallet seed. This command “uses the Mersenne Twister pseudorandom number generator (PRNG) initialized with 32 bits of system time,” which lacks sufficient randomness and therefore sometimes produces the same seed for multiple persons.

Bx seed command producing the same seed twice. Source: Milk Sad information site

The researchers claim to have discovered the vulnerability when they were contacted by a Libbitcoin user whose BTC had mysteriously gone missing on July 21. When the user reached out to other Libbitcoin users to try to determine how the BTC could have gone missing, the person found that other users were also having their BTC siphoned away.

Cointelegraph reached out to Libbitcoin Institute member Eric Voskuil for comment. In response, Voskuil stated that the bx seed command “is provided as a convenience for when the tool is used to demonstrate behavior that requires entropy” and is not intended to be used in production wallets. “If people did in fact use it for production key seeding (as opposed to rolling dice for example) then the warning is insufficient,” Voskuil stated. In that case, “We’ll likely make some change within the next few days to strengthen the warning against production use, or remove the command altogether.”

Wallet vulnerabilities continue to pose a problem for crypto users in 2023. Over $100 million was lost in a hack of the Atomic Wallet in June, which was acknowledged by the app’s team on June 22. Cybersecurity certification platform CER released its wallet security rankings in July, noting that only six out of 45 wallet brands employ penetration testing to discover vulnerabilities.

See also  Degen Crypto Exchange To Wind Down Global Operations Permanently 

Update (Aug. 10 20:51 UTC): This article has been updated to include a comment from Eric Voskuil.

Source link

900k Bitcoin Discovered Hackers loophole newly SlowMist Steal wallet
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

SEC removes huge pattern day trader barrier to allow retail investors to day trade Bitcoin with just $2k margin

April 19, 2026

Bitcoin mining difficulty falls, but projected to rise in next adjustment

April 19, 2026

Bitcoin miners pivot to AI is now an immediate risk to network security – but BTC revenue will still eclipse AI by over $4B

April 19, 2026

Can Bitcoin Buyers Join The Breakout Party? Analyst Says Not Yet

April 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Sam Bankman-Fried Rebuffed Barry Silbert's and Celsius' Requests for Help, Ex-FTX CEO Testifies at His Trial

October 27, 2023

Interest in Avalanche NFTs rise, but what about AVAX?

January 25, 2024

Partnership With SK Telecom Fails To Halt MATIC Slide

August 17, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Senate Clears 10-Day FISA Stopgap After House Revolt Sinks Longer Deal

April 19, 2026

SEC removes huge pattern day trader barrier to allow retail investors to day trade Bitcoin with just $2k margin

April 19, 2026

Cregis Shines at Paris Blockchain Week 2026, Accelerating European Expansion

April 19, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$76,022.00-0.20%
  • ethereumEthereum(ETH)$2,337.08-1.09%
  • tetherTether(USDT)$1.000.02%
  • rippleXRP(XRP)$1.440.02%
  • binancecoinBNB(BNB)$626.70-1.03%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$86.45-0.37%
  • tronTRON(TRX)$0.3333061.06%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.30%
  • dogecoinDogecoin(DOGE)$0.095210-1.10%