Always verify the randomness of your wallet mnemonic generator.

In a recent situation a bunch of wallets generated using bx, that, under the hood, uses a unsafe Mersenne Twister pseudorandom number generator (PRNG) initialized with 32 bits of system time.

With a gamer computer and some hints on wallet creation time you can brute force the wallet creation time to deterministically generate the wallet mnemonic and money is gone....

More information here: https://milksad.info/

Mitigation strategies: use dices to generate your seed offline, and NOT those "airgap" linux computers...

Reply to this note

Please Login to reply.

Discussion

No replies yet.