Vulnerability Intelligence

Formal CVE and GitHub Security Advisories that affect wallet entropy, seed or private-key generation, or closely related libraries. Inclusion means the advisory is official and in scope — not that EntropyWatch re-tested the issue against a particular wallet.

63tracked advisories
2026-08-07newest disclosure
2026-08-19last ingest (succeeded)
56entropy-related
PublishedIDTitleAffectedSeverityClass
2026-08-07CVE-2026-71851crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chaincrypto-jscriticalentropyAdvisory →
2026-05-08CVE-2026-44714bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypassorg.bitcoinj:bitcoinj-corehighentropyAdvisory →
2026-04-23CVE-2026-41564CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking.highentropyAdvisory →
2026-04-14CVE-2025-69893A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor SafemediumbroaderAdvisory →
2026-03-27CVE-2026-33936python-ecdsa: Denial of Service via improper DER length validation in crafted private keysecdsaecdsamediumentropyAdvisory →
2026-03-23CVE-2026-4599Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntcriticalentropyAdvisory →
2026-01-08CVE-2025-14505Elliptic Uses a Cryptographic Primitive with a Risky ImplementationellipticmediumentropyAdvisory →
2025-02-12GHSA-vjh7-7g9h-fjfhElliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)ellipticcriticalentropyAdvisory →
2024-12-04CVE-2024-54134Modified package published to npm, containing malware that exfiltrates private key material@solana/web3.jshighentropyAdvisory →
2024-12-03GHSA-2mhj-xmf4-pr8mMalicious code in @solana/web3.js (npm)@solana/web3.jsunknownentropyAdvisory →
2024-10-21CVE-2024-48930secp256k1-node allows private key extraction over ECDHsecp256k1highentropyAdvisory →
2024-10-15CVE-2024-48948Valid ECDSA signatures erroneously rejected in EllipticellipticmediumentropyAdvisory →
2024-10-10CVE-2024-38365btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionalitygithub.com/btcsuite/btcdhighentropyAdvisory →
2024-10-10CVE-2024-48949Elliptic's verify function omits uniqueness validationellipticmediumentropyAdvisory →
2024-08-02CVE-2024-42459Elliptic's EDDSA missing signature length checkellipticmediumentropyAdvisory →
2024-08-02CVE-2024-42461Elliptic allows BER-encoded signaturesellipticmediumentropyAdvisory →
2024-08-02CVE-2024-42460Elliptic's ECDSA missing check for whether leading bit of r and s is zeroellipticmediumentropyAdvisory →
2024-05-05CVE-2024-34478btcd susceptible to consensus failuresgithub.com/btcsuite/btcdmediumentropyAdvisory →
2024-04-17CVE-2024-30253Handling untrusted input can result in a crash, leading to loss of availability / denial of service@solana/web3.jshighentropyAdvisory →
2024-04-15CVE-2024-31497In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signaturesmediumentropyAdvisory →
2024-02-21CVE-2024-1631Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be usecriticalentropyAdvisory →
2024-02-08CVE-2024-23660The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words fhighentropyAdvisory →
2024-01-22CVE-2024-23342Minerva timing attack on P-256 in python-ecdsaecdsaecdsahighentropyAdvisory →
2024-01-19CVE-2024-23688Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session.mediumentropyAdvisory →
2023-10-25CVE-2023-46233crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standardcrypto-jscriticalentropyAdvisory →
2023-08-09CVE-2023-39910The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue.highentropyAdvisory →
2023-06-12CVE-2020-36732crypto-js uses insecure random numberscrypto-jsmediumentropyAdvisory →
2023-06-09CVE-2023-34363An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle.mediumentropyAdvisory →
2023-04-27CVE-2023-31290Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in DecemediumentropyAdvisory →
2023-03-23CVE-2023-20107A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and CiscohighentropyAdvisory →
2022-11-07CVE-2022-44797btcd mishandles witness size checkinggithub.com/lightningnetwork/lndgithub.com/btcsuite/btcdcriticalentropyAdvisory →
2022-09-20CVE-2022-34746An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versiomediumentropyAdvisory →
2022-09-18CVE-2022-40769profanity through 1.60 has only four billion possible RNG initializations.highentropyAdvisory →
2022-06-29CVE-2022-32969MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fimediumbroaderAdvisory →
2022-03-08CVE-2022-26317A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29).mediumentropyAdvisory →
2022-03-01CVE-2021-36171The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predicthighentropyAdvisory →
2021-11-16CVE-2021-26322Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.highentropyAdvisory →
2021-02-02CVE-2020-28498Elliptic Uses a Broken or Risky Cryptographic AlgorithmellipticmediumentropyAdvisory →
2020-07-29CVE-2020-13822Signature Malleabillity in ellipticelliptichighentropyAdvisory →
2020-06-16CVE-2020-14199BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, pomediumbroaderAdvisory →
2020-01-02CVE-2019-14859Improper Verification of Cryptographic Signature in Pure-Python ECDSAecdsaecdsacriticalentropyAdvisory →
2019-12-11CVE-2019-14317wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces.mediumentropyAdvisory →
2019-11-02CVE-2019-18673On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found.mediumbroaderAdvisory →
2019-10-31CVE-2019-14356On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found.mediumbroaderAdvisory →
2019-10-08CVE-2019-14853ecdsa Denial of Service vulnerability in signature verification and signature malleabilityecdsaecdsahighentropyAdvisory →
2019-08-10CVE-2019-14354On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found.lowbroaderAdvisory →
2019-08-08CVE-2019-14353On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found.mediumbroaderAdvisory →
2019-07-16CVE-2019-13603An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5.mediumentropyAdvisory →
2019-05-03CVE-2019-1715A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and ChighentropyAdvisory →
2018-12-09CVE-2018-19983An issue was discovered on Sigma Design Z-Wave S0 through S2 devices.mediumentropyAdvisory →

Older advisories →

Data is republished from the NVD, the GitHub Advisory Database, and OSV. Inclusion means the advisory is formal and in scope, not that EntropyWatch independently re-tested the issue.