[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

OneKey responds to the Milk Sad incident, confirming that the vulnerability does not affect the security of its software and hardware wallets

Oct 17, 2025 22:27:58

Share to

ChainCatcher news, according to OneKey's Chinese Twitter, regarding the recent "Milk Sad incident" involving a random number vulnerability, the OneKey team clarifies that this vulnerability does not affect the security of the mnemonic phrases and private keys of OneKey's software and hardware wallets.

The vulnerability originates from the Libbitcoin Explorer (bx) version 3.x, which uses a pseudo-random number generator based on system time and the Mersenne Twister-32 algorithm, with a seed space of only 2³² bits. Attackers can derive private keys through prediction or brute force. The affected range includes some older versions of Trust Wallet and all products using bx 3.x or older versions of Trust Wallet Core. OneKey states that its hardware wallets use EAL6+ secure chips with built-in TRNG true random number generators; older devices also pass SP800-22 and FIPS140-2 entropy tests; the software wallet uses system-level CSPRNG entropy sources to generate random numbers, meeting cryptographic standards. The team emphasizes that users are advised to manage assets using hardware wallets and should not import mnemonic phrases generated by software wallets into hardware wallets to ensure the highest level of security.

Related Projects

Latest News

Data: BTC falls below 68,000 USD

ChainCatcher

Mar 23, 2026 05:05:13

Data: BTC falls below 69,000 USD

ChainCatcher

Mar 22, 2026 07:52:30

Data: BTC falls below 70,000 USD

ChainCatcher

Mar 22, 2026 07:46:53

Data: BTC breaks through 71,000 USD

ChainCatcher

Mar 21, 2026 22:12:38

Data: BTC breaks through 71,000 USD

ChainCatcher

Mar 20, 2026 16:07:24

Recent Fundraising

More
$5M Mar 16

New Tokens

More

Latest Updates on 𝕏

More