PT-2023-23277 · Unknown · Trust Wallet Browser Extension+1

Jean-Baptiste Bédrune

·

Publicado

2023-04-27

·

Atualizado

2025-12-31

·

CVE-2023-31290

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trust Wallet Core versions prior to 3.1.1 Trust Wallet browser extension versions 0.0.172 through 0.0.182
Description The issue allows theft of funds due to insufficient entropy, which is 32 bits. This is because the mt19937 Mersenne Twister uses a single 32-bit value as an input seed, resulting in only four billion possible mnemonics. The issue has been exploited in the wild in December 2022 and March 2023. An attacker can efficiently steal funds by identifying Ethereum addresses created since the 0.0.172 release and checking if they could have been created by the affected extension.
Recommendations For Trust Wallet Core versions prior to 3.1.1, upgrade the product version and move funds to a new wallet address. For Trust Wallet browser extension versions 0.0.172 through 0.0.182, upgrade the product version and move funds to a new wallet address.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-31290

Produtos afetados

Trust Wallet Core
Trust Wallet Browser Extension