Multiple reports and research references describe Bitcoin wallet compromise scenarios in which weak, reused, or low-entropy ECDSA nonces allow attackers to recover private keys from public signatures. Several sources tie the risk to the so-called Phantom Curve and Dark Skippy attack patterns, claiming that malicious firmware or flawed random-number generation in hardware and software wallets can leak enough signing material for key recovery after as few as two transactions. Related writeups also connect the issue to broader entropy failures, including alleged hardware-wallet weaknesses such as CVE-2025-27840, and to historical examples like the PlayStation 3 signing flaw, Android OpenSSL wallet compromises, and weak web-wallet RNG implementations.
The references also promote tools such as KeySilentLeak and other blockchain-scanning projects that purportedly analyze Bitcoin signatures for nonce bias, reuse, or reduced entropy and then apply methods including Pollard’s Kangaroo, lattice techniques, and other discrete-logarithm attacks to reconstruct wallet secrets. While some claims are framed as demonstrations involving specific Bitcoin addresses and recovered funds, the underlying security concern matches established cryptographic research showing that biased or repeated nonces can expose keys at scale from passive blockchain analysis. Recommended mitigations across the sources include adopting RFC 6979 deterministic nonce generation, auditing PRNG and entropy sources, enforcing secure boot and firmware verification on hardware wallets, and hardening devices against nonce exfiltration and other signing-side attacks.

Track how attackers are adapting to this technology.
18 events from the most recent confirmed update back to the earliest known activity.
Cryptou published an article explaining that reusing the same ECDSA nonce across two Bitcoin signatures allows algebraic recovery of the nonce and then the private key, resulting in full wallet compromise.
A Cryptou article published research describing KeySilentLeak, a framework for identifying weak Bitcoin signatures and recovering wallet keys from nonce reuse or low-entropy nonce generation. It also referenced the 2024 Dark Skippy hardware-wallet attack concept and a case study involving address 1MikxkAoAQWGBsh6pzsaiHdXAktzzj6Rnt.
Polynonce published an article describing KeySilentLeak as a research cryptanalysis tool for exploiting ECDSA nonce weaknesses such as nonce reuse, predictable nonces, and low-entropy randomness to recover Bitcoin private keys. The article also referenced historical weak-wallet cases including the Milk Sad issue in Libbitcoin Explorer 3.x.
AttackSafe published an analysis of the Dark Skippy attack as a hardware-wallet-focused exploitation of weak ECDSA nonces, claiming two signed transactions can leak enough seed entropy for recovery using Pollard’s Kangaroo. It also described KeySilentLeak and a worked example involving address 1MikxkAoAQWGBsh6pzsaiHdXAktzzj6Rnt.
A GitHub repository under CryptoDeepTools titled "50PhantomCurveAttack" was published, describing Dark Skippy-style low-entropy nonce exploitation and the KeySilentLeak tool for recovering Bitcoin private keys from weak signatures.
CryptoDeepTech published an article analyzing Dark Skippy-style low-entropy nonce attacks in hardware wallets and presenting the KeySilentLeak tool for detecting weak nonce patterns and recovering private keys. The article also described a case study involving Bitcoin address 1MikxkAoAQWGBsh6pzsaiHdXAktzzj6Rnt.
Key3 published an article alleging a "Spectral Fountain" attack in which predictable or weakly seeded PRNGs could make Bitcoin private keys and ECDSA nonces recoverable, and tied the risk to hardware wallets and an alleged entropy issue tracked as CVE-2025-27840. The article also cited claimed demonstrations by CryptoDeepTech involving wallet access recovery and blockchain validation.
Keyhunters published an article describing the "Phantom Curve Attack" as an ECDSA nonce-reuse weakness where two signatures with the same nonce or r value can expose a Bitcoin private key. The article linked the issue to weak RNGs, faulty implementations, and reported wallet-compromise claims.
Keyhunters published an article describing broad cryptocurrency risks from weak private-key generation, insufficient entropy, and flawed PRNG behavior, and tied these to alleged wallet compromises and a claimed wallet recovery holding 21.88992388 BTC. The article also referenced an alleged ESP32-related issue tracked as CVE-2025-27840.
Keyhunters published an article titled "Phantom Nonce," describing a fatal ECDSA vulnerability and private-key recovery threat for lost Bitcoin wallets. This marked public promotion of the nonce-related attack narrative.
B8C TECH published a page titled "BingSec256k1," indicating public release or disclosure of a secp256k1-related project relevant to Bitcoin cryptographic security research.
Polynonce published an article on incorrect private-key generation, systemic vulnerabilities, and secp256k1 order-calculation errors as threats to the Bitcoin ecosystem. This expanded public reporting on Bitcoin key-generation weaknesses.
A GitHub repository titled "Private-key-Debug" was published, covering incorrect private-key generation, system vulnerabilities, and secp256k1 order-calculation issues affecting Bitcoin security.
Keyhunters published an article focused on cryptographic vulnerabilities related to incorrect generation of Bitcoin private keys. The publication marks public discussion of systemic key-generation weaknesses affecting the Bitcoin ecosystem.
A YouTube video titled "How to Earn Cash with Math №2 Bitcoin Wallet Restore through Discrete Logarithm Ricci Flow HNP" was published, presenting wallet-recovery concepts tied to discrete logarithm and hidden-number-problem techniques.
A GitHub repository for "bitcoin-scan," described as a Bitcoin client and ECDSA vulnerability scanner, was published. This reflects public release of tooling aimed at identifying Bitcoin-related ECDSA weaknesses.
No Bullshit Bitcoin published a report titled "A New Class of ECDSA Signature Vulnerability Observed in the Wild on the Bitcoin Blockchain," indicating observation of a distinct ECDSA nonce-related weakness affecting Bitcoin signatures in the wild.
An IACR ePrint paper analyzed biased or repeated ECDSA nonces and reported recovering around 300 Bitcoin private keys, plus additional keys across other ecosystems, from public blockchain data and Internet-wide scans. The paper identified several nonce-bias patterns and noted deterministic nonce generation such as RFC 6979 would prevent these attacks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
19 references tracked. Mallory keeps watching after this page renders.
polynonce.ru
Open sourceattacksafe.ru
Open sourcegithub.com
Open sourcecryptodeeptech.ru
Open sourcegithub.com
Open sourcecryptou.ru
Open sourceeprint.iacr.org
Open sourcecryptou.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.