Attackers exploited a weakness dubbed "Milk Sad" in the Libbitcoin Explorer 3.x library to steal more than $900,000 from cryptocurrency wallets whose seeds were generated with the bx seed command. Researchers said the flaw came from weak randomness during wallet-seed generation, allowing private keys to be guessed and funds drained; one reported theft exceeded $278,318. The issue was identified by the Distrust team, reported to the vulnerability database, and later publicized by blockchain security firm SlowMist, which said it worked with exchanges in an attempt to block the attacker’s address.
The incident put renewed scrutiny on the long-running Libbitcoin project and raised concerns that exposure could extend beyond Bitcoin wherever the library was used to create accounts. Libbitcoin Institute member Eric Voskuil said the vulnerable command was not intended for production wallet use, and reports indicated the project could strengthen warnings or remove the feature. The thefts highlighted how insecure seed generation in developer tooling can translate directly into large-scale wallet compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Libbitcoin Institute member Eric Voskuil responded that the affected command was not intended for production wallet use and said it might be removed or accompanied by stronger warnings. This was the project's public response to the thefts and vulnerability concerns.
Blockchain security firm SlowMist publicized the vulnerability, attributed the thefts to weak randomness in the "bx seed" command, and said it had coordinated with exchanges in an attempt to block the attacker's address. Its reporting broadened awareness of the incident and its cross-cryptocurrency impact.
Attackers exploited predictable seeds generated by the vulnerable Libbitcoin Explorer function to drain affected cryptocurrency wallets, with total losses reported at more than $900,000. SlowMist said one individual theft exceeded $278,318.
The Distrust team identified the Libbitcoin Explorer 3.x weakness and reported it to the CEV vulnerability database. This disclosure established the technical basis for later reporting on thefts tied to the bug.
A flaw later dubbed "Milk Sad" existed in Libbitcoin Explorer 3.x's "bx seed" command, where weak randomness made generated wallet seeds predictable and allowed attackers to derive private keys. The issue affected users who created wallets or accounts with the vulnerable seed-generation function.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
pcnews.ru
Open sourcebitcoinworld.co.in
Open sourcecoindesk.com
Open sourcecrypto.news
Open sourcebitcoinist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.