CVE-2023-39910, known as Milk Sad, affects Libbitcoin Explorer (bx) versions 3.0.0 through 3.6.0. The bx seed command used the non-cryptographic MT19937 PRNG initialized from a 32-bit system-clock-derived value, reducing supposedly 128-, 192-, or 256-bit wallet entropy to no more than 2^32 possible states. Attackers can enumerate candidate seeds, derive BIP39/BIP32 wallets and addresses, and compare them against public blockchain activity without breaking secp256k1, BIP39, or BIP32 cryptography.
Researchers linked the weakness to suspicious 2023 wallet sweeps, including three transactions that moved approximately 29.65 BTC on July 12, and identified more than 2,600 used wallets in a limited Bitcoin-only search. Organizations and individuals that generated mnemonic phrases with affected bx seed releases should consider those wallets compromised, transfer assets to newly created wallets, and generate replacement entropy with an operating-system cryptographically secure PRNG.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Milk Sad published its technical disclosure describing how the vulnerable bx seed command limited reachable wallet-entropy outputs to at most 2^32 states, enabling practical enumeration of candidate wallets.
The entropy weakness affecting Libbitcoin Explorer bx versions 3.0.0 through 3.6.0 was assigned CVE-2023-39910.
Investigators reportedly discovered the Libbitcoin Explorer entropy-generation defect during an incident investigation. The flaw stems from bx seed using a clock-derived 32-bit seed for the non-cryptographic MT19937 PRNG.
A main cluster of three Bitcoin transactions moved approximately 29.65 BTC in suspicious sweeps. At August 2023 exchange rates, the transactions were worth more than US$850,000.
Suspicious small sweep operations associated with the Milk Sad weakness began appearing. The activity involved wallets whose entropy may have been generated by vulnerable Libbitcoin Explorer bx seed releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.