CVE-2023-39910 (“Milk Sad”) affected Libbitcoin Explorer (bx) versions 3.0.0 through 3.6.0 because its bx seed function initialized the non-cryptographic MT19937 pseudorandom-number generator with only 32 bits derived from the system clock. As a result, requests for 256-bit wallet entropy produced seeds drawn from a practical 2^32 search space, enabling attackers to reproduce affected BIP-39 mnemonics, derive private keys, and access associated cryptocurrency funds.
The weakness has been linked to a July 2023 theft wave totaling roughly 29.65 BTC and to thousands of potentially vulnerable active wallets, with exposure extending beyond Bitcoin to other cryptocurrencies using affected seeds. Organizations and users that generated wallets with impacted bx releases should treat those wallets as compromised candidates, move assets to newly created wallets, and generate replacement seed material using a cryptographically secure random source.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Distrust published the full technical disclosure for Milk Sad, documenting that affected bx versions seeded MT19937 with only 32 bits of clock-derived entropy and enabled regeneration of wallet seeds and keys.
MITRE assigned CVE-2023-39910 to the Libbitcoin Explorer weak-seed-generation vulnerability, categorized as CWE-338.
A major theft wave targeting weak bx-generated wallets reportedly occurred on July 12, 2023, stealing approximately 29.65 BTC, valued at more than $850,000 at August 2023 exchange rates.
Suspicious thefts involving wallets generated with Libbitcoin Explorer's weak bx seed mechanism reportedly began around May 3, 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
polynonce.ru
Open sourcecryptodeeptech.ru
Open sourcecryptodeeptech.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.