Profanity through version 1.60 generates Ethereum vanity-address keys using the mt19937 pseudorandom number generator seeded with a timer-derived 32-bit value rather than cryptographically secure 256-bit entropy. This limits the effective initialization space to 2^32 possibilities. Profanity's deterministic, reversible derivation operations over secp256k1 permit an attacker to enumerate or precompute the limited seed space, associate a target vanity address public key with its seed, and recover the corresponding private key. This is an implementation-level entropy failure, not a weakness in secp256k1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a single C++ program and a README. The main file, NOWYGENERATOR202220223.cpp, is a standalone local key generator targeting two cryptocurrency-related weak-RNG vulnerabilities: CVE-2023-39910 (Milk Sad / libbitcoin-explorer) and CVE-2022-40769 (Profanity). It does not exploit a live service or communicate over the network. Instead, it brute-generates candidate private keys from a user-supplied 32-bit seed range and writes them to text files. Code structure is simple: generate_priv_libbitcoin(seed) uses std::mt19937 seeded with a 32-bit integer and concatenates eight 32-bit outputs into a 32-byte private key; generate_priv_profanity(seed) reproduces a linear congruential generator using state = state * 1103515245 + 12345 and similarly emits 32 bytes; format_time() formats elapsed runtime; main() parses optional CLI arguments [start_seed] [end_seed] [output.txt], iterates through the seed range twice, and writes results to libbitcoin_<output> and profanity_<output> while printing progress statistics. Primary capability is bulk generation of candidate private keys for vulnerable wallets, intended for downstream processing by external tools such as the referenced AllChainScanner. The exploit is therefore operational but local-only: it provides a usable payload (candidate keys) rather than direct compromise logic. No network endpoints, C2, or remote exploitation routines are present. Fingerprintable artifacts are limited to local output filenames and documentation URLs. The README heavily emphasizes cryptocurrency wallet recovery/scanning workflows and explains how generated keys can be converted into addresses and checked for balances using external software.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptographic weak-entropy vulnerability in the Profanity Ethereum vanity-address generator. Predictable 32-bit PRNG seeding and reversible key-expansion operations made generated private keys practically recoverable, leading to thefts including the approximately $160 million Wintermute incident.
A specific vulnerability identified as CVE-2022-40769 affecting the Profanity project; the content indicates it can be detected via exposed files and configuration/script artifacts, but does not provide a full technical description.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.