CVE-2024-23660
An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-338
- Affected
- binance/trust wallet
- Source
- cve@mitre.org
References
- https://milksad.info/posts/research-update-5/Exploit, Third Party Advisory
- https://secbit.io/blog/en/2024/01/19/trust-wallets-fomo3d-summer-vuln/Exploit, Third Party Advisory
- https://milksad.info/posts/research-update-5/Exploit, Third Party Advisory
- https://secbit.io/blog/en/2024/01/19/trust-wallets-fomo3d-summer-vuln/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.