Milk Sad

We’re a small team of security researchers looking into the practical problems of weak private keys in popular cryptocurrencies. Our primary focus are keys generated with weak entropy.

Libbitcoin Explorer CVE-2023-39910

Our initial group formed in July 2023 to follow up on mysterious wallet thefts.

Read on:

Current Research

After investigating CVE-2023-39910, a smaller team continued to look into other PRNG weaknesses. Interestingly, we found that the July 2023 theft involved more than one PRNG vulnerability.

Head over to the research updates section for everything that happened after August 2023.

Some highlights:

As part of this continued effort, we publish research data to help other researchers identify thefts and attackers on-chain. Our collection contains over 300k cryptocurrency addresses of weak wallets.

Contact

Ethics

Why the silly “Milk Sad” name?

Running the vulnerable bx seed command with a system time of 0.0 always generates the following BIP39 secret:

milk sad wage cup reward umbrella raven visa give list decorate bulb gold raise twenty fly manual stand float super gentle climb fold park

Original 2023 Team & Credits

Relevant Design Patterns

CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)