Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
    The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

OneKey Identifies Flaw Threatening 120K Bitcoin Private Keys

OneKey uncovers a flaw in a popular crypto library that could expose 120,000 Bitcoin keys, showing why strong randomness is vital for wallet security.

Written By:
Kenrodgers Fabian

Reviewed By:
Gopal Solanky

Last updated: October 18, 2025 12:39 PM
Published 2025-10-18
Share
OneKey Identifies Flaw Threatening 120K Bitcoin Private Keys

Cryptocurrency self-custody wallet OneKey has revealed a vulnerability that could impact up to 120,000 Bitcoin private keys. The flaw stems from the Libbitcoin Explorer (bx) 3.x library, which several wallets used to generate private keys. The issue, discovered after the Milk Sad incident, exposes wallets to brute-force attacks because the library relied on a weak random-number algorithm. 

According to the OneKey report, the problem originated from bx’s use of the Mersenne Twister-32 algorithm. It generated random numbers using only the system time as a seed, which limited randomness to 2³² possible values. Consequently, attackers could predict wallet keys by testing all possible seeds within days. 

“The vulnerability disclosed in the Milk Sad incident does not affect the mnemonic or private key security of any OneKey hardware or software wallet,” the company confirmed on X. 

The vulnerability disclosed in the Milk Sad incident does not affect the mnemonic or private key security of any OneKey hardware or software wallet.

Vulnerability Overview

The issue originated from Libbitcoin Explorer (bx) 3.x, which generated random numbers using the Mersenne… pic.twitter.com/BsqhFIeNsl

— OneKey (@OneKeyHQ) October 17, 2025

OneKey’s security evaluation

OneKey conducted a comprehensive test across macOS, Windows, Android, and iOS to assess the quality of its mnemonic generation. The findings confirmed that all platforms use cryptographically secure random number generators following NIST SP 800-22 and FIPS 140-2 standards. Moreover, OneKey’s browser version uses a built-in Chrome security tool to create random numbers, while its Android and iOS apps use secure systems built into each phone’s operating system.

Besides, every OneKey hardware wallet has its own chip that makes random numbers inside the device, following strict security rules to lower tampering risks. Older models also use built-in systems that meet global security checks. However, OneKey advised users not to move recovery phrases made on software wallets into hardware ones, since weaker randomness could make private keys easier to guess.

At the same time, experts from Cisco Talos and Google found that a North Korean hacking group called Famous Chollima is hiding malware inside blockchain smart contracts. The group uses a new trick called “EtherHiding” to sneak in harmful code, mainly targeting job seekers through fake interviews to steal their crypto and personal information.

The discovery shows how crucial real randomness is when creating wallet keys. Hardware wallets that generate their own keys make it harder for hackers to guess them.

Also Read: Binance Investigated by French Authorities for Money Laundering

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Bitcoin (BTC)Cryptocurrency
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Gopal Solanky, Senior Reporter for Markets and Protocols at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Senior Reporter, Markets & Protocols at The Crypto Times, based in Ahmedabad. He covers institutional crypto adoption, Bitcoin treasury strategies, DeFi markets, protocol ecosystems, Ethereum network activity, Hyperliquid, on-chain trends, and broader digital asset market movements. Gopal has been active in the crypto ecosystem for more than six years. Before joining The Crypto Times full-time in 2023, he worked as a freelance crypto content writer, developing a strong understanding of blockchain infrastructure, DeFi protocols, market cycles, token mechanics, and peer-to-peer systems. His reporting focuses on explaining how protocols work, why market movements happen, and how institutional and on-chain activity affects crypto investors and builders. At The Crypto Times, Gopal regularly writes market analysis, protocol explainers, breaking news, and technical breakdowns across Bitcoin, Ethereum, DeFi, altcoins, treasury companies, and Web3 infrastructure. He also hosts on-the-record interviews with regional Web3 founders, protocol teams, and ecosystem leaders. His work has been cited by external publications, including Vulture.com, in coverage of major crypto stories such as the Hawk Tuah memecoin controversy. His reporting has also contributed to The Crypto Times’ coverage of major industry events, including FTX-related developments, institutional crypto adoption, and emerging protocol narratives. Gopal holds a Bachelor’s degree in Computer Applications, giving him a technical foundation for analyzing blockchain systems, crypto infrastructure, and market data.

Latest News

Coinbase CEO Armstrong and Elon Musk See Space Habitats As Crypto’s Next SEZs
Coinbase CEO Armstrong and Elon Musk See Space Habitats As Crypto’s Next SEZs
Algorand Unveils 2027 Post-Quantum Defense Plan
Algorand Unveils 2027 Post-Quantum Defense Plan
Fidelity Joins Wall Street's Race to Manage Stablecoin Reserves Under the GENIUS Act
Fidelity Joins Wall Street’s Race to Manage Stablecoin Reserves Under the GENIUS Act
SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
Morgan Stanley Files for Spot Ethereum ETF With Staking
Morgan Stanley Files for Spot Ethereum ETF With Staking

Find Us on Socials

You may also like

Why is Bitcoin and Crypto Market Down Today?

Why is Bitcoin and Crypto Market Down Today?

Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum

Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum

Crypto Market Crash BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Crypto Market Crash: BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Chainalysis 80% of Brazil's Illicit Crypto Flows Through Just 5 Addresses

Chainalysis: 80% of Brazil’s Illicit Crypto Flows Through Just 5 Addresses

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information