Unciphered, which helps recover cryptocurrency, finds a BitcoinJS flaw in some wallets made before 2016, and says that up to $1B of crypto is at risk of theft
Washington PostJoseph Menn
Context & Ripple Effects
This warning extends a recurring wallet-security thread: researchers had already identified a double-spending weakness affecting several major crypto wallets, while later coverage documented large aggregate losses across crypto hacks. The notable distinction here is the exposure of older wallets through a shared software component rather than a single current product.
It matters because cryptocurrency users can retain assets and credentials for years. A flaw tied to wallets made before 2016 turns software maintenance history into an active custody risk, even where the underlying blockchain itself is unchanged.
First-order effects
Owners of affected pre-2016 BitcoinJS-based wallets face a potential theft risk and need to determine whether their wallet software or keys fall within the vulnerable implementation.
Wallet providers and recovery specialists gain an immediate need to identify exposed legacy users and provide safe migration or remediation guidance.
Second-order effects
Wallet developers and custodians are pressured to audit inherited cryptographic dependencies and distinguish vulnerable legacy implementations from current products.
The disclosure raises the value of specialized recovery and security services, while making users more cautious about leaving assets in old or unsupported wallet setups.
Third-order effects
If legacy-library flaws continue to surface, crypto custody will increasingly be judged on software lifecycle management and upgrade paths, not just on the security claims of the blockchain.
The pattern points toward a more formal market for audits, disclosure, and migration support for long-lived digital assets; the scale of that shift depends on how many affected wallets remain accessible and funded.
The trend: Crypto custody is moving toward a security model in which aging wallet code and dependency management are as consequential as the blockchain protocol itself.
🚨 Big news from us at @uncipheredLLC: We've publicly disclosed vulnerabilities in BitcoinJS-based wallets generated between 2011 and 2016. The coordinated disclosure has gone smoothly so far. Vendors have notified over a million wallet holders! (please migrate your crypto from...
“He is done with crypto anyway, after starting three companies in the industry and winding up a bit poorer than when he began. Now he is working on artificial intelligence.” the “AI is just crypto scam replayed” theory seems really reasonable https://www.washingtonpost.com/ ...
If you created a bitcoin wallet before 2016, your money may be at risk A company that helps recover cryptocurrency discovered a software flaw putting as much as $1 billion at risk from hackers. https://www.washingtonpost.com/ ...
Today we release our work on Randstorm: a vulnerability affecting a significant number of browser generated cryptocurrency wallets https://randstorm.com/ Reporting @washingtonpost https://www.washingtonpost.com/ ... Technical write-up: https://www.unciphered.com/... #Bitcoin #blo…
At least we are making progress with entropy failures. Instead of your usual Mersenne Twister 32 bit fail, we have now ~48 bit old javascript Math.random() fails 🤦 good Job @uncipheredLLC for discovering that https://www.unciphered.com/... [image]
The list of vulnerable implementations is not telling the full story. Even if the project is dead, seed phrases created with such are still as much vulnerable even if used within modern wallets. Users of such need to move their funds ASAP! https://www.unciphered.com/... [image]
A company I've been advising, Unciphered, has discovered a serious security flaw in many cryptocurrency wallets created before 2016. https://www.washingtonpost.com/ ... If you've got a wallet from that era, you should read this article and protect yourself immediately.