ChainBleedv0.1 · open intel
← back to feed·PRIVATE-KEY2023-07-12 · 2y ago
Incident · SLOWMIST

Klever

Low Entropy Mnemonic Vulnerability
Estimated loss
VERDICT —OUT OF SCOPE
Root cause is private-key / signer compromise — the on-chain contract behaved exactly as written. No pre-deployment source audit or bytecode review reaches the key-custody perimeter; this is operational-security territory (HSM/MPC hygiene, key rotation, hot-wallet isolation). Bytecode would show nothing wrong.
▰ METHOD
PRIVATE KEY
PRIVATE-KEY
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Klever published a report on an external security incident on July 12. All wallets affected by the suspicious activity on July 12 were reported to be affected by a known vulnerability caused by low-entropy mnemonics. It's important to underscore that this issue is not exclusive to Klever. Reports indicate that users of multiple wallet providers are affected. All the wallets involved were imported into Klever Wallet K5. These wallets had not been originally created using Klever Wallet K5, instead all the wallets were created using an old and weak pseudorandom number generator (PRNG) algorithm as their entropy source. This algorithm was commonly used in early versions of various cryptocurrency wallet providers, which relied on the Javascript platform. The use of such a weak PRNG algorithm can significantly compromise the security and unpredictability of the generated keys, potentially making them more vulnerable to attacks or unauthorized access. Klever strongly recommends immediately migrating old wallets to new wallets created on Klever Wallet K5 or Klever Safe. Attack method (per SlowMist): Low Entropy Mnemonic Vulnerability. Reported loss: -.

Primary source
https://klever.org/en/blog/klever-alert-external-security-incident
Sourced from
slowmist
Technical record
chain
protocol
Klever
bug_class
private-key
date_occurred
2023-07-12
loss_usd
source_id
sm:klever::2023-07-12
Related — same bug class· private-key
2026-04-30
1mo ago
MULTI
Wasabi Perps
Admin Key Compromised
private-key
$5.50M
OUT OF SCOPE
2026-04-30
1mo ago
ETH
Wasabi Protocol
Private Key Leakage
private-key
$5.70M
OUT OF SCOPE
2026-04-29
1mo ago
Syndicate Labs
Private Key Leakage
private-key
$380.0K
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vault
Admin Key Compromised
private-key
$3.50M
OUT OF SCOPE
2026-04-21
1mo ago
SUI
Volo Vaults
Private Key Leakage
private-key
$3.50M
OUT OF SCOPE
2026-04-16
1mo ago
MULTI
Grinex
Hot wallet hack
private-key
$15.00M
OUT OF SCOPE
ChainBleed — live web3 threat intelligence