« All posts

Wallet SDK Generates BIP39 Seeds from Math.random() — Is This Bounty-Eligible?

A security researcher questions the bounty eligibility of a wallet SDK's use of Math.random() for BIP39 seed generation.

A security researcher has discovered that a cryptocurrency wallet SDK generates BIP39 mnemonic phrases by calling Math.random() once per word. This method leads to a high failure rate in standard BIP39 validation, locking users out of their funds. The researcher is assessing the severity and bounty eligibility of these findings before submitting a report.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work