CVE-2023-31290 is a critical vulnerability in Trust Wallet Core (before 3.1.1) and the Trust Wallet browser extension (versions 0.0.172-0.0.182) that allows for the theft of cryptocurrency funds. The vulnerability stems from the use of a weak 32-bit entropy seed for mnemonic generation, significantly reducing the number of possible wallet addresses. This flaw has a CVSS score of 5.9 (Medium) due to its high impact on integrity (I:H) and moderate attack complexity (AC:H), enabling attackers to efficiently identify and compromise affected wallets. The vulnerability has been actively exploited in the wild since December 2022, though no public exploit code or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.0.172, < 0.0.183CPE matchmatch criteria | cpe:2.3:a:trustwallet:trust_wallet_browser_extension:*:*:*:*:*:*:*:* | ||
< 3.1.1CPE matchmatch criteria | cpe:2.3:a:trustwallet:trust_wallet_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.