Binance's vulnerability footprint centers on its cryptocurrency wallet and cryptographic key-management infrastructure, particularly Trust Wallet and its TSS (Threshold Signature Scheme) library components. The observed weakness classes reflect configuration and cryptographic primitives: incorrect default permissions and use of weak pseudo-random number generators, which matter in the context of asset custody and signing operations where such flaws can directly compromise key material and transaction integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Binance over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23660HIGH The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words f | Feb 8, 2024 | 7.5 | 24 | NO | NO |
CVE-2020-12118HIGH The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensit | Apr 23, 2020 | 8.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Binance.
Media articles that mention a CVE ID that affects a product developed by Binance — matched by CVE ID, not by vendor name.