CVE-2021-38195Active Exploitation(parity / libsecp256k1)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for parity libsecp256k1 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libsecp256k1

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
libsecp256k1

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-09: 1Active Exploitation · 2026-08-09: 1Technical Details · 2026-08-09: 108-09
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Ashutosh Singh@0xAshutosh
    Active Exploitation

    Bitcoin’s cryptographic security isn’t just about whether secp256k1 is “broken.” Recent vulnerabilities show risks across the entire stack: • CVE-2024-49364 — private-key extraction • CVE-2024-48930 — ECDH private-key extraction • CVE-2023-49292 — private-key recovery • CVE-2023-39910 — weak wallet entropy • CVE-2021-38195 — invalid signature acceptance • CVE-2019-25003 — timing side channel CVE-2023-39910 (Milk Sad) was exploited in the wild, enabling recovery of vulnerable wallet private keys and theft of funds. August 2026 adds another warning: a Coldcard wallet flaw was linked to coordinated attacks reportedly draining nearly $89M from 1,000+ Bitcoin wallets. And vulnerabilities don’t always have CVEs. Reused/predictable ECDSA nonces, RNG failures, invalid-curve attacks, side channels, firmware bugs and supply-chain compromises can all threaten private keys. Bitcoin also relies on Schnorr signatures through BIP-340 and Taproot (BIP-341/342), not just ECDSA. Then there’s the long-term threat: quantum computers could eventually break the elliptic-curve cryptography securing Bitcoin. The risk isn’t that secp256k1 has suddenly been cracked. The risk is the entire security stack. Bitcoin needs continuous cryptographic auditing, secure randomness and nonce generation, hardened implementations, responsible disclosure, and a credible post-quantum migration path — before the threat becomes urgent.

    Post summary

    Bitcoin’s ecosystem has several cryptographic CVEs, one of which (CVE‑2023‑39910) has been actively exploited in the wild, underscoring the need for ongoing auditing, secure randomness, and a post‑quantum migration plan.

    00011384
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparitylibsecp256k1-rust-

Explore more