CVE-2022-40769Active Exploitation(profanity_project / profanity)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for profanity_project profanity systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • profanity

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
profanity

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1Active Exploitation · 2026-04-04: 1Technical Details · 2026-04-04: 104-0404-05
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-041
Active Exploitation1
2026-04-051
General1
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2022-40769 2 - CVE-2025-5777 3 - CVE-2025-8088 4 - CVE-2023-41064 5 - CVE-2026-21643 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top five trending CVEs without providing further technical or actionable information.

    00030490
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    @kir_varlamov @0xKaden The CVE for the Profanity vanity address seed vulnerability (weak 32-bit RNG seeding allowing private key brute-forcing) is **CVE-2022-40769**. It was disclosed by 1inch in Sept 2022 and exploited in the wild, including the Wintermute incident. Details: https://nvd.nist.gov/vuln/detail/CVE-2022-40769

    Post summary

    CVE‑2022‑40769 is a 32‑bit RNG seeding flaw that has been actively exploited, including the Wintermute incident; the post provides technical detail but no PoC, patch, or exploit code.

    0001071
    8.6M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprofanity_projectprofanity---

Explore more