CVE-2023-31290General(trustwallet / trust_wallet_browser_extension)

HIGHCVSS 5.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for trustwallet trust_wallet_browser_extension systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only four billion possible mnemonics. The affected versions of the browser extension are 0.0.172 through 0.0.182. To steal funds efficiently, an attacker can identify all Ethereum addresses created since the 0.0.172 release, and check whether they are Ethereum addresses that could have been created by this extension. To respond to the risk, affected users need to upgrade the product version and also move funds to a new wallet address.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trust_wallet_browser_extension
  • trust_wallet_core

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-31)
  • 4 total mentions across 3 days

Affected systems

Products
trust_wallet_browser_extensiontrust_wallet_core

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-31: 1Mentions · 2026-08-08: 1Mentions · 2026-08-31: 2PoC Mentioned / Linked · 2026-08-31: 2Exploit Tool / Code · 2026-08-31: 2Active Exploitation · 2026-08-31: 1Technical Details · 2026-08-31: 107-3108-0808-31
Signal classification2 categories
General
250.0%
PoC
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-311
General1
2026-08-081
General1
2026-08-312
PoC2
Full discourse4 posts
  • Francois Garillot@huitseeker
    General

    • installing an official Trust Wallet browser extension https://nvd.nist.gov/vuln/detail/CVE-2023-31290 • installing an official Trust Wallet iOS app https://nvd.nist.gov/vuln/detail/CVE-2024-23660 8/13

    Post summary

    The text simply lists two CVE entries with links to NVD pages, providing no further details on exploitation, patches, or technical aspects.

    11010126
    2.4K followersView on X
  • easyHackCash@easyHackCash
    PoC

    Just open-sourced a BTC wallet cracking POC toolkit covering most publicly known vulnerabilities: - Coldcard Yasmarang — reproducing the $116M hack - TrustWallet — CVE-2023-31290 / CVE-2024-23660 - Libbitcoin Milk Sad — $900K+ stolen - CryptoJS Blockchain info — $5M+ stolen - Coldcard Dice — still unpatched, never publicly disclosed Your average home PC can join the game. With CUDA acceleration: 50,000 mnemonics/private keys per second. GitHub took down my repo. Again. I rebuilt. Again. New home: https://github.com/easyHvckCash/easyWallet More POCs coming soon. Stay tuned. 🔓

    Post summary

    The user has published a proof-of-concept BTC wallet cracking toolkit that includes exploit code for several high‑profile CVEs, reports ongoing exploitation with significant theft amounts, and provides a GitHub repository for the code.

    00011320
    2.0K followersView on X
  • easyHackCash@easyHackCash
    PoC

    开源了一套 BTC 钱包破解 POC 工具集,涵盖了目前已知的大部分公开漏洞: - Coldcard Yasmarang — 复现 1.16 亿美元攻击 - TrustWallet — CVE-2023-31290 / CVE-2024-23660 - Libbitcoin Milk Sad — 超 90 万美元被盗 - CryptoJS Blockchain info — 超 500 万美元被盗 - Coldcard Dice — 至今未修复,从未公开披露 普通家用电脑即可参与。CUDA 加速下可达每秒 5 万个助记词/私钥的扫描速度。 GitHub 封了我的仓库。又一次。我重建了。又一次。新地址:https://github.com/easyHvckCash/easyWallet 更多 POC 持续更新中,敬请关注。🔓

    Post summary

    该条目宣布一套开源 BTC 钱包破解 PoC 工具集,包含多个 CVE 的利用代码,强调可通过 GPU 加速扫描,但未报告现行活跃攻击或补丁信息。

    00010280
    2.0K followersView on X
  • Arturo Jamaica@ajamaica
    General

    @nicogsobrino Si han tenido. Trust wallet por ejemplo https://mallory.ai/vulnerabilities/CVE-2023-31290

    Post summary

    The user mentions a Trust Wallet CVE (CVE‑2023‑31290) and links to a webpage, but provides no additional details, claims of exploitation, or mitigation information.

    00010273
    13.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrustwallettrust_wallet_browser_extension---
Apptrustwallettrust_wallet_core---

Explore more