CVE-2023-33241General(gg18_project / gg18)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch gg18_project gg18 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gg18
  • gg20

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
gg18gg20

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-22: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-25: 105-2205-25
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-221
General1
2026-05-251
Active Exploitation1
Full discourse2 posts
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: THORChain hit by $10.7M theft after leaving CVE-2023-33241 patch undeployed for 9 days, marking its third major breach in 5 years. https://threatcluster.io/cluster/thorchain-hit-by-107-million-theft-due-to-unapplied-patch-9d7ff6e6

    Post summary

    The article reports a $10.7 million theft from THORChain caused by an unpatched CVE‑2023‑33241, confirming active exploitation in the wild.

    0201311.3K
    396 followersView on X
  • Shigeyuki Azuchi@techmedia_think
    General

    @nakajo 公式発表出てましたね。原因はGG20のTSSが狙われたっぽい。 具体的な攻撃手法はまだ開示されてないようですが、CVE-2023-33241 or TSSHOCK系なのか、またはそれ以外なのかは今後の開示待ちですかね。 https://thorchain.org/blog/thorchain-exploit-report-1

    Post summary

    The post reports that CVE-2023-33241 has been officially announced, with preliminary indications pointing to an attack on GG20 TSS, but no technical details, exploit code, or mitigation information are provided.

    01010249
    4.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgg18_projectgg18---
Appgg20_projectgg20---

Explore more