CVE-2024-1631Disclosure(dfinity / icp-js-core)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is expected that the library generates the secret key using secure randomness. However, a recent change broke this guarantee and uses an insecure seed for key pair generation. Since the private key of this identity (535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe) is compromised, one could lose funds associated with the principal on ledgers or lose access to a canister where this principal is the controller.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321CWE-330

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • icp-js-core

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
icp-js-core

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-16: 1Technical Details · 2026-03-16: 103-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    Insecure key generation in `agent-js` Ed25519KeyIdentity.generate (CVE-2024-1631) may lead to cryptographic identity compromise. Review usage. #Infosec #Cryptography #Web3 https://www.pulsepatch.io/posts/cve-2024-1631-agent-js-insecure-key-generation

    Post summary

    A tweet announces CVE‑2024‑1631, noting insecure Ed25519 key generation in agent-js’s Ed25519KeyIdentity.generate that could compromise cryptographic identities, but it does not provide a PoC, exploit code, active exploitation evidence, or a patch.

    0000050
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdfinityicp-js-core-node.js-

Explore more