CVE-2024-23660General(binance / trust_wallet)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for binance trust_wallet systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trust_wallet

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-31)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
trust_wallet

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-01: 1Mentions · 2026-08-08: 1Mentions · 2026-08-31: 2PoC Mentioned / Linked · 2026-08-31: 2Exploit Tool / Code · 2026-08-31: 2Technical Details · 2026-08-01: 108-0108-0808-31
Signal classification2 categories
General
250.0%
PoC
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-011
General1
2026-08-081
General1
2026-08-312
PoC2
Full discourse4 posts
  • Francois Garillot@huitseeker
    General

    • installing an official Trust Wallet browser extension https://nvd.nist.gov/vuln/detail/CVE-2023-31290 • installing an official Trust Wallet iOS app https://nvd.nist.gov/vuln/detail/CVE-2024-23660 8/13

    Post summary

    The content merely references two CVEs through NVD links without providing any additional context such as PoC, exploit code, active exploitation, patches, or technical details.

    11010126
    2.4K followersView on X
  • easyHackCash@easyHackCash
    PoC

    Just open-sourced a BTC wallet cracking POC toolkit covering most publicly known vulnerabilities: - Coldcard Yasmarang — reproducing the $116M hack - TrustWallet — CVE-2023-31290 / CVE-2024-23660 - Libbitcoin Milk Sad — $900K+ stolen - CryptoJS Blockchain info — $5M+ stolen - Coldcard Dice — still unpatched, never publicly disclosed Your average home PC can join the game. With CUDA acceleration: 50,000 mnemonics/private keys per second. GitHub took down my repo. Again. I rebuilt. Again. New home: https://github.com/easyHvckCash/easyWallet More POCs coming soon. Stay tuned. 🔓

    Post summary

    The author released an open‑source GPU‑accelerated POC toolkit for cracking BTC wallets, including exploits for CVE‑2023‑31290 and CVE‑2024‑23660, and has shared the code on GitHub.

    00011320
    2.0K followersView on X
  • easyHackCash@easyHackCash
    PoC

    开源了一套 BTC 钱包破解 POC 工具集,涵盖了目前已知的大部分公开漏洞: - Coldcard Yasmarang — 复现 1.16 亿美元攻击 - TrustWallet — CVE-2023-31290 / CVE-2024-23660 - Libbitcoin Milk Sad — 超 90 万美元被盗 - CryptoJS Blockchain info — 超 500 万美元被盗 - Coldcard Dice — 至今未修复,从未公开披露 普通家用电脑即可参与。CUDA 加速下可达每秒 5 万个助记词/私钥的扫描速度。 GitHub 封了我的仓库。又一次。我重建了。又一次。新地址:https://github.com/easyHvckCash/easyWallet 更多 POC 持续更新中,敬请关注。🔓

    Post summary

    The author has open‑source a BTC wallet cracking PoC toolset that targets several known vulnerabilities, including named CVEs, and offers a GitHub repository for continuous updates.

    00010280
    2.0K followersView on X
  • Bitcoin Meetup Ostschweiz 🇨🇭 #NoBIP110 Split@Peter_6_5
    General

    @cz_binance @TrustWallet Not Android, only Browser-Extension (Wasm) – CVE-2023-3129 and iOS problem 2018 (CVE-2024-23660).

    Post summary

    The tweet points to two CVEs: one affecting only browser extensions using WebAssembly and another related to an iOS bug, without providing further exploit, patch, or active usage details.

    00010155
    437 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbinancetrust_wallet0.0.4iphone_os-

Explore more