Android Bitcoin Wallets Are Easy to Steal

by anonymous on 2013-08-13 14:43:13

The Bitcoin community has issued a warning that Android Bitcoin wallets are vulnerable to theft due to a weakness in Android's random number generator. Users should quickly transfer their bitcoins to a secure address not generated by an Android phone or tablet.

There have been multiple reports of users having their Bitcoin balances stolen from their Android devices. The issue seems to be related to SecureRandom(), which contains a bug. This causes Android-based Bitcoin wallets to potentially reuse the same random number in transaction signatures. If this random number is used twice with the same private key, the private key can be recovered, allowing third parties to access the Bitcoin balance stored at a specific address.