CVE-2024-23660

HIGH

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the devi...

Affects 1 product across 1 vendor.

BCS5.31
CVSS 3.17.5
EPSS0.6%
Percentile43th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-338: CWE-338
◆ SAGE Intelligence — CITED Relevance Research Team

The Binance Trust Wallet app for iOS version 0.0.4 misuses the trezor-crypto library, using only the device time as an entropy source for generating mnemonic words. This vulnerability can lead to economic losses as attackers can predict and generate mnemonics for specific timestamps.

BSID: BS-2024-GLOBAL-052226-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-23660?
The Binance Trust Wallet app for iOS version 0.0.4 misuses the trezor-crypto library, using only the device time as an entropy source for generating mnemonic words. This vulnerability can lead to economic losses as attackers can predict and generate mnemonics for specific timestamps.
What is the CVSS score for CVE-2024-23660?
CVE-2024-23660 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. EPSS: 0.6%.
Is CVE-2024-23660 actively exploited?
No confirmed active exploitation of CVE-2024-23660 as of 2026-05-30.
How do I remediate CVE-2024-23660?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-23660?
CVE-2024-23660 affects: Binance.
Vulnerability Details
CVE IDCVE-2024-23660
BSIDBS-2024-GLOBAL-052226-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Published2024-02-08
Last Modified2025-05-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, exploiting the predictable entropy source to gain unauthorized access to user wallets.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Binance Trust Wallet
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 898 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashb0c32afcdaccee992f763657cf6571abef3176f737566b13ed14e93526618722503a141a8dc066d56f35ab2db2eb8ed0ac991b241b4a9519d4ad7f80a9d0cb96
Related CVEs affecting Binance
CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2025-27106 8.8 binance-trading-bot is an automated Binance trading bot with trailing buy/sel... CVE-2020-12118 8.2 The keygen protocol implementation in Binance tss-lib before 1.2.0 allows att...
View all Binance CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →