Post
Topic
Board Collectibles
Re: RarityCheck VIBGYOR gilded #12 swept yesterday.
by
DaveF
on 08/08/2024, 22:11:33 UTC
Walletgenerator.net has had known vulnerabilities since at least 2019: https://medium.com/mycrypto/disclosure-key-generation-vulnerability-found-on-walletgenerator-net-potentially-malicious-3d8936485961

But one other issue is that walletgenerator does not support the creation of Vanity keys...so I'm confused why you even switched to using this software from bitaddress?

This is for the website- not for the code on github which RC said he used.
One of the main reasons this vulnerability was found was by comparing the two code bases, which revealed the addition of the malicious code.

From that medium article you posted in (2019):
'At this time, the code on GitHub is not malicious nor vulnerable, nor has it been malicious or vulnerable previously.'
Last checkin for that code on github appears to be 7 years ago.

Even if that code was compromised, if it was on an air gapped system theres no way it could have communicated the keys back to the malicious actors.
Something doesnt smell right here.

The code on github seems to be clean, the site WAS compromised but as of now is not.
Now, note I said SEEMS clean, there might be something else that I missed, I am not a programmer nor do I pretend to be but since the github has been static for 7+ years as you pointed out I would *think* there is something else going on.

Because, if it really was bad, you would *think* there would be a lot more people with lost funds.

Have you reported this to GitHub? They should take it down if it is compromised.

https://github.com/walletgeneratornet/WalletGenerator.net/issues/293

    Good man.  Will they now pull it off the site? I hope nobody else downloads it

As pointed out, if the code is bad on github it's been that way for a loooong time with no other issues that have been reported.

-Dave