|

Researcher finds vulnerabilities in popular paper wallet site

  • The analysis revolves around WalletGenerator’s original open-source code.
  • The researcher advised removing funds from WalletGenerator-based paper wallets.

Harry Denley, a security researcher from MyCrypto.com, has recently posted a brief analysis of popular paper wallet site “WalletGenerator.net.” The core of the analysis revolves around WalletGenerator’s original open-source code. The online code matched the open-source code and it generated wallets using a client-side technique that took in real random entropy and produced a unique wallet until August 17, 2018. 

As per Denley:

“Approaching from a different angle, we then used the “Bulk Wallet” generator to generate 1,000 keys. In the non-malicious, GitHub version, we are given 1,000 unique keys, as expected.


However, using WalletGenerator.net at various times between May 18, 2019 -May 23, 2019, we would only get 120 unique keys per session. Refreshing our browser, switching VPN locations, or having a different party perform the same test would result in a different set of 120 keys being generated.”

Denley highly recommends moving funds off of your WalletGenerator-based paper wallets:

“We’re still considering this highly suspect and still recommending users who generated public/private keypairs after August 17, 2018, to move their funds. We do not recommend using WalletGenerator.net moving forward, even if the code at this very moment is not vulnerable.”

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Injective token surges over 13% following the approval of the mainnet upgrade proposal

Injective price rallies over 13% on Thursday after the network confirmed the approval of its IIP-619 proposal. The green light for the mainnet upgrade has boosted traders’ sentiment, as the upgrade aims to scale Injective’s real-time Ethereum Virtual Machine architecture and enhance its capabilities to support next-generation payments.

Solana Price Forecast: SOL slips below $82 as hawkish Fed tone sparks risk-off sentiment

Solana is trading below $82 at the time of writing on Thursday after failing to break out of the upper consolidation range over the weekend. The Minutes from the Federal Open Market Committee on Wednesday kept interest rates unchanged, but a less dovish tone that followed dampened risk appetite and pressured risky assets.

Warren warns crypto bailout would enrich Trump family biz: Report

Senate Banking Committee ranking member Elizabeth Warren has reportedly sent a letter to Treasury Secretary Scott Bessent and Federal Reserve chair Jerome Powell, urging them not to bail out “cryptocurrency billionaires” with taxpayer dollars. 

Top Crypto Gainers: World Liberty Financial, Sky, and Cosmos confront major resistance

World Liberty Financial, Sky, and Cosmos rank among the top gainers over the last 24 hours but face critical overhead resistance levels. WLFI gained momentum at the World Liberty Forum, an invite-only conference held at Mar-a-Lago by US President Donald Trump’s family, while SKY and ATOM reversed off a crucial support level. 

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: BTC bears aren’t done yet

Bitcoin (BTC) price slips below $67,000 at the time of writing on Friday, remaining under pressure and extending losses of nearly 5% so far this week.