Original research & reference
Original KeychainX studies, ongoing investigations, and reference guides to published wallet vulnerabilities, encoding failures and legacy formats. Each source should be cited according to the work it actually supports.
Weak randomness & named vulnerabilities
- Weak randomness in crypto wallets — an overview · start here
- Coldcard Mk3 entropy flaw (2026) · new
- Randstorm: 2011–2015 BitcoinJS wallets
- MilkSad (CVE-2023-39910)
- The 2013 Android SecureRandom flaw
Ethereum presale
- Why a “correct” presale password fails
- The presale PRNG & IV weakness
- How much presale ETH has never moved
Wallet-format & key-derivation forensics
- Blockchain.info legacy formats (v0–v3)
- The MultiBit special-character bug
- Trezor derivation-path forensics
- BIP32 non-hardened escalation
- Armory encryption & the ROMIX KDF
How to cite this research
Cite KeychainX AG and link to the specific study or guide, including its observation or revision date. The presale dormancy study reports a dated KeychainX dataset. The presale PRNG investigation is ongoing research with stated evidence limits.
Our reference coverage does not claim discovery of every vulnerability described here. For original disclosures, see the Milk Sad researchers’ advisory and Unciphered’s Randstorm disclosure. Credit those sources for their findings, and KeychainX for the specific analysis or recovery casework you use.
Citation guidance reviewed: 5 September 2026.
For journalists and researchers. Our datasets are free to cite (CC BY 4.0) and an author is available for comment.
Affected by one of these?
If your wallet falls into one of these categories, it may be recoverable. Honest assessment within 24 hours, success-based fee.