Share this article

Google patches Android flaw that led to bitcoin heist

Google released an advisory for the Android flaw that led to the theft of thousands of dollars in bitcoin.

Updated Sep 10, 2021, 11:29 a.m. Published Aug 16, 2013, 8:52 a.m.
WP_20130815_006

Google has released an advisory to developers on how to deal with the recently discovered flaw in Android that led to the theft of thousands of dollars in bitcoin from mobile app wallets.

The [then] potential flaw was first reported on the Bitcoin forum, where it was reported that over 55 BTC had been stolen from multiple users to the same bitcoin address. The forum user also reported that the (software) clients that had been stolen from had signed the transaction messages with the same random number. This in turn led some to believe that Android's pseudo random number generator (PRNG) was not being properly initialised.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

When transaction messages are signed, they are signed with a combination of one's private key and a random number. The random number's purpose is to conceal the value of the private key. If the same random number is used more than once, the private key can be deduced.

blockchain android update
blockchain android update

Bitcoin developers issued an alert about this within 24 hours of the forum post. In which it named some of the affected apps: Bitcoin WalletBlockchain.info walletBitcoinSpinner and Mycelium Wallet. Furthermore, it confirmed that updates had been prepared for the named applications. Indeed, we can independently verify that at least the Blockchain.info app had been updated prior to the time of writing.

The Bitcoin developers went on to advise that users make sure they update their apps as soon as possible, and in the meantime to move coins away to an alternative wallet.

More recently, Google come forward to make a statement on its Android Developer blog. It confirmed that applications using the Java Cryptography Architecture (JCA) were not receiving cryptographically strong values due to improper initialization (i.e. a "seed value"). It also confirmed that the PRNG of Android's SSL and TLS signing was not affected by this flaw.

Fortunately there is something that developers can (and have) done now to deal with the problem, as the underlying PRNG of the JCA can be explicitly initialised with a better-than-default seed value.

Furthermore, the Android developer team has issued a fix to the Open Handset Alliance (OHA) so that OEMs can implement the fix into their Android distributions. However, any Android update has to pass through OEM testing, and then go through operator approval. Therefore, the patch will likely take a long time to trickle down to end users.

Bitcoin expert and information security professional Vladimir Marchenko reminded users that flaws in software do happen, and that they should always be mindful of applying security patches and software updates in a timely manner. He also spoke to the strength of the Bitcoin team:

"This incident has also demonstrated how professionally, quickly and efficiently the bitcoin community has reacted and resolved the issue. Bravo!"

Marchenko went on to give the following cautionary note: "As a general note it might be unwise to use mobile phones to store large amounts of bitcoins. The mobile devices are, however, extremely convenient in day-to-day use of bitcoin and having small amounts stored there while larger amounts are stored more securely elsewhere makes sense.

"Just like people have savings accounts and current accounts in banks, users should separate long-term storage of larger amounts of bitcoins and more convenient storage of smaller amounts for day-to-day use. This reduces the amount of assets at risk and therefore overall risk, while providing a reasonable level of convenience."

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Coinbase Sees Crypto Recovery Ahead as Liquidity Improves and Fed Rate Cut Odds Climb

Coinbase

The crypto exchange also took note of a so-called AI bubble that continues to go strong and a weaker U.S. dollar.

What to know:

  • Coinbase Institutional is seeing a potential December recovery in crypto, citing improving liquidity and a shift in macroeconomic conditions that could favor risk assets like bitcoin.
  • The firm's optimism is driven by rising odds of Federal Reserve rate cuts, with markets pricing in a 93% chance easing next week, and improving liquidity conditions.
  • Several recent institutional developments, including Vanguard's crypto ETF policy reversal and Bank of America's greenlighting of crypto allocations, have contributed to bitcoin's rebound from recent lows.