You Build. We Defend. Since 2014 protecting critical decentralized systems: L1 nodes, smart contracts audits, wallets, web3 dApps, exchanges, bridges.

1/ Wallet teams: Your users can switch wallets and carry the a vulnerability with them. If a mnemonic was generated by a broken PRNG, importing it into a new wallet does not make it safe. That’s the problem Unlukey is built to solve.
4
4
11
861
5/ The check is private by design. The mnemonic never leaves the wallet. No address lookup. No central service that needs to know what the user is checking. Wallets can check locally against the published and reproducible datasets.
1
92
6/ This is where wallet teams can help. A weak mnemonic can stay in use for years, even after the original app is gone. Users import it, receiving funds and assuming everything is fine. Integrate Unlukey and warn them before an attacker finds them. github.com/coinspect/unlukey
1
90
Wallet teams: what are you waiting for? Unlukey gives defenders a real advantage: the chance to identify weak wallets before attackers do.
We simplified Unlukey. Instead of precomputing billions of addresses (BIP39) from weak seed-generation vulnerabilities, we want wallets to detect weak entropy directly. Unlukey provides the research + datasets. We’re looking for wallet teams interested in integrating.
3
299
If wallets collaborate, we can get ahead of attackers and warn users affected by weak wallet-generation bugs. Simple: Unlukey does the research and distributes datasets of known weak pre-BIP39 entropy output for wallets to check locally.
Unlukey now has a public repository and client SDK: github.com/coinspect/unlukey The goal is simple: make detection of known weak seeds something wallets can add with one integration.
217
Unlukey now has a public repository and client SDK: github.com/coinspect/unlukey The goal is simple: make detection of known weak seeds something wallets can add with one integration.
Researching weak wallet generation incidents we found that even when we could identify affected addresses, we had no way to warn the users who were using them. Unlukey turns each known weak generation code into datasets that wallets can use to identify and warn users: coinspect.com/blog/introduci…
2
2
5
1,349
Wallets can integrate it to detect recovery phrases generated by known weak seed-generation vulnerabilities. Checks run client-side. Secrets never leave the device.
1
89
Researching weak wallet generation incidents we found that even when we could identify affected addresses, we had no way to warn the users who were using them. Unlukey turns each known weak generation code into datasets that wallets can use to identify and warn users: coinspect.com/blog/introduci…
4
8
1,850
We simplified Unlukey. Instead of precomputing billions of addresses (BIP39) from weak seed-generation vulnerabilities, we want wallets to detect weak entropy directly. Unlukey provides the research + datasets. We’re looking for wallet teams interested in integrating.
Today we’re releasing Unlukey🎲 a free, public tool to identify wallet addresses generated from weak seed phrases. The goal is simple: help users detect vulnerable wallets before attackers do. 🧵
2
5
798
None of those 45 wallets are in Coinspect's Wallet Security Ranking.
I was able to decompile and analyse 494 wallets on the AppStore. I found 45 apps that raised red flags for me during my research. I looked specifically for 2 things: private keys exfiltration and weak entropy.
2
1
4
1,284
After researching wallet-generation vulnerabilities like Ill Bloom and Coldcard, we started asking: For the next weak wallet-generation vulnerability, how can we warn affected users before an attacker finds their funds?
3
6
1,096
Coinspect Security retweeted
Huge congrats to @ambire for breaking into the Top 3 of our latest Wallet Security Ranking! 🏆 You’re doing a phenomenal job. The progress is clear, the improvements really show, and this result is well deserved. Congrats to the whole team! 👏
6
18
247