Share this article

Developers find Android flaw that makes bitcoin wallets vulnerable to theft

An Android flaw is compromising all wallets running on Google's mobile platform. Here's what to do.

Updated Sep 10, 2021, 11:28 a.m. Published Aug 11, 2013, 10:46 p.m.
Android mobile

Android wallet users were sent into a panic over the weekend, after Google discovered a flaw in its mobile operating system that rendered generated bitcoin addresses unsafe.

According to Mike Hearn

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

, the forum contributor who reported the bug, the way in which random numbers are generated in Android is flawed. Random numbers are used along with a private key to sign a transaction when sending from a bitcoin address. The flaw means that any random number used more than once with the same public bitcoin address enables that address to be compromised.

This problem will affect any Android-based bitcoin wallet user who has used a bitcoin address more than once. It means that a person could recover that user’s private signature by analyzing the transaction in the block chain, enabling them to spend bitcoins from that address.

If you have used the same random number more than once with the same bitcoin address when sending from an Android wallet, your bitcoins are in danger.

The solution is to generate a new bitcoin address using a repaired version of the random number generator, and then to send all your money in your wallet back to yourself, according to Bitcoin.org. However, this relies on getting an updated version of your Android wallet if you're still going to use an Android-based app.

A report from Hearn suggests that an update of Andreas Schildbach’s Bitcoin Wallet has been prepared and is undergoing testing (a manual install is available via this forum posting for bitcoin users).

BitcoinSpinner

is preparing an update, as is Mycelium Wallet. Blockchain.info has released an update, according to Hearn, which allows users to manually rotate keys. Another update in the next few days will automatically send all coins controlled by previous keys to the new one.

In the meantime, however, bitcoins are reportedly being stolen from compromised addresses. Over 55 bitcoins are said to have been sent to this address from compromised addresses.

The upshot of all this is that bitcoin users will learn something: never use the same bitcoin address twice. We have always known that not reusing addresses makes you less trackable online. It is also a way to protect against exploits such as these, which aren’t a fault of the bitcoin network at all, but are rather down to a flaw in a platform supporting third-party bitcoin wallet services.

It’s also worthwhile transferring coins from an online bitcoin address to a ‘cold’ offline wallet, leaving just enough coins in your hot wallet to cover basic transactions.

Finally, once your bitcoins have been transferred to the new, safe address, back up your wallet.

Image credit: Flickr / pittaya

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Coinbase Reopens India Signups, Targets Fiat On-Ramp in 2026 After Two-Year Freeze

Coinbase (appshunter.io/Unsplash/Modified by CoinDesk)

Coinbase halted services entirely in 2023, off-boarded millions of Indian users and shuttered local access while reassessing regulatory exposure.

What to know:

  • Coinbase has resumed onboarding users in India, marking its return to the market after a two-year hiatus due to regulatory issues.
  • The exchange is currently allowing crypto-to-crypto trading and plans to reintroduce fiat on-ramps next year.
  • Despite regulatory challenges, Coinbase is investing in India, including increasing its stake in local exchange CoinDCX.