How Cake Wallet’s Broken Seed Generator Got My Bitcoin Stolen

This happened in May 2021. For years, I believed something had gone wrong during a Bitcoin-to-Monero exchange. Only now, after investigating Cake Wallet’s historical source code, analysing the blockchain transaction and checking independent vulnerability research, have I finally discovered what really happened.

On 24 May 2021, 0.02 BTC was stolen from my Cake Wallet immediately after it arrived. Cake later promised compensation, but never paid.

The evidence now leaves almost no room for doubt: Cake generated my 12-word Bitcoin seed using a catastrophically weak random-number generator. Someone reconstructed my private key, monitored my wallet and swept the deposit.

What happened

I mainly used Cake for Monero. On 10 May 2021, I successfully exchanged 0.042 BTC to XMR and switched back to my XMR wallet.

Cake’s security warning appeared only when the vulnerable BTC wallet was active. While using XMR, I received no warning.

On 24 May, I transferred 0.02 BTC to my Cake address: bc1qfn7hukuer8ym4uhrh9edrkexae6yz2q93ck8as

After opening the BTC wallet, I finally saw Cake’s warning. I immediately tried to secure the funds by exchanging them to XMR.

Cake created ChangeNOW order 885358134a16cf. The correct ChangeNOW deposit address was: 3NR3gNJgM35qJ3SArfpBAuGGa11D2181Ty

ChangeNOW never received the funds. Instead, 0.0199 BTC was swept to: bc1q570kz3cf7540ph3azsd77x2n7tfle3reulat55

Transaction:

7baeee179e4322f4795ae2bbb0d1265c80a6179bbc77760d1226495e92707d27

The bottom three transactions under “Yesterday”: I received 0.02 BTC, but 0.0199 BTC was stolen before the exchange to XMR could be completed.
…aaaand it’s gone!

Cake created a guessable private key

Cake’s vulnerable releases generated 12-word Bitcoin seeds with Dart’s insecure Random() function instead of a cryptographically secure generator.

Independent researchers later proved that Cake’s implementation produced only about 1,049,308 possible valid seeds. That is not meaningful wallet security. It is an enumerable list of private keys.

My address bc1qfn7… appears in the researchers’ published dataset of wallets generated by Cake’s broken code. My original seed also reproduces the address at Cake’s exact historical derivation path.

There is no longer serious doubt that Cake generated my wallet with the known vulnerability.

The theft scenario

My deposit confirmed in block 684762 at 12:59 CEST. Minutes later, while I was trying to exchange it to XMR, someone swept it. The theft confirmed in the next block.

The stealing transaction is version 2 and uses block 684762 as its locktime. That matches Electrum’s transaction behaviour in 2021. Cake’s own transaction builder created version-1 transactions without that locktime.

The logical conclusion is:

  1. Someone enumerated Cake’s weak seeds and reconstructed mine.
  2. They monitored my address.
  3. When the deposit confirmed, they used the recovered key to sweep it.
  4. Cake merely detected the external transaction and displayed it as “Sent.”
  5. My ChangeNOW order remained unpaid.

The destination is not part of my wallet. Extensive offline derivation tests confirm that my seed does not control it. The stolen BTC remains unspent there today.

Cake’s warning was inadequate and too late

Cake disclosed the vulnerability shortly before my loss, but its response was nowhere near proportionate to the danger.

The app should have said:

Your private key is predictable and is already known to attackers. Do not deposit Bitcoin, move all funds NOW!

Instead, Cake displayed a vague migration message only after opening the affected BTC wallet.

Cake continued showing compromised deposit addresses. It did not block incoming payments, disable exchanges, force migration or display an app-wide warning while users had another wallet active.

I first saw the warning after making the deposit. I immediately attempted to move the BTC to XMR, but an attacker monitoring Cake’s predictable key was already faster.

Cake promised compensation

I reported everything to Cake support on 27 May 2021. My original report already documented that the warning did not appear while my XMR wallet was active and that I saw it only after depositing the BTC.

Cake later promised compensation. That compensation never arrived.

This was not caused by me exposing my seed. It was not a failed ChangeNOW conversion. Cake generated a private key that outsiders could calculate.

Cake created the vulnerability, failed to warn me before accepting another deposit into the compromised wallet, and never honoured its compensation promise.

That is why I hold Cake Wallet responsible for the loss.

Evidence

Leave a Reply

Your email address will not be published. Required fields are marked *