Stealing Bitcoin with Math
speakerdeck.com
speakerdeck.com
It should no longer be the case that platform vendors are able to abrogate responsibility for bad RNGs or RNG bugs. The stakes are too high for people to get it wrong. Even in 2016 we're still seeing repeats of browsers and OS's with "predictable random number generator" bugs even though we have a pretty clear handle in the literature for how to do it well.
The commit that fixed the issue: https://github.com/bitcoinjs/bitcoinjs-lib/commit/bc37e65014...
The issue itself was that a `Buffer` was being interpreted as `0` by crypto-js's cryptographic hash functions in our implementation of RFC6979, thus creating a case of duplicate `k` values.
The second most interesting point was the majority of the funds (>20k USD) stolen from Counterparty (the only known users of our master branch at that time) was returned by a grey hat.
Bitcoin's classification in the US means that it's SUPPOSED to be subject to all the scrutiny and protections that convertible currencies are supposed to have, although I can't speak to the regulation of that.
That's a question of intent and reasonable interpretation. I'm fairly sure "I didn't audit the browser PRNG," will not be looked upon by any court you can name as a reasonable thing to expect people to do.