Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Scalar-Venom-Attack — Exploit and research repository analyzing CVE-2025-60013, a critical HSM initialization vulnerability enabling Bitcoin private key recovery via buffer overflow and shell metacharacter injection in F5OS-A FIPS modules. | Kitploit
Tools/GitHubGitHub/demining/scalar-venom-attack
Memory ForensicsVulnerability AnalysisExploitationForensicsDigital ForensicsCryptographyPenetration TestingHardware SecurityPapers & Research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning & Education
Binary Exploitation
GitHubdemining/scalar-venom-attack

Scalar-Venom-Attack

Exploit and research repository analyzing CVE-2025-60013, a critical HSM initialization vulnerability enabling Bitcoin private key recovery via buffer overflow and shell metacharacter injection in F5OS-A FIPS modules.

View RepositoryWebsite
31610 months agoNot yet reviewed
Scalar Venom Attack: A critical HSM initialization vulnerability (CVE-2025-60013) allows for Bitcoin wallet private key recovery via a buffer overflow and shell metacharacters in the F5OS-A FIPS security module.

This paper analyzes cryptographic vulnerabilities discovered in modern cryptographic key management infrastructure, with a particular focus on critical flaws in the architecture of hardware security modules (HSMs) when handling elliptic curve private keys. The study focuses on a class of attacks that exploit insufficiently isolated RAM management in certified cryptographic devices. In the modern Bitcoin cryptographic ecosystem, private key security is a fundamental requirement for protecting digital assets worth trillions of dollars globally. Hardware Security Modules (HSMs) certified to the FIPS 140-2 standard have traditionally been considered to provide impenetrable protection for cryptographic keys through hardware-level isolation and strict memory management protocols. However, the discovery of the critical vulnerability CVE-2025-60013 in the F5OS-A FIPS HSM module, combined with the Scalar Venom Attack class of attacks (also known as Scalar Poison, Memory Phantom Leak Attack, or Private Key Compromise via Memory Leakage), has radically changed this notion, demonstrating the possibility of completely compromising Bitcoin private keys through the exploitation of memory management flaws.


  • Tutorial: https://youtu.be/cvWLH5dvbAA
  • Tutorial: https://cryptodeeptech.ru/scalar-venom-attack
  • Tutorial: https://dzen.ru/video/watch/691a7a10a8b7c874612993eb
  • Google Colab: https://colab.research.google.com/drive/1e93p7gxpTtfMU2L83w7I1tRDJQ1tENYa

The Scalar Venom Attack is a critical class of memory management vulnerabilities (classified as CWE-415, CWE-401, and more broadly as a Sensitive Memory Leak Attack (SMA)) that allows an attacker to extract cryptographic scalars (ECDSA private keys) from a process’s RAM by exploiting insufficient sanitization and memory scrubbing after cryptographic operations. Unlike traditional cryptanalytic attacks aimed at mathematically solving the elliptic curve discrete logarithm problem (ECDLP), this attack bypasses cryptography itself by exploiting fundamental architectural flaws in the implementation of cryptographic libraries and HSM memory management protocols.

This research demonstrates a catastrophic attack chain that occurs when combining CVE-2025-60013 ( F5OS-A FIPS HSM initialization vulnerability when using passwords containing special shell metacharacters) with Scalar Venom Attack techniques , resulting in a critical threat scenario with a CVSS score of 9.5+ (Critical), despite CVE-2025-60013’s official rating as a medium-level vulnerability (CVSS 5.7). This combination undermines the operational integrity of millions of Bitcoin addresses controlled by compromised HSMs and represents a paradigm shift in cryptographic attack methods beyond traditional single-vector exploits.


Scalar Venom Attack: A critical HSM initialization vulnerability (CVE-2025-60013) enables private Bitcoin wallet key recovery through buffer overflow exploitation and shell metacharacters in the F5OS-A FIPS security module


CVE classification and vulnerability descriptions

CVE-2025-60013: F5OS-A FIPS HSM Initialization Vulnerability

CVE-2025-60013 is an OS Command Injection vulnerability (classified as CWE-78) during the initialization process of the FIPS Hardware Security Module for F5 platforms. The vulnerability occurs when a user with privileged access (Admin or Resource Admin role) attempts to initialize the FIPS HSM module using a password containing special shell metacharacters, such as [unclear], [unclear ;] |, &[ $unclear], `and others.

Technical mechanism of vulnerability:

When processing a password containing shell metacharacters, the HSM initialization code passes the password string to system C library functions without properly validating and sanitizing the input. The vulnerable code looks like this:

// Vulnerable code in HSM initialization procedure
void hsm_initialize(const char* password) {
ec_secret master_key; // HSM private key
char temp_buffer[256];
strcpy(temp_buffer, password); // VULNERABILITY: buffer overflow + shell interpretation
derive_key_from_password(master_key, password); // creates copies of key
// If initialization fails, memory is not cleared!
// master_key remains in the stack, its copies—in heap
}

Critical consequence: The initialization process remains in memory with partially compromised cryptographic structures, creating multiple “phantom” copies of the HSM master key in the stack and heap. Although the HSM may not initialize correctly, the process’s memory contains cryptographic artifacts accessible to forensic analysis.

Official classification:

  • CVSS 3.1: AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L (base score: 5.7 — MEDIUM)
Download Tool