CVE-2025-65849 Details
Description
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via mathematical deduction. NOTE: this is disputed by the Supplier because the product's objective is "to discourage automated scraping / bots, not guarantee resistance to determined attackers." The documentation states “the goal is not to provide a secure cryptographic algorithm but to use a proof-of-work mechanism that allows any capable device to decrypt the hidden data.”
A cryptanalytic vulnerability has been identified in Altcha's Proof-of-Work obfuscation mode, affecting version 0.8.0 and later. This vulnerability allows remote users to recover the Proof-of-Work nonce in constant time through mathematical deduction. The issue arises from the improper use of symmetric encryption, which exposes secret information in a non-confidential manner, creating a total break in the obfuscation scheme.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 8, 2025CISA-ADP
Assessed Dec 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://altcha.org/docs/v2/obfuscation/ | [email protected] | Vendor |
| https://github.com/altcha-org/altcha/blob/154f874cbcdd4e639783463130d13988a2bd1bdc/src/helpers.ts#L170-L194 | [email protected] | Source CodeVendor |
| https://github.com/eternal-flame-AD/altcha-deobfs | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Altcha | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 11, 2025 | CVE Modified | [email protected] |
| Dec 11, 2025 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | New CVE Received | [email protected] |
Volerion