Secrets — Crypto & Blockchain

Ethereum, Bitcoin and other blockchain private keys and wallet credentials.

All rules in this category are kind secrets. They run under vulnetix secrets and the secrets stage of vulnetix scan.

Rule IDNameSeverityDetection
VNX-SEC-652Bitcoin WIF private keyCriticalkeyword + regex
VNX-SEC-653BIP39 mnemonic seed phraseCriticalkeyword + regex
VNX-SEC-654Solana keypair byte arrayCriticalkeyword + regex
VNX-SEC-655Tron (TRX) private keyCriticalkeyword + regex
VNX-SEC-656Infura project IDMediumkeyword + regex + entropy
VNX-SEC-657Infura project secretHighkeyword + regex + entropy
VNX-SEC-658Alchemy auth token (alcht_)Highkeyword + regex
VNX-SEC-659Alchemy API keyHighkeyword + regex + entropy
VNX-SEC-660QuickNode API tokenHighkeyword + regex + entropy
VNX-SEC-661Moralis API keyHighkeyword + regex + entropy
VNX-SEC-662Etherscan API keyMediumkeyword + regex + entropy
VNX-SEC-663BscScan API keyMediumkeyword + regex + entropy
VNX-SEC-664PolygonScan API keyMediumkeyword + regex + entropy
VNX-SEC-665Blockchain.com API keyHighkeyword + regex
VNX-SEC-666Coinbase Wallet API secretCriticalkeyword + regex + entropy
VNX-SEC-667Binance API keyCriticalkeyword + regex + entropy
VNX-SEC-668Binance API secretCriticalkeyword + regex + entropy
VNX-SEC-669Kraken API keyCriticalkeyword + regex + entropy
VNX-SEC-670Kraken private API keyCriticalkeyword + regex + entropy
VNX-SEC-671Bitfinex API keyCriticalkeyword + regex + entropy
VNX-SEC-672Tatum API keyHighkeyword + regex
VNX-SEC-673thirdweb secret key (sk_)Highkeyword + regex + entropy
VNX-SEC-674WalletConnect project IDMediumkeyword + regex + entropy
VNX-SEC-698BscScan/Etherscan-family multichain key (V2)Mediumkeyword + regex + entropy
VNX-SEC-699Coinbase API key (organizations/ EC key name)Highkeyword + regex
VNX-SEC-700Ethereum keystore JSON (V3 wallet)Highkeyword + regex
VNX-SEC-706Bitcoin testnet WIF private keyMediumkeyword + regex
VNX-SEC-707Solana base58 secret keyCriticalkeyword + regex + entropy
VNX-SEC-708Helius API keyHighkeyword + regex
VNX-SEC-713OKX API passphraseCriticalkeyword + regex + entropy
VNX-SEC-714OKX API secretCriticalkeyword + regex + entropy
VNX-SEC-715Bybit API keyCriticalkeyword + regex + entropy
VNX-SEC-716Bybit API secretCriticalkeyword + regex + entropy
VNX-SEC-717Gemini exchange API key (account-/master-)Criticalkeyword + regex + entropy
VNX-SEC-718Dune Analytics API keyMediumkeyword + regex + entropy
VNX-SEC-719Pinata JWT (IPFS)Highkeyword + regex
VNX-SEC-724Coinbase Commerce API keyHighkeyword + regex
VNX-SEC-725Ankr API keyMediumkeyword + regex + entropy
VNX-SEC-733Bittrex/legacy exchange API secretHighkeyword + regex + entropy
VNX-SEC-734KuCoin API passphraseCriticalkeyword + regex + entropy
VNX-SEC-735CoinMarketCap API keyMediumkeyword + regex
VNX-SEC-981Coinbase CDP API key ID (organizations path)Highkeyword + regex
VNX-SEC-982Coinbase CDP EC private key (PEM, assignment)Criticalkeyword + regex + entropy
VNX-SEC-983Kraken API secret (base64 private key)Criticalkeyword + regex + entropy
VNX-SEC-984Gemini API secret (master/account secret)Criticalkeyword + regex + entropy
VNX-SEC-985KuCoin API keyHighkeyword + regex + entropy
VNX-SEC-986KuCoin API secret (UUID)Criticalkeyword + regex + entropy
VNX-SEC-987OKX API key (UUID)Highkeyword + regex + entropy
VNX-SEC-988Bitstamp API keyHighkeyword + regex + entropy
VNX-SEC-989Bitstamp API secretCriticalkeyword + regex + entropy
VNX-SEC-990Gate.io API keyHighkeyword + regex + entropy
VNX-SEC-991Gate.io API secretCriticalkeyword + regex + entropy
VNX-SEC-992Crypto.com Exchange API keyHighkeyword + regex + entropy
VNX-SEC-993Crypto.com Exchange API secretCriticalkeyword + regex + entropy
VNX-SEC-994Huobi/HTX API keyHighkeyword + regex + entropy
VNX-SEC-995Huobi/HTX secret keyCriticalkeyword + regex + entropy
VNX-SEC-996MEXC API keyHighkeyword + regex + entropy
VNX-SEC-997MEXC API secretCriticalkeyword + regex + entropy
VNX-SEC-998Deribit client IDHighkeyword + regex + entropy
VNX-SEC-999Deribit client secretCriticalkeyword + regex + entropy
VNX-SEC-1000dYdX API key (UUID)Highkeyword + regex + entropy
VNX-SEC-1001dYdX API secretCriticalkeyword + regex + entropy
VNX-SEC-1002Fireblocks API key (UUID)Criticalkeyword + regex + entropy
VNX-SEC-1003Fireblocks API secret (RSA private key)Criticalkeyword + regex + entropy
VNX-SEC-1004BitGo access token (v2x)Criticalkeyword + regex
VNX-SEC-1005Anchorage API key (assignment)Criticalkeyword + regex + entropy
VNX-SEC-1006Circle USDC API key (live)Criticalkeyword + regex
VNX-SEC-1007Chainalysis API key (assignment)Highkeyword + regex + entropy
VNX-SEC-1008TRM Labs API key (assignment)Highkeyword + regex + entropy
VNX-SEC-1009web3.storage API token (legacy JWT, assignment)Highkeyword + regex + entropy
VNX-SEC-1010Pinata API key (legacy, assignment)Highkeyword + regex + entropy
VNX-SEC-1011Pinata API secret (legacy, assignment)Criticalkeyword + regex + entropy
VNX-SEC-1012NFT.storage API token (JWT, assignment)Highkeyword + regex + entropy
VNX-SEC-1013Crossmint API key (server-side)Criticalkeyword + regex
VNX-SEC-1014Binance API secret (assignment, alt context)Criticalkeyword + regex + entropy
VNX-SEC-1015Bybit API secret (assignment, alt context)Criticalkeyword + regex + entropy
VNX-SEC-1016KuCoin API secret (passphrase-paired, alt context)Criticalkeyword + regex + entropy
VNX-SEC-1017Bitfinex API secret (assignment, alt context)Criticalkeyword + regex + entropy

Remediation

Rotate any exposed credential immediately, remove it from source, and load it from a secrets manager or environment variable instead. Purge it from git history with git filter-repo. See CWE-798 and the OWASP Secrets Management Cheat Sheet.