imToken has released a security statement addressing concerns about the randomness of non-custodial wallet private keys, sparked by recent US law enforcement news. Officials stated that users of the imToken software wallet and imKey hardware wallet are unaffected.
The statement noted that the imToken software wallet generates private keys locally using a secure random number source on iOS and Android. Its core codebase, TokenCore, has been open source and auditable since 2018, and private keys are never transmitted over the internet. The imKey hardware wallet uses a true random number generator (TRNG) within its secure chip to generate mnemonics and private keys. imToken emphasized that both products are non-custodial and do not store user private keys or mnemonics. Users are reminded to properly back up their mnemonics.
