CryptoJS Weak Random Number Generator Leads to $5.7M Loss in Five Crypto Wallets
A vulnerability in the CryptoJS library's weak random number generator (RNG) enabled attackers to drain over $5.7 million from five crypto wallet apps by exploiting predictable recovery phrases. The flaw, traced to the CryptoJS.lib.WordArray.random() function, was partially fixed but later reverted, leaving users exposed until version 4.0.0.
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.
Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of
*** END OF TRANSMISSION ***