CyberSecurity News
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
AI summary
A weak random number generator in the CryptoJS library has been linked to the theft of at least $5.7 million from users of five crypto wallet apps. The vulnerable function, CryptoJS.lib.WordArray.random(), was introduced 12 years ago and generated weak entropy, affecting the creation of recovery phrases. This weakness has been identified by Coinspect as the cause of the Ill Bloom wallet drains. Coinspect's analysis of on-chain data has tracked the thefts, which occurred in two sweeps starting in late May. The affected wallet apps relied on the flawed CryptoJS library, resulting in compromised recovery phrases. The total loss is estimated to be at least $5.7 million.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

