discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

A vulnerability in the CryptoJS library's random number generator has been identified as the cause of $5.7 million in losses from five crypto wallet apps. The issue affects recovery phrase generation and has been fixed in some apps, but users are advised to create new phr…

By Swati Khandelwal·Aug 6·thehackernews.com·2 min read

Intelligence analysis by Llama

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Image: thehackernews.com

A weakness in the CryptoJS library's random number generator has led to $5.7 million in losses from five crypto wallet apps. The issue affects recovery phrase generation and has been fixed in some apps, but users are advised to take action to protect their funds.

Why it matters

This story matters to anyone following the security of crypto wallets and the potential risks of using vulnerable software. The issue highlights the importance of regular updates and security patches to protect user funds.

Imagine you have a super-long password to keep your money safe. But, if someone knows how you made that password, they can guess it easily. That's what happened with some crypto wallet apps. They used a weak password generator that made it easy for hackers to guess the password and steal the money. Now, the apps have fixed the problem, but users need to create new, stronger passwords to keep their money safe.

Analysis

Background

The issue was identified by Coinspect, a blockchain security firm, as a weakness in the CryptoJS library's random number generator. The library, which is used in many crypto wallet apps, was found to be vulnerable to attacks that could compromise user funds.

The Vulnerability

The vulnerability was introduced in the CryptoJS library 12 years ago and was not addressed until recently. The issue affects recovery phrase generation, which is used to create unique and secure phrases for users to access their funds. The vulnerable generator reduced the search space of 2^128 and 2^256 to roughly 2^39 and 2^47, making it possible to enumerate and compromise user funds.

Affected Wallets

Coinspect identified five crypto wallet apps that were affected by the vulnerability: RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo. The firm found that these apps used the vulnerable generator to create recovery phrases, which were then used to access user funds. The affected apps have since been fixed, but users are advised to create new phrases securely and move their funds.

Impact

The vulnerability has led to $5.7 million in losses from the affected wallets. The issue highlights the importance of regular updates and security patches to protect user funds. Coinspect's analysis found that the affected population runs into the thousands across Ethereum Virtual Machine (EVM)-compatible networks and Bitcoin, but did not provide a wallet-by-wallet breakdown.

Response

Coinspect has published a public advisory and a checker that accepts wallet addresses to identify affected users. The firm has also notified vendors and searched for exposed addresses. The affected apps have since been fixed, but users are advised to take action to protect their funds.

Key points

  • A vulnerability in the CryptoJS library's random number generator has been identified as the cause of $5.7 million in losses from five crypto wallet apps.
  • The issue affects recovery phrase generation and has been fixed in some apps, but users are advised to create new phrases securely and move their funds.
  • Coinspect has published a public advisory and a checker that accepts wallet addresses to identify affected users.
  • The affected apps have since been fixed, but users are advised to take action to protect their funds.
The Upside

The fact that the affected apps have been fixed and users are being advised to take action to protect their funds is a positive development. Additionally, the public disclosure of the vulnerability and the publication of a public advisory by Coinspect demonstrate a commitment to transparency and security.

The Downside

The fact that the vulnerability was not addressed for 12 years and affected thousands of users is a concerning development. The potential for further attacks and losses remains a risk until all affected users have taken action to protect their funds.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecurityvulnerabilityblockchainwallets

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 6, 2026

Source

thehackernews.com

Share

Topics

cryptosecurityvulnerabilityblockchainwallets

Related

More from this desk

Aug 6·bleepingcomputer.com

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

A browser security gap has been exposed by AI, which enterprises cannot ignore. This gap is a result of employees moving sensitive data through browser-based applications, and AI has accelerated the volume and visibility of these interactions.

Aug 6·thehackernews.com

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, …

Aug 6·schneier.com

Adversarial Clothing Designed to Fool Facial Recognition Systems

Companies are manufacturing adversarial clothing designed to confuse facial recognition systems, but the technology has not been thoroughly tested, and its effectiveness is uncertain.

Aug 6·thehackernews.com

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into …