hacker-news · Crawled Aug 6, 2026

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

1 IoCs
Read original article ↗

AI Summary

A weak random number generator in the CryptoJS library, specifically CryptoJS.lib.WordArray.random(), was exploited to compromise cryptocurrency wallet recovery phrases, leading to the theft of approximately $5.7 million across two attack waves. The vulnerability affected five wallet applications—RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo—where weak entropy reduced the effective search space for recovery phrases from 2^128 or 2^256 down to roughly 2^39 or 2^47, making them brute-forceable. The flaw was exploited in attacks between May and July 2026, with stolen funds traced across Bitcoin, Ethereum, Tron, Rootstock, and Polygon blockchains. The issue stems from a regression in CryptoJS versions prior to 4.0.0, where a previously fixed issue was reintroduced in version 3.3.0 due to backward compatibility concerns.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo ferrumnet/bip39 Details →