threat-intel
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
High
Summary
A vulnerability in the CryptoJS library's random number generator has led to approximately $5.7 million in cryptocurrency drains affecting five wallet applications. Coinspect discovered that the weak random number generator, used to create recovery phrases, allowed attackers to predict these phrases and steal funds. While some wallets have been patched, users of older versions with compromised recovery phrases need to create new ones and migrate their funds. The issue was exploited in two waves, impacting thousands of wallets across multiple blockchains.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
