Crypto users lost at least $5.69 million because their wallet seeds were too predictable

1 hour ago 2



A flaw in software used by at least five crypto wallets made some recovery phrases predictable enough for attackers to reconstruct, contributing to at least $5.69 million in traced thefts since May.Earlier this month, blockchain security firm Coinspect said RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo used a weak random-number generator from the CryptoJS library to create some crypto wallet recovery phrases.According to the security firm:“The vulnerable implementation was introduced in June 2014 as part of an attempt to strengthen WordArray.random() in response to GitHub issue #7, “randomBytes is not random enough”, and was implemented in commit ff1f003.”Malicious attackers have targeted this vulnerability across multiple attack waves, with Coinspect tracing about $3.14 million drained on May 27 and another $2.55 million between May 30 and July 13.The firm also stated that the attack had a third wave between July 20 and 21, which drained around $40,000 across the Chinese-mnemonic subset.Cumulatively, the security firm's analysis covered more than 2,000 seeds with activity across Bitcoin, Ethereum, Tron, Rootstock, and Polygon, making the $5.69 million figure a lower bound...

Read Entire Article