Crypto news report · source clearly identified

Predictable Wallet Recovery Phrases Lead to $5.69 Million in Theft

A weak random‑number generator in the CryptoJS library caused recovery phrases for several wallets to be predictable, enabling attackers to steal at least $5.69 million across multiple blockchains.

A vulnerability in the random‑number generator used by several cryptocurrency wallets allowed attackers to reconstruct recovery phrases and steal funds. Blockchain security firm Coinspect traced at least $5.69 million in losses since May.

Vulnerable wallets and the technical flaw

Coinspect identified five wallets—RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo—as using a weakened CryptoJS WordArray.random() function. The flawed implementation, introduced in June 2014, reduced the effective entropy of generated phrases from the expected 2^128‑2^256 range to roughly 2^39‑2^47, making enumeration feasible.

Timeline of thefts

  • May 27: $3.14 million drained.
  • May 30 – July 13: $2.55 million drained.
  • July 20 – 21: about $40,000 drained from addresses using a Chinese‑mnemonic subset.

The analysis covered more than 2,000 seeds with activity on Bitcoin, Ethereum, Tron, Rootstock and Polygon, so the $5.69 million figure is a lower bound.

Impact and remediation

Because the weakness lies in the seed generation process, updating the app does not secure already‑generated phrases. Users must create a new recovery phrase with a secure generator and transfer their funds. Coinspect released a tool called Unlukey to let users check whether addresses derived from their phrases appear in known exposed datasets.

Vendor responses

  • Bexo Wallet fixed the issue in version 20.1.0.
  • NanChat fixed it in version 1.3.0 and advised pre‑1.3.0 users to migrate.
  • Bitcoin Libre fixed it in version 4.
  • RRWallet and Milo have been discontinued.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
August 27, 2026, 2:40 PM
Original headline
Crypto users lost at least $5.69 million because their wallet seeds were too predictable
View original report ↗