Crypto news report · source clearly identified
Predictable Wallet Recovery Phrases Lead to $5.69 Million in Theft
A weak random‑number generator in the CryptoJS library caused recovery phrases for several wallets to be predictable, enabling attackers to steal at least $5.69 million across multiple blockchains.

A vulnerability in the random‑number generator used by several cryptocurrency wallets allowed attackers to reconstruct recovery phrases and steal funds. Blockchain security firm Coinspect traced at least $5.69 million in losses since May.
Vulnerable wallets and the technical flaw
Coinspect identified five wallets—RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo—as using a weakened CryptoJS WordArray.random() function. The flawed implementation, introduced in June 2014, reduced the effective entropy of generated phrases from the expected 2^128‑2^256 range to roughly 2^39‑2^47, making enumeration feasible.
Timeline of thefts
- May 27: $3.14 million drained.
- May 30 – July 13: $2.55 million drained.
- July 20 – 21: about $40,000 drained from addresses using a Chinese‑mnemonic subset.
The analysis covered more than 2,000 seeds with activity on Bitcoin, Ethereum, Tron, Rootstock and Polygon, so the $5.69 million figure is a lower bound.
Impact and remediation
Because the weakness lies in the seed generation process, updating the app does not secure already‑generated phrases. Users must create a new recovery phrase with a secure generator and transfer their funds. Coinspect released a tool called Unlukey to let users check whether addresses derived from their phrases appear in known exposed datasets.
Vendor responses
- Bexo Wallet fixed the issue in version 20.1.0.
- NanChat fixed it in version 1.3.0 and advised pre‑1.3.0 users to migrate.
- Bitcoin Libre fixed it in version 4.
- RRWallet and Milo have been discontinued.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- August 27, 2026, 2:40 PM
- Original headline
- Crypto users lost at least $5.69 million because their wallet seeds were too predictable