A software flaw that made some cryptocurrency wallet recovery phrases predictable may have enabled thieves to steal at least $5.69 million, according to an analysis cited by CryptoSlate on August 27. The issue is tied to wallet software that relied on a weak random number generator in the CryptoJS library.
Coinspect, a blockchain security firm, said the vulnerability appears to have affected more than 2,000 seed phrases across five blockchain networks. The firm said at least five wallet apps generated recovery phrases in a way that could be predicted, though the specific apps have not been publicly confirmed.
Weak randomness at the center of the issue
Coinspect traced the problem to the random number generator used in CryptoJS, a software library employed in some wallet applications. According to the firm, that weakness reduced the unpredictability expected in seed phrase generation, creating conditions in which recovery phrases could be guessed by attackers.
Seed phrases are meant to serve as the master backup for a crypto wallet. If those phrases become predictable, anyone able to derive them can potentially restore the wallet and move its assets without needing direct access to the original device.
Multiple waves of theft were identified
Coinspect said the vulnerability was likely exploited on several occasions rather than in a single incident. In its analysis, the firm tracked roughly $3.14 million in stolen funds on May 27.
It also identified another $2.55 million drained between May 30 and July 13. A further attack on July 20 and July 21 led to approximately $40,000 in additional losses, which appeared to be counted separately from the minimum $5.69 million total cited in the analysis.
Scope remains incomplete
The security firm said more than 2,000 seed phrases appear to have been exposed across five blockchain networks. Even so, the known figures may not represent the full extent of the damage.
Coinspect said the wallet apps affected have not yet been confirmed publicly, and the total losses also remain unconfirmed. That leaves open the possibility that additional compromised wallets or thefts could still be identified as the investigation continues.
What is confirmed so far
At this stage, the clearest confirmed findings are the software weakness identified by Coinspect, the estimate of more than 2,000 affected seed phrases, and the traced thefts totaling at least $5.69 million, with an extra roughly $40,000 reported from a later attack window.
The next key step will be confirmation of which wallet applications used the vulnerable implementation and whether the eventual loss tally rises beyond the amounts already tracked by the firm.
Source: en.bloomingbit.io