Crypto Heists: Weak Random Number Generator Exposed, macOS Stealer Uncovered
A recently discovered outdated random number generator in several cryptocurrency wallets has led to an estimated $5.7 million in theft. The issue lies in the CryptoJS.lib.WordArray.random() function, which was written over 12 years ago and produces weak entropy that can be easily brute-forced by attackers.
The vulnerable code affected at least five crypto wallets: NanChat, Bitcoin Libre, Bexo Wallet, RRWallet, and Milo. Coinspect analysts reported two waves of attacks, with the first wave occurring on May 27 and the second from May 30 to July 13, resulting in losses of $3.14 million and $2.55 million respectively.
Meanwhile, a new macOS infostealer has been discovered, which spreads via phishing emails and exfiltrates system passwords and Apple Keychain data. The malware can also intercept and modify transactions in various cryptocurrencies before they are signed, allowing attackers to quietly divert a percentage of funds to their own address.