Cryptocurrency Wallets Hit by 12-Year-Old Software Flaw Worth $5.69 Million
A vulnerability in software used by at least five cryptocurrency wallets has led to significant losses for users. The flaw, which was introduced in June 2014, made some recovery phrases predictable enough for attackers to reconstruct.
According to blockchain security firm Coinspect, the vulnerable implementation was part of an attempt to strengthen a random-number generator from the CryptoJS library. This weakness allowed malicious attackers to target multiple wallets across various attack waves.
Cumulatively, the security firm's analysis covered more than 2,000 seeds with activity across Bitcoin, Ethereum, Tron, Rootstock, and Polygon. The total losses attributed to this vulnerability are estimated at $5.69 million.
The affected crypto wallets list may not be exhaustive, as exposure depends on the software version that originally generated the phrase rather than the brand alone.