CryptoJS Library Flaw Exposes Wallet Users to Estimated $5.7 Million Loss
A flaw in the CryptoJS library has led to an estimated $5.7 million in losses across five crypto wallet applications, according to security firm Coinspect.
The issue lies in the lib.WordArray.random() function, which was introduced 12 years ago and affects wallet apps used to generate recovery phrases.
Coinspect's analysis puts the measured theft at a lower bound of $5.7 million across two sweeps since late May, with losses estimated to run into the thousands.