Predictable Wallet Seeds Exposed: Crypto Users Lose Millions
A software flaw has led to at least $5.69 million in losses for cryptocurrency users whose wallet seeds were generated using a weak random-number generator.
The vulnerability was identified by blockchain security firm Coinspect, which found that five crypto wallets - RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo - used the CryptoJS library to create recovery phrases with predictable patterns.
This made it possible for attackers to reconstruct wallet secrets and drain funds. The first wave of attacks occurred on May 27, resulting in $3.14 million drained, followed by another wave between May 30 and July 13, which saw $2.55 million lost.
The security firm also detected a third wave between July 20 and 21, draining around $40,000 from the Chinese-mnemonic subset. Cumulatively, Coinspect's analysis covered more than 2,000 seeds across various cryptocurrencies, including Bitcoin, Ethereum, Tron, Rootstock, and Polygon.