Interestana
Home/News/Crypto Wallet Drain Linked to Weak CryptoJS RNG
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Crypto Wallet Drain Linked to Weak CryptoJS RNG

Crypto Wallet Drain Linked to Weak CryptoJS RNG

A critical vulnerability within the JavaScript cryptography library CryptoJS, specifically in its `CryptoJS.lib.WordArray.random()` function, has been identified as the root cause behind approximately $5.7 million in cryptocurrency drains. Security firm Coinspect revealed this finding, detailing how the weak random number generator (RNG) function, present in the library for the past 12 years, supplied insufficient entropy. This deficiency led to predictable recovery phrases being generated by affected wallet applications, thereby enabling attackers to compromise user funds. Coinspect's on-chain analysis indicates that the total theft, observed across two distinct draining events since late May, has a lower bound of $5.7 million. The vulnerability impacted at least five distinct cryptocurrency wallet applications that relied on this specific RNG function for generating their users' seed phrases or recovery keys. The compromised function, `CryptoJS.lib.WordArray.random()`, is a core component for generating random data, which is essential for cryptographic security, particularly in the creation of private keys and recovery phrases. When this function fails to produce truly random numbers, it creates predictable patterns that can be exploited. The attackers were able to leverage these predictable patterns to derive the private keys associated with user wallets. The implications of this vulnerability are significant, as it highlights a fundamental flaw in a widely used cryptographic library that has been present for over a decade. The fact that this issue remained undetected and unaddressed for so long underscores the persistent challenges in securing software, especially within the rapidly evolving cryptocurrency ecosystem. The affected applications, by using an outdated or flawed RNG implementation, inadvertently exposed their users to substantial financial risk. The security firm Coinspect's detailed analysis involved tracing transactions on the blockchain to quantify the extent of the losses and identify the pattern of exploitation. The vulnerability's longevity suggests that a broad range of users and applications might have been exposed, even if the full extent of the damage is still being uncovered. The incident serves as a stark reminder for developers and users in the crypto space to rigorously audit their dependencies and ensure that all cryptographic functions are up-to-date and employ robust, well-vetted random number generation techniques. The $5.7 million figure represents a conservative estimate, and further investigation may reveal additional losses. The reliance on a single, flawed RNG function across multiple applications points to a systemic issue within the development practices of some crypto wallet providers. This event is likely to prompt increased scrutiny of the security practices and codebases of cryptocurrency wallet providers and the underlying libraries they utilize.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next