Predictable Wallet Seeds Cost Users at Least $5.69m
A weak random number generator from a 2014 library commit made recovery phrases in five wallets reconstructable. Attackers found them.

A flaw in shared software made some crypto recovery phrases predictable enough for attackers to reconstruct, contributing to at least $5.69m in traced thefts since May.
The blockchain security firm Coinspect found that RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo all used a weak random number generator from the CryptoJS library to generate some recovery phrases.
A twelve-year-old fix that broke things
The origin is documented precisely. "The vulnerable implementation was introduced in June 2014 as part of an attempt to strengthen WordArray.random() in response to GitHub issue #7, 'randomBytes is not random enough'," Coinspect wrote.
The change was made to improve randomness. It made it worse, and sat in a widely used library for over a decade.
The waves
Attackers exploited it repeatedly. Coinspect traced about $3.14m drained on 27 May, another $2.55m between 30 May and 13 July, and a third wave on 20-21 July that took roughly $40,000 across a subset using Chinese-language mnemonics.
The analysis covered more than 2,000 seeds with activity across Bitcoin, Ethereum, Tron, Rootstock and Polygon.
Why this failure mode is the worst one
A seed phrase is the entire security model of a self-custody wallet. If the randomness behind it is weak, every other protection is decorative — the passphrase, the hardware, the backup regime, none of it matters, and nothing the user did wrong or right affects the outcome.
It is also silent. There is no way to look at twelve words and tell whether they came from a good source of entropy, which is why the affected users had no signal until the funds moved.
More from peatpost

Ledger Says It Wasn't Hacked. A Rival Reproduced the Bug Anyway.
OneKey's security team recreated a transaction-replacement attack against an outdated version of Ledger's Ethereum app.

Morgan Stanley's Fund Led Solana ETF Inflows as SOL Passed $100
MSOL took 60% of a $9.1m day, extending a run that included the category's largest single session of the year.

Bitcoin's Bottom Signal Is Flashing. The Data Says Don't Rush.
VanEck's capitulation dashboard lit up — and its own history shows those clusters underperformed over the following three and six months.
Discussion
0 commentsNo comments yet — be the first to weigh in.