3 hours ago
Crypto users lose at least $5.69 million through predictable wallet seeds
Crypto users lost at least $5.69 million because their wallet seeds were too predictable
CryptoSlate

Crypto users lost at least $5.69 million in traced thefts after attackers reconstructed predictable wallet recovery phrases. Coinspect identified the flaw in RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo. The affected wallet list may not be exhaustive. Exposure depends on the software version that generated the phrase rather than the wallet brand alone. Coinspect traced about $3.14 million drained on May 27. Attackers drained another $2.55 million between May 30 and July 13. A third attack wave drained around $40,000 between July 20 and 21 from wallets using the Chinese-mnemonic subset. Coinspect's analysis covered more than 2,000 seeds. The activity involved Bitcoin, Ethereum, Tron, Rootstock, and Polygon. The $5.69 million figure is a lower bound on total losses. The wallets used a weak random-number generator from the CryptoJS library. The vulnerable implementation was introduced in June 2014. The weakness reduced search spaces expected to contain 2^128 or 2^256 possibilities to roughly 2^39 and 2^47. Attackers could enumerate the affected phrases, derive blockchain addresses, and check those addresses for funds. An older CryptoJS dependency alone does not establish exposure. The vulnerable function also had to generate the wallet secret. Updating an app cannot repair a recovery phrase created with insufficient randomness. Importing the same phrase into another software or hardware wallet does not remove the vulnerability. Bexo fixed the generation path in version 20.1.0. NanChat fixed it in version 1.3.0. Bitcoin Libre fixed it in version 4. RRWallet and Milo have been discontinued. NanChat advised users who created wallets before version 1.3.0 to treat them as compromised and migrate to a newly generated phrase. Coinspect released Unlukey to check public blockchain addresses against known exposed datasets without submitting private information. A matching address indicates potential exposure. A negative result only means the address was not found in the published data. Users with confirmed affected wallets should generate a new recovery phrase securely and move the funds it controls.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.