Cybersecurity
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.
AI Summary
Coinspect discovered that the CryptoJS.lib.WordArray.random() function, a random number generator in the CryptoJS library, supplied weak entropy. The weakness was present in the library for 12 years. It affected wallet applications that use the function to generate recovery phrases. The vulnerability led to the Ill Bloom wallet draining $5.7 million from users. The issue highlights the risk of relying on legacy cryptographic code in mobile wallet apps.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- 'Salesbleed' Exploits Salesforce Agents to Enable Slack PhishingContinue reading
- MacSync malware uses public iCloud calendars to deliver new payloadsContinue reading
- Autonomous AI Hacks Raise Thorny Questions of Legal AccountabilityContinue reading
- SectopRAT Returns, Hiding Inside a Legitimate ApplicationContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow