Decade-Old Weak RNG in CryptoJS Drains $5.7M from Crypto Wallets
Five cryptocurrency wallet applications relied on CryptoJS's flawed random number generator to create cryptographic seed phrases, a vulnerability that went undetected and unpatched for over a decade. Because the entropy was insufficiently random, attackers could systematically guess recovery phrases and drain wallets without any direct system access. This incident highlights the danger of blindly trusting third-party cryptographic libraries without ongoing scrutiny of their security properties. Supply chain dependencies—especially in security-critical code paths like key generation—must be continuously evaluated, not simply adopted and forgotten. The $5.7 million loss demonstrates that a single weak link in a cryptographic foundation can silently undermine an entire application's security model.
Tactical Insight
Immediate actions
- Audit all cryptographic dependencies for known weaknesses in random number generation and replace any that do not use platform-native CSPRNG (Cryptographically Secure Pseudo-Random Number Generator) sources.
- Notify affected users immediately and provide clear, step-by-step instructions to migrate funds to wallets with securely generated seed phrases.
- Scan your software bill of materials (SBOM) for any other use of CryptoJS or similarly deprecated/unmaintained cryptographic libraries.
Long-term improvements
- Mandate formal cryptographic review of all third-party libraries used in security-critical code paths (key generation, signing, encryption) before adoption and at regular intervals.
- Maintain a versioned SBOM for every product and integrate automated dependency vulnerability scanning into the CI/CD pipeline.
- Establish a policy requiring replacement of any cryptographic library that is unmaintained, end-of-life, or flagged by a reputable vulnerability database.
Detection measures
- Implement continuous monitoring for anomalous transaction patterns (e.g., bulk wallet drains) that may indicate systematic key compromise.
- Subscribe to security advisories for all open-source dependencies and configure automated alerts when a new CVE affects any library in your stack.
- Conduct periodic third-party penetration testing specifically targeting cryptographic implementations and key-generation logic.