Back to all lessons
Awareness Lessons
2 months ago

Decade-Old Weak RNG in CryptoJS Drains $5.7M from Crypto Wallets

Five cryptocurrency wallet applications relied on CryptoJS's flawed random number generator to create cryptographic seed phrases, a vulnerability that went undetected and unpatched for over a decade. Because the entropy was insufficiently random, attackers could systematically guess recovery phrases and drain wallets without any direct system access. This incident highlights the danger of blindly trusting third-party cryptographic libraries without ongoing scrutiny of their security properties. Supply chain dependencies—especially in security-critical code paths like key generation—must be continuously evaluated, not simply adopted and forgotten. The $5.7 million loss demonstrates that a single weak link in a cryptographic foundation can silently undermine an entire application's security model.

Tactical Insight

Immediate actions

  • Audit all cryptographic dependencies for known weaknesses in random number generation and replace any that do not use platform-native CSPRNG (Cryptographically Secure Pseudo-Random Number Generator) sources.
  • Notify affected users immediately and provide clear, step-by-step instructions to migrate funds to wallets with securely generated seed phrases.
  • Scan your software bill of materials (SBOM) for any other use of CryptoJS or similarly deprecated/unmaintained cryptographic libraries.

Long-term improvements

  • Mandate formal cryptographic review of all third-party libraries used in security-critical code paths (key generation, signing, encryption) before adoption and at regular intervals.
  • Maintain a versioned SBOM for every product and integrate automated dependency vulnerability scanning into the CI/CD pipeline.
  • Establish a policy requiring replacement of any cryptographic library that is unmaintained, end-of-life, or flagged by a reputable vulnerability database.

Detection measures

  • Implement continuous monitoring for anomalous transaction patterns (e.g., bulk wallet drains) that may indicate systematic key compromise.
  • Subscribe to security advisories for all open-source dependencies and configure automated alerts when a new CVE affects any library in your stack.
  • Conduct periodic third-party penetration testing specifically targeting cryptographic implementations and key-generation logic.