Back to advisories

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

A decade-old weak RNG vulnerability in CryptoJS has enabled attackers to guess recovery phrases and drain cryptocurrency wallets, resulting in $5.7M+ in confirmed losses across five wallet apps. Affected users cannot patch their way out. this requires immediate fund migration to new wallets with properly generated recovery phrases.

CRITICALAdvisoryAug 08, 2026
Action required
Identify any CryptoJS implementations in your environment generating cryptographic material. Flag wallet applications using CryptoJS for RNG. Alert users of affected wallets immediately and direct them to migrate funds to alternatives with secure entropy sources.
Affected products
CryptoJSRRWalletBexo WalletNanChatBitcoin Libre