Crypto
Home›Crypto›Market Structure›Predictable wallet seeds enabled thefts of at least $5…
Predictable wallet seeds enabled thefts of at least $5.69 million
Security firm Coinspect traced about $3.14 million drained on May 27, plus another $2.55 million from May 30 to July 13, and said older phrase generations cannot be repaired by simple app updates.
A software flaw in multiple crypto wallets made some recovery phrases predictable enough for attackers to reconstruct, leading to at least $5.69 million in traced thefts since May, according to analysis cited by CryptoSlate.
Coinspect said wallets including RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo used a weak random number generator from the CryptoJS library to create certain recovery phrases. The firm traced roughly $3.14 million drained on May 27 and about $2.55 million drained between May 30 and July 13, and it also identified a third wave between July 20 and 21 that drained around $40,000 across the Chinese mnemonic subset.
The analysis covered more than 2,000 seeds with activity across Bitcoin, Ethereum, Tron, Rootstock and Polygon, and the $5.69 million figure is described as a lower bound because the affected-wallet list may not be complete. Coinspect also said exposure depends on the software version used to generate the phrase, not just the wallet brand.
CryptoSlate reports that a recovery phrase can recreate the private keys controlling a wallet, so anyone who obtains or reconstructs the phrase can potentially move funds. The weakness cannot be fixed by updating an app if the phrase was generated with insufficient randomness, and importing the same phrase into another wallet type would carry the same vulnerability; Coinspect said Bexo fixed the generation path in version 20.1.0 and NanChat fixed it in version 1.3.0, while Bitcoin Libre fixed it in version 4, and RRWallet and Milo have been discontinued.
Latest closeBitcoin $79,985.12 ▲1.2%|Ethereum $2,503.32 ▼0.1%