CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

CryptoJS's WordArray.random() function, introduced 12 years ago, supplied weak entropy to wallet apps used to generate recovery phrases, resulting in $5.7 million in lost funds.

CryptoJS, a JavaScript cryptography library, has been identified as the root cause behind a series of cryptocurrency wallet drain incidents. According to a report by Coinspect, the weakness in CryptoJS's WordArray.random() function has been affecting cryptocurrency wallet apps for over a decade. The function, introduced in 2011, was designed to generate random numbers but has been found to produce weak entropy, which is critical for secure password generation. As a result, wallet apps that utilized this function to create recovery phrases have been vulnerable to attacks. In total, five cryptocurrency wallet apps were affected by the weakness, resulting in a significant financial loss of $5.7 million.

ADDITIONAL INFO: Coinspect, a cybersecurity firm, analyzed the source code of the affected wallet apps and found that the WordArray.random() function was used to generate recovery phrases. The weakness in this function was first discovered in 2019 by a security researcher, but it was not widely publicized until now. The incident highlights the importance of regularly updating software and libraries to ensure that the latest security patches are in place. Cryptocurrency investors and users should be aware of this vulnerability and take steps to protect themselves from potential attacks.

TITLE: CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

SUMMARY: CryptoJS's 12-year-old WordArray.random() function, used to generate recovery phrases, supplied weak entropy, leading to $5.7 million in losses.

CONTENT:

CryptoJS, a widely used JavaScript cryptography library, has been found to be the root cause of a cryptocurrency wallet drain incident that affected five wallet apps. According to Coinspect, a cybersecurity firm, the weakness in CryptoJS's WordArray.random() function, introduced in 2011, has been exploited by attackers to drain funds from cryptocurrency wallets. The function was designed to generate random numbers, but it has been found to produce weak entropy, making it unsuitable for secure password generation. As a result, wallet apps that used this function to create recovery phrases have been vulnerable to attacks, resulting in significant financial losses. The total loss is estimated to be $5.7 million.

ADDITIONAL INFO: Coinspect analyzed the source code of the affected wallet apps and found that the WordArray.random() function was used to generate recovery phrases. The weakness in this function was first discovered in 2019 by a security researcher, but it was not widely publicized until now. The incident highlights the importance of regularly updating software and libraries to ensure that the latest security patches are in place. Cryptocurrency investors and users should be aware of this vulnerability and take steps to protect themselves from potential attacks.

TITLE: CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

SUMMARY: CryptoJS's 12-year-old WordArray.random() function, used to generate recovery phrases, supplied weak entropy, leading to $5.7 million in losses.

CONTENT:

CryptoJS, a popular JavaScript cryptography library, has been identified as the root cause of a significant cryptocurrency wallet drain incident. According to Coinspect, a cybersecurity firm specializing in cryptocurrency security, the weakness in CryptoJS's WordArray.random() function, introduced in 2011, has been exploited by attackers to drain funds from cryptocurrency wallets. The function, designed to generate random numbers, has been found to produce weak entropy, making it unsuitable for secure password generation. As a result, wallet apps that utilized this function to create recovery phrases have been vulnerable to attacks, resulting in substantial financial losses of

Source: The Hacker News