Security Firm Says Predictable Crypto Wallet Seed Phrases Fueled at Least $5.69 Million in Theft
Forecast Trend Report by Period


A flaw in cryptocurrency wallet software left some seed phrases, also known as recovery phrases, vulnerable to prediction, allowing thieves to steal at least $5.69 million, according to an analysis. More than 2,000 seed phrases across five blockchain networks are believed to have been affected.
CryptoSlate reported on August 27 that blockchain security firm Coinspect identified a weakness in the CryptoJS library's random number generator that made recovery phrases for at least five wallet apps predictable.
Coinspect believes hackers exploited the vulnerability multiple times. It tracked about $3.14 million stolen on May 27 and another $2.55 million drained between May 30 and July 13.
A third attack took place on July 20 and July 21, causing an additional roughly $40,000 in losses. That figure appears to have been counted separately from the minimum $5.69 million in losses cited in the analysis.
Coinspect said more than 2,000 seed phrases across five blockchain networks appear to have been affected. The specific wallet apps involved and the full scale of the losses have not yet been confirmed.

JH Kim
reporter1@bloomingbit.ioHi, I'm a Bloomingbit reporter, bringing you the latest cryptocurrency news.