CryptoJS Weak RNG Wallet Drains (2026) — Crypto Hack
ActiveA weak random number generator in the CryptoJS library affected 5 crypto wallet apps, leading to ~$5.7M in wallet drains across the affected applications.
Summary
A weak random number generator in the CryptoJS library affected 5 crypto wallet apps, leading to ~$5.7M in wallet drains across the affected applications.
How It Was Compromised — Wallet via Weak Random Number Generator
A weak random number generator (RNG) vulnerability in the widely-used CryptoJS JavaScript library led to approximately $5.7 million in wallet drains across 5 separate cryptocurrency wallet applications in August 2026. The weak RNG produced predictable or low-entropy values, allowing attackers to brute-force private keys generated by affected wallets. The incident demonstrated the cascading risks of shared library vulnerabilities across the cryptocurrency ecosystem, where a single flawed dependency can compromise multiple independent applications.
Fund Flow & Laundering Analysis
Stolen funds from the 5 affected wallet apps were moved across multiple blockchains, with the distributed nature of the attacks across separate wallet applications complicating coordinated fund tracing.