virginnfts.

Decoding liquidity in the NFT economy.

News

Weak Random Number Generators in Crypto Wallets Lead to $5.69 Million in Asset Theft

Blockchain security firm Coinspect has linked a weak random number generator inside the JavaScript CryptoJS library to at least $5.69 million stolen across three attack waves since late May, according to a CryptoSlate report.

Weak Random Number Generators in Crypto Wallets Lead to $5.69 Million in Asset Theft

The flaw made seed phrases guessable in at least five wallet apps and may have touched more than 2,000 phrases across five blockchain networks. If your wallet depends on browser-based key generation, treat this as an active threat to your assets.

The predictable phrase problem

Coinspect's analysis shows the vulnerable generator lets an attacker narrow down the word sequences used to back up and restore your wallet. With enough samples, the attacker can reconstruct your phrase and clone your wallet on another device. The researchers documented three drains: roughly $3.14 million on May 27, an additional $2.55 million traced between May 30 and July 13, and a smaller wave of about $40,000 on July 20–21.

The five affected wallet apps have not been publicly named, which means you cannot rule your setup out by brand alone. Any wallet that relied on the vulnerable CryptoJS implementation to generate keys is at risk, even if its interface looks trustworthy.

Your mitigation protocol

1. Audit your wallet. Check whether your provider documents CryptoJS or browser-based key generation. If the documentation is silent, assume exposure.

2. Generate a fresh wallet on a hardware device. Move every NFT and every token to the new address. Do this before attackers drain your existing one.

3. Revoke all token approvals on the old address. Use a revocation tool to cancel allowances granted to marketplaces and DeFi contracts. A compromised wallet is still a liability even after you stop funding it.

4. Isolate the old wallet. Do not sign new transactions from it. Treat any remaining balance as bait.

5. Verify your recovery phrase offline. Write it down. Never type it into a website, browser extension, or chat window. Legitimate wallet software will never ask for your existing phrase to "verify" it.

Non-negotiable checklist:

  • Move funds to a hardware-backed wallet before you finish reading.
  • Confirm your wallet does not depend on CryptoJS for key generation.
  • Remove any browser extension you did not personally install this week.
  • Never enter a recovery phrase into a webpage, form, or extension.
  • Monitor your addresses for unauthorized transactions.
  • Track broader liquidity signals — market equilibrium and altcoin rotation trends can help you time exits when exploit-driven volatility spikes.

The browser-extension attack surface

The same hostile environment has produced a parallel threat on Firefox. Socket researchers identified 77 extensions tied to a crypto wallet theft campaign active since at least March, with 40 confirmed to steal recovery phrases or login credentials. Thirty-seven of the listed extensions posed as harmless sports score apps to hide the shared infrastructure. Some imitated OKX or Rabby Wallet, and at least one — 0KX WEB3 — loaded a fake setup page hosted on Supabase that prompted users to type in their seed phrase directly.

Fifteen extensions copied real Rabby Wallet code and quietly forwarded any newly created or imported phrase to attacker-controlled servers. A shared code string, EQOx7EIPZSNi, appeared across multiple extensions, confirming a single operator. Mozilla removed several listings after researchers reported the active ones.

Your browser is part of your custody stack. Every extension is a potential keylogger, and any extension that asks for your seed phrase is an attack.