A flaw in the CryptoJS library used by at least five cryptocurrency wallets made certain recovery phrases predictable, enabling attackers to steal at least $5.69 million since May. The thefts occurred in multiple waves, including $3.14 million on May 27 and another $2.55 million between late May and mid-July. The analysis covers over 2,000 seeds across five networks (Bitcoin, Ethereum, Tron, Rootstock and Polygon), making the $5.69 million figure a lower bound rather than total losses. Affected users must generate a new recovery phrase securely and move their funds.
Source: Read the original article

