A flawed random number generation function in the JavaScript library CryptoJS, present for twelve years, allowed hackers to crack seed phrases of over 2,100 wallets across Bitcoin, Ethereum, Tron, Rootstock and Polygon networks. Total losses exceeded $5.7 million, with $2.57 million lost on Bitcoin alone. On May 27, 2026, 431 accounts were drained in a single day for $3.14 million. Affected applications include RWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet, some of which have already shut down. Security experts warn that updating applications is insufficient, as any seed phrase generated by the defective system remains permanently compromised.
Source: Read the original article

