SECURITY·중요도 9·2026. 08. 06.·The Hacker News
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
── KO ──────────────────
CryptoJS의 약한 난수 생성기가 570만 달러 손실의 원인으로 지목되었다.
Coinspect는 CryptoJS.lib.WordArray.random() 함수가 약한 난수 생성기임을 밝혀냈다. 이로 인해 Ill Bloom 지갑이 손실을 입었다. 12년 전에 도입된 이 함수는 회복 구문을 생성하는 데 필요한 약한 엔트로피를 제공하였다. 현행 분석에 따르면, 5월 말 이후 두 번의 해킹으로 인해 발생한 도난액은 최소 570만 달러로 추정된다.
── EN ──────────────────
CryptoJS's weak RNG is linked to $5.7 million in thefts from crypto wallets.
Coinspect has identified the CryptoJS.lib.WordArray.random() function as a weak random number generator responsible for draining funds from the Ill Bloom wallet. Introduced 12 years ago, this function provided weak entropy, impacting wallet apps that generate recovery phrases. On-chain analysis estimates that the theft across two incidents since late May is at least $5.7 million.