THE article discusses a severe vulnerability in CryptoJS, a JavaScript cryptography library, which has used a weak random number generator for over a decade. This flaw led to predictable wallet seed phrases, allowing attackers to exploit wallets across 14 different blockchains starting from May 27, 2026. Wallets created using affected software may be at significant risk, particularly those tied to less popular mobile apps.
Users are advised to check if their wallet addresses are linked to this vulnerability and to migrate to new, secure wallets immediately. The article outlines the risks involved, explains how the attack works, and provides protective steps for users.