Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$76,430.7 -2.44%
ETH Ethereum
$2,430.5 -2.86%
SOL Solana
$99.49 -2.28%
BNB BNB Chain
$719.5 -0.28%
XRP XRP Ledger
$1.4 -0.37%
DOGE Dogecoin
$0.0819 -2.38%
ADA Cardano
$0.2025 -2.69%
AVAX Avalanche
$7.45 +0.00%
DOT Polkadot
$0.9852 -2.38%
LINK Chainlink
$11.3 -1.02%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$76,430.7
1
Ethereum
ETH
$2,430.5
1
Solana
SOL
$99.49
1
BNB Chain
BNB
$719.5
1
XRP Ledger
XRP
$1.4
1
Dogecoin
DOGE
$0.0819
1
Cardano
ADA
$0.2025
1
Avalanche
AVAX
$7.45
1
Polkadot
DOT
$0.9852
1
Chainlink
LINK
$11.3

🐋 Whale Tracker

🔵
0x514f...7f18
1d ago
Stake
3,361.50 BTC
🔵
0x0f30...9ee8
3h ago
Stake
1,048,748 DOGE
🔴
0x3b2d...7396
30m ago
Out
2,577,518 USDT

💡 Smart Money

0xd569...6600
Top DeFi Miner
+$2.3M
88%
0xcc11...4b95
Top DeFi Miner
+$4.9M
74%
0x2be3...f9a3
Early Investor
+$2.1M
74%

🧮 Tools

All →
NFT

The Entropy That Wasn't: How a 2014 Code Fix Enabled $5.7M in Wallet Thefts

CryptoTiger

The numbers demand attention. A search space of 2^256 compressed to 2^47. The difference is not incremental. It is existential. Somewhere in the arithmetic lies the difference between cryptographic sovereignty and a shared secret with a stranger. This is the story of how a single function in a widely used JavaScript library turned the promise of self-custody into a liability for thousands of users.

The Entropy That Wasn't: How a 2014 Code Fix Enabled $5.7M in Wallet Thefts

The protocol does not lie; the interface does. But sometimes the protocol itself carries the wound.

In May 2025, security researchers at Coinspect identified an active drain of funds from wallets whose recovery phrases were generated with insufficient entropy. The root cause traced back to CryptoJS, a JavaScript cryptography library, and specifically to its WordArray.random() function. The flaw was introduced in 2014, when a developer responded to a GitHub issue by modifying how the function sourced randomness. The patch seemed reasonable at the time. It was not. Eleven years later, attackers are still harvesting the consequences.

The affected wallets are not household names. Bexo, NanChat, Bitcoin Libre, RRWallet, Milo. The first three have since patched their implementations. The last two have ceased operations entirely. But the damage does not respect brand boundaries. Coinspect analyzed over two thousand seed phrases across five wallet applications. The confirmed theft amount stands at $5.69 million. That figure is a floor, not a ceiling. The analysis covered only a subset of chains and seeds. The real number is likely higher.

The mechanics deserve attention. The vulnerable function produced random words with dramatically reduced entropy. Instead of the industry-standard 128 or 256 bits of security, affected phrases carried approximately 39 to 47 bits of effective entropy. The difference between these numbers is the difference between a vault door and a cardboard box. With 2^47 possibilities, a determined attacker with modest computing resources can enumerate the space, derive addresses, and check for balances. The attackers did exactly this. Between May and July, they systematically swept funds from vulnerable wallets. The operation was automated, patient, and effective.

I have spent twenty-five years watching this industry. I have audited multi-sig contracts at the assembly level and dissected consensus mechanisms in bear market silence. What strikes me about this incident is not the technical sophistication of the attack. It is the banality of the cause. A single library function, patched in haste, trusted for a decade. The entire edifice of decentralized finance rests on assumptions of secure randomness. When that assumption fails at the foundation, everything built above it becomes provisional.

Let me be precise about what happened. The BIP39 standard requires a cryptographically secure pseudo-random number generator for mnemonic generation. Modern wallets use window.crypto.getRandomValues(), which taps into the operating system's entropy sources. The affected wallets used CryptoJS's WordArray.random(), which sourced its randomness from a flawed implementation. The library is popular. The function was specific. But the damage cascades far beyond the five named wallets.

Here is the uncomfortable truth: the exposure depends not on the wallet brand but on the software version used at the time of phrase generation. A user who generated a mnemonic with an affected version of any application built on CryptoJS is vulnerable, regardless of whether they later migrated to a different wallet. The phrase is the key. The phrase was generated with insufficient entropy. The key is weak. Importing it into a hardware wallet does not strengthen it. The weakness travels with the phrase.

This is the "generate is permanent" property of mnemonic security. Updating an application prevents the creation of new weak phrases. It does nothing for phrases already generated. The only remediation is migration: generate a new phrase with secure software, move funds to the new address, abandon the old one. NanChat understood this. The team proactively notified users and facilitated migration. RRWallet and Milo chose a different path. They shut down. Their users were left to discover the vulnerability on their own, or through the draining of their accounts.

The supply chain dimension deserves scrutiny. CryptoJS is not obscure. It is a widely distributed library. The vulnerable function was introduced in response to a GitHub issue in 2014. The fix seemed reasonable. It was not reviewed with the rigor that cryptographic code demands. This is the recurring pattern in our industry: a single point of failure, embedded in a dependency, invisible to the end user, catastrophic in its impact. We build in the dark to light the public square. But the dark also hides our errors.

What the market has not yet priced in is the scope of potential exposure. Coinspect identified five wallets. How many other projects, wallet or otherwise, use CryptoJS's WordArray.random() in their key generation paths? The answer is unknown. The confidence interval is uncomfortable. Developers who integrated this library may be sitting on the same time bomb, unaware that their users' funds are enumerable. The silence before the block confirms the truth: entropy is not a feature you can verify after the fact. It is a property that must be guaranteed at the moment of generation.

The Entropy That Wasn't: How a 2014 Code Fix Enabled $5.7M in Wallet Thefts

The contrarian angle here is not about the attackers. It is about the industry's response. The reflexive reaction to any wallet compromise is to blame the user. "You should have used a hardware wallet." "You should have verified your phrase." These responses are technically correct and morally hollow. A hardware wallet cannot fix a weak phrase. Verifying a phrase does not reveal its entropy. The responsibility lies with the developers who chose a library without auditing its cryptographic guarantees, and with an industry that has not yet established mandatory supply chain security standards for key generation code.

Consider the regulatory implications. This is not a securities question. It is a consumer protection question. Users entrusted their assets to software that promised cryptographic security and delivered a simulacrum of it. Regulators in the United States and Europe have shown increasing interest in wallet security standards. Incidents like this provide the factual basis for intervention. The question is no longer whether wallet security will be regulated. It is when, and how prescriptively.

Certainty is a bug in a stochastic world. The only certainty here is that the attack is ongoing. The affected wallets' users remain exposed. The broader ecosystem remains exposed to the extent that other projects integrated the vulnerable function. The opportunity cost of not acting is measured in stolen funds that will never be recovered. The opportunity for the industry is to treat this as a watershed moment for supply chain security in cryptographic software.

What should a user do today? Generate a new phrase with a wallet that uses window.crypto.getRandomValues() or equivalent modern APIs. Transfer all assets. Verify the new phrase's integrity by checking a few addresses. Do not trust a wallet that cannot demonstrate its entropy source. Do not trust a project that cannot show its dependency audit. Trust is earned through verifiable process, not through marketing.

To own the chain is to own the history. But to own the chain, you must first own your keys. And to own your keys, you must be certain of their origin. The origin is the seed. The seed is only as strong as the entropy that birthed it. When that entropy fails, everything else is theater. The affected users learned this lesson at a cost of millions. The rest of us have the privilege of learning it for free. The question is whether we will.