Twitter/X

A single attacker running a laptop drained $5.7M from 953 wallets

Brief

A single attacker using an ordinary laptop drained $5.7M from 953 wallets between May 27 and July 13 by brute‑forcing weakened recovery phrases caused by a reverted CryptoJS RNG fix (patch in 2014, rollback in 2015, broken code live until 2020) that cut entropy to ~2^39; five wallets (RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, Milo) were impacted and only NanChat warned the public by Aug 5, 2026.

Why it matters

A single attacker running a laptop drained $5.7M from 953 wallets: $3.14M from 431 wallets on May 27 and $2.55M from 522 seeds between May 30 and July 13.

Key details

  • Root cause: a CryptoJS RNG bug — a 2014 patch was rolled back in 2015 and the broken RNG stayed live until 2020, degrading 128-bit entropy to roughly 2^39 and making recovery phrases guessable on consumer hardware.
  • Five wallet apps used the vulnerable code: RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo; only NanChat posted a public advisory as of Aug 5, 2026, while the other four remained silent.
Source evidence

There has apparently been a drain very similar to Coldcard happening to 5 other wallet software:

RRWallet
Bexo Wallet
NanChat
Bitcoin Libre
Milo

Nanchat is the only one who posted an advisory

DBCrypto (@DBCrypt0)

A LAPTOP drained $5.7M from 953 wallets in 47 days!

Not a hacking collective or a state actor

One person with ordinary hardware guessing recovery phrases…

The reason is even worse

A JavaScript library reverted a bug fix in 2015 and nobody noticed it for 5 years 🤯

Crazy, right? Here's how it went down:

CryptoJS had a weak random number generator back in 2014 but someone patched it

Then a year later, a new release rolled the patch back because the fix broke other things

The broken version stayed live until 2020 and five wallet apps used it to generate recovery phrases

So the promoted 128 bits of entropy got downgraded to roughly 2^39

Guessable on a laptop some college kid could own

And that’s exactly what someone did

$3.14M was drained from 431 accounts on May 27

Then another $2.55M from 522 seeds between May 30 and July 13

The worst part is the notice didn’t drop till August 5th

So the drains ran for over two months before anyone said a word publicly

Even as of today only 1 of the 5 named wallets has posted a public warning

The other four are all quiet 🤨

RRWallet
Bexo Wallet
NanChat
Bitcoin Libre
Milo

But there may be others

So if your wallet was built before 2021 go check what it was built on

Because whoever drained these 953 wallets is probably still running that script

— https://nitter.net/DBCrypt0/status/2085354628603166972#m