A weakness in the CryptoJS library’s random-number generator made some recovery phrases generated by at least five wallet apps predictable enough for attackers to reconstruct, Coinspect said. The blockchain security firm traced at least $5.69 million in thefts, including about $3.14 million drained on May 27 and another $2.55 million between May 30 and July 13. A separate attack on July 20 and 21 caused roughly $40,000 in additional losses. More than 2,000 seed phrases across Bitcoin, Ethereum, Tron, Rootstock and Polygon appear to have been affected, although the specific apps involved and the full scale of losses have not been confirmed. Users with potentially affected wallets should create a new recovery phrase using secure, audited software or a hardware wallet and move their funds, because updating an app or importing the old phrase elsewhere does not remove the risk.