- Sources: primary, investigation
- Summary: CVE-2026-71851 is scored CVSS 3.1 9.0 and affects crypto-js below 4.0.0. The advisory states that a nominal request for 128 or 256 bits from
CryptoJS.lib.WordArray.random() yields effective search spaces of roughly 2^39 and 2^47. The weak generator entered in 3.1.2-4 in June 2014 and was present in every 3.x release except 3.2.0 and 3.2.1, and 4.0.0 replaced it with the platform cryptographic API. Version 3.3.0 reverted the 3.1.2-4 change as a breaking change, so a project tracking the 3.x line could resolve to a newer version that still carried the weak generator. Coinspect's Ill Bloom investigation, dated 2026-08-05, confirmed that downstream wallets used the function as the entropy source for BIP39 recovery phrases, and puts the measured lower bound of stolen assets at about 5 million dollars as of 2026-07-13 across two drain waves. That figure is a lower bound, not a total. An application is affected only where that function generated a security-sensitive value, so depending on crypto-js below 4.0.0 is not on its own sufficient. - Why it matters: A secret generated through the affected function stays enumerable after the library is upgraded, so the required work is a dependency audit across direct and transitive paths plus rotation of every long-term secret that path produced, not a version bump.
- Follow-up: Track further drain waves attributed to this generator and any wallet vendor publishing a rotation notice.
send feedback on this story