RRWallet Hack
What happened
On August 6, 2026, public research identified discontinued RRWallet as one of several wallet apps affected by weak recovery-phrase generation in CryptoJS, which made private keys predictable and led to theft.
RRWallet used CryptoJS.lib.WordArray.random() as an entropy source for recovery-phrase generation; Coinspect identified that function as a weak random-number generator that made affected wallet keys predictable.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.