A weak generator in a widely used JavaScript crypto library
A random number generation weakness in the CryptoJS library meant that values intended to be unguessable could be reproduced. Because the library is embedded in a very large number of downstream projects, applications inherited the weakness without any mistake of their own.
Public reporting linked the flaw to wallet applications whose users lost funds — the practical outcome of a secret that could be recomputed rather than guessed.