Oh you don't know this story? A bunch of wallets lost a bunch of user funds by using a broken implementation of SecureRandom on Android. Then later blockchain.info fucked up again by using a web call to random.org that failed.
Since address reuse was rampant, there resulted many cases of reused R, even at large scale.