A wave of sophisticated thefts has shaken the cryptocurrency community, exposing a critical flaw affecting the core security of widely used web and mobile wallets. Attackers leveraged a longs
A wave of sophisticated thefts has shaken the cryptocurrency community, exposing a critical flaw affecting the core security of widely used web and mobile wallets. Attackers leveraged a longstanding vulnerability in the CryptoJS JavaScript library to brute-force secret seed phrases, compromising user funds with alarming ease.
Flaw in CryptoJS exposes hundreds of wallets
The vulnerability, identified as “Ill Bloom,” has been linked to the theft of assets from over 2,100 wallet addresses on major blockchain networks including Bitcoin, Ethereum, Tron, Rootstock, and Polygon. Losses attributed to this exploit have now surpassed $5.7 million.
Normally, a standard 12-word seed phrase is designed to be virtually unbreakable, requiring computational timescales beyond the age of the universe to crack. However, CryptoJS library versions 3.x, specifically those starting with 3.1.2 except for 3.2.0 and 3.2.1, had a critical defect in their random number generation functions.
This bug caused the affected versions to produce only weak pseudo-randomness, drastically reducing the number of possible seed phrase combinations and making brute-force attacks feasible even on ordinary home computers.
Compounding the problem, CryptoJS was quietly embedded within hundreds of software packages. Wallet developers widely integrated it without awareness, inadvertently exposing users across many applications.
More than 2,100 wallet addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon have fallen victim to Ill Bloom, with total losses above $5.7 million.
The first large-scale incident linked to Ill Bloom occurred on May 27, 2026, when attackers compromised 431 wallets in one day, siphoning off $3.14 million. Bitcoin investors suffered the greatest impact, losing $2.57 million. Ethereum, Rootstock, Tron, and Polygon users also faced significant losses, with values ranging from $23,000 to $286,000 across these networks.
Impacted wallets and user safeguards
By August, applications confirmed as affected included RWallet (also known as RRWallet), Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. Some projects, notably Milo and RWallet, have ceased operations, leaving users with no dedicated support channels.
Developers of Bitcoin Libre responded by patching the bug in earlier releases. NanChat has issued a new security fix for its users, while an update for Bexo Wallet was still under review in app stores at the time of reporting.
Security researchers warn that updating wallet applications alone is not enough to safeguard user assets. Seed phrases created on versions affected by Ill Bloom remain fundamentally vulnerable, as their entropy was compromised from the start.
Specialists recommend that users review all public addresses potentially exposed, and if risk is detected, immediately transfer funds to freshly generated wallets. They urge the community to avoid storing substantial sums in browsers or mobile wallets whose keys were created with unsafe libraries.
For investors aiming to minimize risks and closely monitor their digital assets, leveraging advanced portfolio tools is vital. CryptoAppsy, for example, eliminates account setup complexity and brings together investments, real-time pricing, and multi-currency management on a single platform. By using features such as smart price alerts, coin-specific news filtering, instant tracking of new altcoins, and macroeconomic data like Fed interest rates, users can remain vigilant and ready to react to changes in market conditions.
Experts emphasize that if a wallet’s seed phrase originated from the defective CryptoJS versions, only migrating to a new wallet that generates fresh keys can restore full security.
The post Hackers exploit CryptoJS flaw to steal $5.7 million from 2,100 crypto wallets appeared first on COINTURK NEWS.