Security Breach in Cryptocurrency Sector
A significant security breach has come to light within the cryptocurrency sector, revealing vulnerabilities linked to widely used web and mobile wallets. This breach stems from an enduring flaw in the CryptoJS JavaScript library that has allowed cybercriminals to exploit it for brute-forcing users’ seed phrases with just basic home computing resources. Dubbed “Ill Bloom,” this vulnerability has already resulted in over 2,100 wallet addresses being emptied across various blockchain networks, including Bitcoin, Ethereum, Tron, Rootstock, and Polygon, tallying losses that surpass $5.7 million.
Details of the Vulnerability
Typically, a 12-word seed phrase serves as an effective safeguard, theoretically requiring billions of years to decipher. However, the CryptoJS library versions 3.x—particularly versions starting from 3.1.2, with exclusions of 3.2.0 and 3.2.1—harbored a flawed random number generation function. As a result, rather than producing truly random outputs, it generated predictable sequences, severely compromising the integrity of seed phrase security.
Widespread Impact
The impact has been widespread, as CryptoJS is embedded within numerous projects, meaning several wallets might be compromised without their developers’ knowledge. Among the wallets that have been identified so far are RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. Many of these applications have either ceased operations or are struggling to implement necessary fixes.
Timeline of Events
The onset of these mass thefts began on May 27, 2026, when 431 accounts were targeted in a single day, leading to withdrawals amounting to $3.14 million. The most significant losses were suffered by Bitcoin holders, who collectively lost $2.57 million, while other networks faced varying degrees of financial hit: Ethereum users lost $286,000, followed by Rootstock at $177,000, Tron at $81,000, and Polygon at $23,000.
Current Status and Recommendations
By August, the scope of affected applications had widened significantly. Some wallets, such as Milo Wallet and RWallet, have shut their operations entirely, leaving their users unsupported. Fortunately, developers from Bitcoin Libre have addressed the flaw in earlier versions, and NanChat has issued an update, though Bexo Wallet’s patch awaits approval from app stores.
It is critical to note that simply updating a wallet application will not safeguard funds previously generated through the compromised system. If a user’s seed phrase was created within this flawed framework, it remains permanently at risk. Security experts are advising cryptocurrency holders to review their public addresses rigorously. If any risk is identified, they should promptly transition to secure, new wallets and refrain from keeping large sums in wallets originating from browsers.