
A flaw in CryptoJS let hackers guess seed phrases, draining $5.7M from web wallets. Bitcoin holders lost $2.57M. On-chain tracking continues.
A vulnerability in the 12-year-old CryptoJS library has led to the theft of $5.7 million from web crypto wallets and mobile applications, according to a market report. The flaw, identified as "Ill Bloom," affected versions 3.x of the JavaScript library. Hackers exploited a weakness in the random number generation function, which did not produce full cryptographic entropy. That reduced the range of mathematical possibilities needed to brute-force 12-word seed phrases.
Under normal conditions, guessing a seed phrase would take billions of years. The flaw meant conventional home computers could crack them in short timeframes, cybersecurity analyses cited in the report said.
The first large wave of thefts hit on May 27. A total of 431 accounts were drained in a single day, with initial losses of $3.14 million. Bitcoin holders took the biggest hit, losing $2.57 million. The rest was spread across Ethereum ($286,000), Rootstock ($177,000), Tron ($81,000), and Polygon ($23,000).
Several applications integrated the defective library, including RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. Industry developers said CryptoJS was often included indirectly through third-party software packages, meaning many teams implemented the code without realizing the underlying flaw for years.
Responses from affected platforms have varied. Milo Wallet and RWallet permanently shut down, the report said. Bitcoin Libre and NanChat issued patches for their latest versions. Other applications are still awaiting approval for updates in mobile app stores.
Updating the app, however, does not invalidate the vulnerability of a previously generated seed phrase. Technical documentation emphasized that any cryptographic key generated under the flawed system remains mathematically exposed. The nature of blockchain architecture prevents a private key compromised at inception from regaining its default security level.
Industry experts cited by the source urged users to verify the origin of their addresses and immediately transfer funds to new wallets created outside web environments prone to the flaw. On-chain analytics firms will continue to monitor movements of addresses linked to the attackers in the coming weeks.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.