
A bug in the CryptoJS library, first released in 2016, let attackers brute-force seed phrases. Over 2,100 addresses drained. Migration is the only fix.
A coordinated wave of thefts has drained more than 2,100 crypto addresses across Bitcoin, Ethereum, Tron, Rootstock and Polygon networks – a haul exceeding $5.7 million tied to a bug in a JavaScript library first released in 2016.
The vulnerability, researchers have dubbed Ill Bloom, lives inside CryptoJS library versions 3.x starting with 3.1.2 (excluding versions 3.2.0 and 3.2.1). The random number generation function in those builds produces predictable sequences instead of true cryptographic randomness, meaning seed phrases generated by affected wallets are mathematically compromised.
Normally a 12-word seed phrase represents a space so large it would take billions of years to brute-force. With this defect, the effective range of possible variants shrinks to something an ordinary home computer can exhaust in days or weeks.
Wallets confirmed affected include RWallet (also called RRWallet), Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet. Milo and RWallet have already shut down, leaving users without recourse. Bitcoin Libre developers fixed the exposed version; NanChat released a patch. Bexo Wallet is still awaiting an approved update in app stores.
CryptoJS shipped bundled inside hundreds of software packages. Wallet developers who incorporated it may not know their code relies on the flawed random number generator. That means the list of affected wallets is likely longer than what has been publicly confirmed.
The first coordinated batch of thefts hit May 27, 2026. In a single day attackers hit 431 accounts and withdrew $3.14 million. Bitcoin holders lost $2.57 million of that. Ethereum addresses lost $286,000, Rootstock $177,000, Tron $81,000 and Polygon $23,000.
Updating the wallet application alone does not fix the problem. A seed phrase generated by the defective system stays vulnerable indefinitely – the math does not change. Experts are urging anyone who used a browser-based wallet or one that relied on CryptoJS to check their public addresses and migrate funds to wallets whose keys were generated outside those affected libraries.
The bigger risk is discovery: with the bug now public and the code path known, attackers can scan for addresses generated by the vulnerable system at scale. The $5.7 million figure represents what has already been taken. It may capture only the first wave of detection.
For more context on the broader crypto security environment, see our crypto market analysis.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.