Crypto Wallet Hackers Exploit Decade-Old Code Bug for $5.7 Million
A bug in web-based crypto wallets has been identified as the cause of over $5.7 million in losses across various networks, including Bitcoin, Ethereum, Tron, Rootstock, and Polygon. The vulnerability, known as 'Ill Bloom', is linked to a 12-year-old code bug in the CryptoJS library that affects versions 3.x, starting with 3.1.2.
The issue arises from defective random number generation, which produces predictable combinations instead of full-fledged digital randomness. This compromises seed phrase security, allowing hackers to crack it down to an extremely limited range of possible variants.
According to reports, the first wave of mass thefts occurred on May 27, 2026, with 431 accounts targeted in a single day, resulting in $3.14 million withdrawn at once. Bitcoin holders suffered the largest losses, with over $2.57 million lost, followed by Ethereum ($286,000), Rootstock ($177,000), Tron ($81,000), and Polygon ($23,000).
Experts warn that updating a wallet application does not guarantee protection from this vulnerability. If a seed phrase was originally generated by the defective system, it remains mathematically compromised forever.