Crypto Wallets Hit by Ill Bloom Vulnerability
A recently discovered bug in web-based crypto wallets has led to over $5.7 million in losses across multiple networks, including Bitcoin, Ethereum, and Tron. The vulnerability, codenamed Ill Bloom, was caused by a defect in the random number generation function of the CryptoJS library, which allowed attackers to predict seed phrases and drain funds.
The bug, dating back to 2014, affected wallet developers who had been using outdated versions of CryptoJS, including RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. The first wave of mass thefts occurred on May 27, 2026, with attackers withdrawing $3.14 million in one day, mostly from Bitcoin holders.
The situation was exacerbated by the widespread use of CryptoJS 'under the hood' of other software packages, leaving wallet developers unaware of the vulnerability. Updates to affected applications will not protect funds, as the seed phrase remains compromised forever. Experts urge investors to check their public addresses and migrate to new wallets if necessary.