Cryptocurrency Wallets Compromised by Decade-Old Code Bug
A 12-year-old code bug has compromised the security of over 2,100 digital wallets across various blockchain networks, resulting in cumulative losses exceeding $5.7 million as of early August 2026.
The vulnerability, named 'Ill Bloom,' originates from a defect in random number generation in older versions of the JavaScript CryptoJS library.
Hackers were able to guess seed phrases and steal millions of dollars from affected users across Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks.
The technical issue was detected in versions 3.x of the CryptoJS library, which has been in use for over a decade. The function responsible for generating random numbers within that software package did not work properly, resulting in reduced entropy and making it easier to guess seed phrases.
The first massive wave of thefts occurred on May 27, with 431 accounts drained in a short period, totaling an initial financial impact of $3.14 million, with Bitcoin holders taking the brunt of the hit at $2.57 million.