CryptoJS Bug Exposes $5.7 Million in Web-Based Wallets
A serious bug has been discovered in web-based crypto wallets, putting millions of dollars at risk. The issue, known as 'Ill Bloom', affects the CryptoJS JavaScript library and allows hackers to brute-force users' secret seed phrases using ordinary home computers.
The vulnerability was caused by a defective random number generation function in CryptoJS versions 3.x, starting with 3.1.2, except for 3.2.0 and 3.2.1. This has resulted in predictable combinations of numbers, narrowing down the range of possible seed phrase variants.
The bug was first detected on May 27, 2026, when 431 accounts were compromised, resulting in losses of over $3.14 million, with Bitcoin holders taking the largest hit at $2.57 million.
Experts are warning investors to check their public addresses and migrate to new wallets if a threat is detected, as updating a wallet application does not protect the funds.