Skip to content
Back to Guavy Wire
Crypto

CryptoJS Bug Exposes Web Wallets to $5.7M in Coordinated Thefts

Instruments
BTC ETH MATIC POL
Share

A critical vulnerability in the CryptoJS JavaScript library has exposed web-based crypto wallets to a series of coordinated thefts, resulting in losses exceeding $5.7 million.

The bug, dubbed 'Ill Bloom,' allows hackers to brute-force users' secret seed phrases using ordinary home computers. The vulnerable code was introduced in versions 3.x of CryptoJS starting with 3.1.2, except for 3.2.0 and 3.2.1.

The issue affects several wallets, including RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet, among others. The affected wallets' developers may not even be aware of the vulnerability since CryptoJS was often bundled with other libraries.

The first wave of mass thefts occurred on May 27, 2026, when 431 accounts were compromised in a single day, resulting in $3.14 million in withdrawals. The losses were distributed across various networks, including Bitcoin, Ethereum, Rootstock, Tron, and Polygon.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc