CryptoJS Library Flaw Exposes Over 2,100 Digital Wallets
A critical vulnerability in a widely-used JavaScript library has compromised the security of over 2,100 digital wallets across various blockchain networks. The issue, known as 'Ill Bloom,' originated from a defect in random number generation in older versions of the CryptoJS library.
The flaw allowed hackers to guess seed phrases and steal millions of dollars from affected users on platforms such as Bitcoin, Ethereum, Tron, Rootstock, and Polygon. As of early August 2026, cumulative losses exceeded $5.7 million.
A total of 431 accounts were drained in a short period on May 27, resulting in an initial financial impact of $3.14 million, with Bitcoin holders taking the brunt of the hit at an estimated loss of $2.57 million.