CryptoJS Library Vulnerability Leads to $5.7 Million in Lost Funds
A critical vulnerability in the CryptoJS JavaScript library has led to a series of coordinated thefts on the crypto market, exposing a hidden threat at the foundation of web and mobile wallet security.
The bug, known as Ill Bloom, allows hackers to brute-force users' secret seed phrases using ordinary home computers. This vulnerability affects 12-year-old code in CryptoJS library versions 3.x, starting with 3.1.2, except for versions 3.2.0 and 3.2.1.
The random number generation function in these affected versions generates predictable combinations instead of full-fledged digital randomness, narrowing seed phrase security down to an extremely limited range of possible variants.