Hack of 2,100 Wallets Due to an Old Bug; "Ill Bloom" Vulnerability Wipes Out Millions in Cryptocurrency!
An old vulnerability in the CryptoJS programming library has allowed hackers to guess the recovery phrases of some cryptocurrency wallets using ordinary computers, draining users' assets. This vulnerability, dubbed "Ill Bloom," has affected over 2,100 addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks, with damages exceeding $5.7 million.
The main danger of this attack is that the issue is not limited to a single wallet or a specific network. CryptoJS has been used for years as a hidden component in hundreds of other software and libraries, and some wallet developers have utilized its random number generation capability to create recovery phrases; a feature that lacked necessary security in vulnerable versions.
How Did the CryptoJS Bug Compromise Wallet Recovery Phrases?
A typical 12-word recovery phrase is cryptographically secure enough that breaking it through standard trial and error methods is practically impossible. However, in some versions of the 3.x CryptoJS library, including version 3.1.2 and versions after it except for 3.2.0 and 3.2.1, the random number generation function was flawed.
In simple terms, this function produced predictable patterns instead of completely random numbers. As a result, the number of possible combinations for wallet recovery phrases was drastically reduced, allowing attackers to check potential options one by one using the processing power of ordinary computers.
The problem became more serious when CryptoJS was not directly visible in many software applications and was used as a software dependency in the background. Consequently, wallet developers might have been unaware of this flaw in their underlying infrastructure.
The First Wave of Theft; $3.14 Million in One Day
The first widespread wave of thefts occurred on May 27, 2026. Attackers targeted 431 accounts in just one day, extracting approximately $3.14 million in cryptocurrency.
Bitcoin accounted for the largest share of this loss, with about $2.57 million of the stolen assets related to this network. Ethereum followed with around $286,000, Rootstock with $177,000, Tron with $81,000, and Polygon with $23,000.
As investigations continued, the number of potentially affected wallets and software also increased.
Why Updating Wallets Is Not Enough to Save Assets?
One of the most important points about the Ill Bloom vulnerability is that updating software does not necessarily save users' assets.
If a wallet's recovery phrase was generated when the software was using a vulnerable version of CryptoJS, that recovery phrase has been weak from the start. Therefore, even if the developer later fixes the bug, the previous recovery phrase will still be predictable.
By August, the names of several wallets, including RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet, were mentioned among the affected software. Some of these projects, including Milo and RWallet, have even ceased operations.
However, the developers of Bitcoin Libre have fixed the flaw in older versions, and NanChat has released a new security patch. The new update for Bexo Wallet is still awaiting approval from app stores.
-- Price
What Should Users of Old Wallets Do?
Experts recommend that users who suspect their wallet's recovery phrase was generated with the vulnerable version of CryptoJS should not just settle for installing the latest software version. They should first check the public addresses associated with the wallet, and if any signs of danger are observed, assets should be transferred to a completely new wallet.
The important point is that users should not wait for a theft to occur to transfer their assets. If the previous recovery phrase can be guessed due to weaknesses in the random number generation process, an attacker can access the corresponding private key at any time.
For this reason, experts advise against keeping significant amounts in wallets whose recovery phrases were generated in a browser or using unreliable software infrastructure.
An Old Flaw, A Threat to Today's Wallet Security
The Ill Bloom saga once again shows that the security of a wallet is not solely dependent on its proprietary codes. Using a third-party library that seemingly has no direct relation to asset management can jeopardize the security of millions of users' private keys.
On the other hand, this attack has a significant difference from many common hacks: there is no need for direct penetration into the exchange server or the user's device. If the recovery phrase was generated insecurely from the start, an attacker can access the user's assets by reconstructing possibilities without physical access to the device.
For users, the message is clear; if a wallet has used a vulnerable infrastructure to generate its recovery phrase, creating a completely new wallet and transferring assets to it is the safest way to discard suspicious keys.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

10 Trillion Euros in Dormant Savings: What the EU Wants to Do with Your Money

XRP Ledger tested by BIS researchers for data checks

AI Inference Startup Wafer Raises $40 Million in Series A Funding, Valuation Exceeds $200 Million

2026's Most Wild DeFi Yield Strategies: No Betting on Explosive Growth, Just Harvesting On-Chain Speculation Fees
AI Wars II Is Here: WEEX Labs Launches Its Biggest Human vs. AI Trading Showdown Yet, Early Bird Round Opens Sept 3
WEEX Labs officially launches AI Wars II, the second season of its Human vs. AI trading championship. Early bird registration opens Sept 3-6, with the first 20,000 users sharing a 100,000 USDT prize pool. Register now.

No Matter Whether Warsh Raises Rates or Not, He is Definitely One of Us

Wall Street Morning Brief: U.S. Treasury Sell-off Pauses, U.S. Stocks Rise, Software Stocks and Japanese Bond Auction Hide Concerns

MUFG and Progmat Begin Proof-of-Concept for Tokenized Investment Trusts in Real Environment

How Uniswap's Fee Switch Redefined Revenue

Current Status Ahead of Litecoin's Next Halving

Jobs, Warsh, and the FedWatch Reversal: What Comes Next for Bitcoin?
Kevin Warsh’s hawkish Jackson Hole speech has flipped the market’s September Fed expectations from “hold” toward a possible rate hike. With the August jobs report, CPI, and the FOMC decision arriving in quick succession, Bitcoin is entering a two-week macro stress test.

No Need to Switch Platforms or Move Funds: BiFu Allows Crypto Traders to Trade Gold and Forex Directly

Palantir CEO: AI Sovereignty Depends on Control of Application Layer

What Kind of Blockchain Does Finance Really Need When Throughput Is No Longer a Bottleneck?

From a Loss of 1.1 Million to a Profit of 10 Million in 10 Months: A Review of Hyperliquid Arbitrage by Two Individuals

H3 Max Turbo Released, Speed Increased by 2.5 Times, Price Reduced to $0.01 per Second

Debt Expansion and Currency Shuffle: The Biggest Beta Opportunity in the Crypto Market According to Hayes

Bitwise: Bitcoin Decouples from US Stocks, Officially Enters Digital Gold Pricing Cycle

Which Altcoins Benefit from the Popularity of Robinhood Chain Without Issuing Tokens?

Last Night, Silicon Valley Experienced a Battle of AI Titans
Leverage, Ferraris, and the Law of Attraction: Carl Moon’s "First Life" | WE TALK by WEEX
From a supermarket clerk in Northern Europe to a trader, racer, and musician who dictates his own destiny, Carl Moon’s story isn’t a simple get-rich-quick fantasy. It’s a long-term, self-driven game of goals, discipline, and risk control.

Kimi's Parent Company Moonlight Dark Side Launches Hong Kong IPO with Valuation of $50 Billion

What is 'Red September'? The Bitcoin Curse and Why Wall Street Can't Escape It

Hugging Face Founder Hopes Everyone Can Train Robots in the Future

A New Study Refutes the 'Bank Collapse Theory' in the Crypto Circle

U.S. Treasury Becomes a 'Shadow Central Bank', Eroding the Independence of Federal Reserve Monetary Policy

An AI Training Data Startup Just Became Y Combinator's Fastest-Ever Unicorn

Sam Price: The Impact of the Dollar on the Crypto Market

Magalu on Mercado Livre: What the Partnership Reveals About E-commerce

Wholesale Dollar Falls but Remains Above $1.510 as Market Anticipates Greater Pressures
10 Trillion Euros in Dormant Savings: What the EU Wants to Do with Your Money
XRP Ledger tested by BIS researchers for data checks
AI Inference Startup Wafer Raises $40 Million in Series A Funding, Valuation Exceeds $200 Million
2026's Most Wild DeFi Yield Strategies: No Betting on Explosive Growth, Just Harvesting On-Chain Speculation Fees
AI Wars II Is Here: WEEX Labs Launches Its Biggest Human vs. AI Trading Showdown Yet, Early Bird Round Opens Sept 3
WEEX Labs officially launches AI Wars II, the second season of its Human vs. AI trading championship. Early bird registration opens Sept 3-6, with the first 20,000 users sharing a 100,000 USDT prize pool. Register now.









