12-Year-Old Code Bug Strikes Web Crypto Wallets, Costing Investors $5.7 Million

fiverr
Bybit


TL;DR:

  • The vulnerability named “Ill Bloom” affects more than 2,100 digital wallets distributed across the Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks.
  • Cumulative losses from this security flaw exceed $5.7 million as of early August 2026.
  • The technical issue originates from a defect in random number generation in older versions of the JavaScript CryptoJS library.

A security flaw detected in an old code library compromised the security of multiple web crypto wallets and mobile applications. Thanks to this weakness, hackers managed to guess seed phrases and steal millions of dollars from affected users across various blockchain networks.

A Historical Software Error Compromises Cryptographic Keys

A market report reveals that a vulnerability identified as “Ill Bloom” compromised the security of several digital custody applications. The origin of the incident dates back to a flaw in versions 3.x of the JavaScript library CryptoJS, which has been in use for over 12 years. According to cybersecurity analyses cited in the report, the function responsible for generating random numbers within that software package did not work properly.

The technical specifications of the investigation indicate that the system did not create cryptographic combinations with full entropy. This limitation drastically reduced the range of mathematical possibilities needed to guess the 12 words of the recovery phrases. Under normal conditions, brute-forcing a seed phrase would take billions of years. However, due to this flaw, conventional home computers were able to complete the decryption process in short timeframes.

okex

Records show that the first massive wave of thefts occurred on May 27. On that day, a total of 431 accounts were drained in a short period, totaling an initial financial impact of $3.14 million. Bitcoin holders took the brunt of the hit, with estimated losses of $2.57 million. The remaining losses were distributed among users of Ethereum ($286,000), Rootstock ($177,000), Tron ($81,000), and Polygon ($23,000).

web-based crypto walletsweb-based crypto wallets

Software Update Limitations and Migration Recommendations

Applications such as RWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet integrated this defective library into their architecture. According to information provided by industry developers, CryptoJS was often included indirectly in multiple third-party software packages. This led several development teams to implement the code without realizing the underlying structural flaw for years.

Over recent months, responses from affected platforms have been mixed. According to report data, services like Milo Wallet and RWallet permanently shut down operations. On the other hand, projects like Bitcoin Libre and NanChat issued fix patches for their latest versions, while other applications are still awaiting approval for updates in mobile app stores.

Despite the published security patches, technical documentation emphasizes that updating the application does not invalidate the vulnerability of a previously generated seed phrase. According to market data, any cryptographic key generated under the flawed system remains mathematically exposed, regardless of patches applied to subsequent software. The nature of blockchain architecture prevents a private key that was compromised at its inception from regaining its default level of security.

Industry experts cited by the source suggest that users verify the origin of their addresses and immediately transfer funds to new wallets created outside web environments prone to the flaw. Tracking of the affected funds will continue as on-chain analytics firms monitor the movements of addresses linked to the attackers in the coming weeks.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*