A major series of coordinated thefts has been recorded on the crypto market, exposing a hidden threat at the very foundation of the security of popular web and mobile wallets. Due to an old bug in the CryptoJS JavaScript library, hackers were able to brute-force users’ secret seed phrases using ordinary home computers.
The vulnerability, codenamed Ill Bloom, has already led to the draining of more than 2,100 addresses across the Bitcoin, Ethereum, Tron, Rootstock and Polygon networks. Total losses to date have exceeded $5.7 million.
Normally, a 12-word seed phrase is a cryptographically secure lock that would take billions of years to crack. However, in CryptoJS library versions 3.x, starting with 3.1.2, with the exception of 3.2.0 and 3.2.1, the random number generation function was defective.
Instead of producing full-fledged digital randomness, it generated predictable combinations, narrowing seed phrase security down to an extremely limited range of possible variants.
The situation was made worse by the fact that CryptoJS was shipped “under the hood” of hundreds of other software packages, while wallet developers had been using it blindly for years.
The first wave of mass thefts took place on May 27, 2026, when 431 accounts were hit in just one day and attackers withdrew $3.14 million at once. Bitcoin holders took the largest hit, losing $2.57 million, while the remaining losses were distributed across Ethereum ($286,000), Rootstock ($177,000), Tron ($81,000) and Polygon ($23,000).
Updates won’t help: How to save your crypto from “Ill Bloom”
By August, the list of confirmed affected applications had expanded to include RWallet (RRWallet), Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet. Some of them, including Milo and RWallet, have already shut down, leaving users without support.
Bitcoin Libre developers fixed the bug in earlier versions, NanChat released a fresh patch, while an update for Bexo Wallet is still awaiting approval in app stores.
The dangerous part of the Ill Bloom vulnerability is that simply updating a wallet application does not protect the funds. If a seed phrase was originally generated by the defective system, it remains mathematically compromised forever.
Experts are urging investors to check their public addresses and, if a threat is detected, immediately migrate to new wallets, completely avoiding the storage of large amounts in wallets whose keys were generated inside a browser.


