Blockchain security firm Coinspect has identified a critical vulnerability in the popular JavaScript cryptography library CryptoJS, specifically in the CryptoJS.lib.WordArray.random() function, which has been used as an entropy source for generating recovery phrases in multiple cryptocurrency wallet applications. The weakness, introduced over a decade ago, reduced the effective entropy of generated phrases from 2^128 or 2^256 to roughly 2^39 or 2^47, making them enumerable on ordinary hardware.
Coinspect’s on-chain analysis attributes at least $5.7 million in cryptocurrency thefts to this flaw, which they have dubbed ‘Ill Bloom.’ The attacks occurred in two waves: a May 27 sweep that took approximately $3.14 million from 431 accounts, and a second run between May 30 and July 13 that stole $2.55 million from addresses tied to 522 seeds. The analysis tracks 2,114 identified seeds across Bitcoin, Ethereum, Tron, Rootstock, and Polygon.
Five wallet applications have been confirmed as affected: RRWallet (discontinued, no fix), Bexo Wallet (fixed in version 20.1.0, but builds not yet uploaded), NanChat (fixed in version 1.3.0), Bitcoin Libre (fixed in version 4, released July 2024), and Milo (discontinued, no fix). Coinspect cautions that other vulnerable wallets may exist but could not be examined because they were removed from app stores or replaced with patched versions.
The vulnerability was publicly disclosed via GitHub advisory GHSA-rg76-677x-56q9 on August 5, 2026, with a Critical rating and a CVSS score of 9.0. The advisory notes that all CryptoJS releases below 4.0.0 are affected, despite exceptions in 3.2.0 and 3.2.1 which used native cryptographic randomness. Version 3.3.0 reverted to the weak code, and version 4.0.0 permanently restored native randomness in February 2020.
Coinspect advises users who generated recovery phrases using affected wallet versions to consider those phrases compromised and to create new ones securely, as updating the app does not repair an existing phrase. The firm has also released a public checker that accepts wallet addresses to determine if they are at risk.
CVEs: CVE-2026-XXXXX, CVE-2026-50522
Attack groups: Ill Bloom
Companies: Coinspect, The Hacker News
Products: CryptoJS, RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, Milo
Original source: thehackernews.com