Web Wallet Security Flaw Linked to $5.7 Million Crypto Theft Across Multiple Blockchains
0
0

- Researchers linked the CryptoJS vulnerability to coordinated cryptocurrency thefts exceeding $5.7 million across Bitcoin, Ethereum Tron Polygon Rootstock networks, affecting thousands.
- Faulty random number generation weakened seed phrase security, allowing attackers to brute-force vulnerable wallets using ordinary consumer computers instead of hardware.
- Developers released patches for several affected wallets, but experts urged users to migrate funds into newly generated secure wallets.
A long-standing vulnerability in the CryptoJS JavaScript library has been linked to coordinated cryptocurrency thefts exceeding $5.7 million, exposing a security weakness that affected thousands of wallets across multiple blockchain networks. Security researchers found that the flaw weakened recovery phrase generation in several applications, allowing attackers to compromise more than 2,100 addresses across Bitcoin, Ethereum, Tron, Polygon and Rootstock without targeting the underlying blockchains themselves.
Researchers identified the vulnerability as Ill Bloom and traced the attacks to outdated CryptoJS versions used by numerous wallet developers over several years. Instead of breaching blockchain infrastructure, hackers exploited predictable seed phrase generation, enabling them to recover private keys using ordinary consumer computers rather than expensive specialized hardware.
Also Read: Upbit Delists BONK Over Unresolved Security and Disclosure Concerns
Faulty random number generation weakened wallet security
A standard 12-word recovery phrase normally provides exceptionally strong cryptographic protection against brute-force attacks, making unauthorized access practically impossible under normal circumstances. However, CryptoJS versions beginning with 3.1.2, except for versions 3.2.0 and 3.2.1, generated insufficient randomness during wallet creation, significantly reducing the number of possible recovery phrase combinations available to attackers.
Consequently, hackers could identify vulnerable seed phrases far more efficiently than expected, turning what should have required billions of years into an attack that ordinary computers could realistically perform. The weakness spread widely because the affected CryptoJS library had been integrated into hundreds of software packages, while many wallet developers remained unaware that the underlying random number generator contained a serious flaw.
The largest coordinated attack occurred on May 27, 2026, when hackers compromised 431 wallet addresses and stole approximately $3.14 million in digital assets during a single operation. Bitcoin holders suffered the largest losses at roughly $2.57 million, while Ethereum users lost about $286,000, Rootstock users lost nearly $177,000, Tron users lost approximately $81,000, and Polygon holders lost around $23,000.
Affected wallet developers respond with security updates
By August, investigators had confirmed that more than 2,100 wallet addresses had been compromised, prompting several wallet providers to respond with different security measures. Researchers identified RWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet among the affected applications, although each developer handled the situation differently.
Milo Wallet and RWallet shut down their services following the discovery, while Bitcoin Libre corrected the flaw in earlier releases and NanChat distributed a software update. Meanwhile, Bexo Wallet completed its security fix, although users are still waiting for approval through mobile app stores before receiving the update.
Experts urge immediate migration to newly generated wallets
Security experts warned that installing a software update does not remove the underlying risk because recovery phrases created through the defective CryptoJS library remain permanently vulnerable. Consequently, users whose wallets originated from affected applications should immediately transfer their assets into newly generated wallets created with secure software, while avoiding the long-term storage of significant cryptocurrency holdings in browser-generated wallets linked to vulnerable CryptoJS versions.
The Ill Bloom incident demonstrates how weaknesses inside widely used software libraries can quietly spread across numerous cryptocurrency applications before coordinated attacks expose the underlying problem. It also highlights the importance of secure random number generation, as a single software dependency ultimately placed thousands of cryptocurrency wallets and millions of dollars in digital assets at risk.
Also Read: Michael Saylor Drops Bold Bitcoin Claim as Crypto Clarity Act Faces Major Delay
The post Web Wallet Security Flaw Linked to $5.7 Million Crypto Theft Across Multiple Blockchains appeared first on 36Crypto.
0
0
Securely connect the portfolio you’re using to start.







