COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Hackers exploit CryptoJS flaw to steal $5.7 million from 2,100 crypto wallets
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > Hackers exploit CryptoJS flaw to steal $5.7 million from 2,100 crypto wallets
Cryptocurrency News

Hackers exploit CryptoJS flaw to steal $5.7 million from 2,100 crypto wallets

In Brief

  • 🚨 Hackers stole $5.7 million from over 2,100 wallets using a CryptoJS library flaw.

  • 💼 Affected wallets span Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks.

  • 📱 Major wallet apps like RWallet, Bexo, and Milo are impacted, with some shutting down.

  • 🔍 Users generating $BTC keys with faulty libraries face lasting risk unless they migrate funds.
Dr. Levent Kurt
Dr. Levent Kurt 45 minutes ago
Share
SHARE

A wave of sophisticated thefts has shaken the cryptocurrency community, exposing a critical flaw affecting the core security of widely used web and mobile wallets. Attackers leveraged a longstanding vulnerability in the CryptoJS JavaScript library to brute-force secret seed phrases, compromising user funds with alarming ease.

1StepSwap
Tokenized Stock
PAY
USDT USDT
↓
RECEIVE
AAPL AAPL
Contents
Flaw in CryptoJS exposes hundreds of walletsImpacted wallets and user safeguards

Flaw in CryptoJS exposes hundreds of wallets

The vulnerability, identified as “Ill Bloom,” has been linked to the theft of assets from over 2,100 wallet addresses on major blockchain networks including Bitcoin, Ethereum, Tron, Rootstock, and Polygon. Losses attributed to this exploit have now surpassed $5.7 million.

Normally, a standard 12-word seed phrase is designed to be virtually unbreakable, requiring computational timescales beyond the age of the universe to crack. However, CryptoJS library versions 3.x, specifically those starting with 3.1.2 except for 3.2.0 and 3.2.1, had a critical defect in their random number generation functions.

This bug caused the affected versions to produce only weak pseudo-randomness, drastically reducing the number of possible seed phrase combinations and making brute-force attacks feasible even on ordinary home computers.

Compounding the problem, CryptoJS was quietly embedded within hundreds of software packages. Wallet developers widely integrated it without awareness, inadvertently exposing users across many applications.

More than 2,100 wallet addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon have fallen victim to Ill Bloom, with total losses above $5.7 million.

The first large-scale incident linked to Ill Bloom occurred on May 27, 2026, when attackers compromised 431 wallets in one day, siphoning off $3.14 million. Bitcoin investors suffered the greatest impact, losing $2.57 million. Ethereum, Rootstock, Tron, and Polygon users also faced significant losses, with values ranging from $23,000 to $286,000 across these networks.

Impacted wallets and user safeguards

By August, applications confirmed as affected included RWallet (also known as RRWallet), Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. Some projects, notably Milo and RWallet, have ceased operations, leaving users with no dedicated support channels.

Developers of Bitcoin Libre responded by patching the bug in earlier releases. NanChat has issued a new security fix for its users, while an update for Bexo Wallet was still under review in app stores at the time of reporting.

Security researchers warn that updating wallet applications alone is not enough to safeguard user assets. Seed phrases created on versions affected by Ill Bloom remain fundamentally vulnerable, as their entropy was compromised from the start.

Specialists recommend that users review all public addresses potentially exposed, and if risk is detected, immediately transfer funds to freshly generated wallets. They urge the community to avoid storing substantial sums in browsers or mobile wallets whose keys were created with unsafe libraries.

For investors aiming to minimize risks and closely monitor their digital assets, leveraging advanced portfolio tools is vital. CryptoAppsy, for example, eliminates account setup complexity and brings together investments, real-time pricing, and multi-currency management on a single platform. By using features such as smart price alerts, coin-specific news filtering, instant tracking of new altcoins, and macroeconomic data like Fed interest rates, users can remain vigilant and ready to react to changes in market conditions.

Experts emphasize that if a wallet’s seed phrase originated from the defective CryptoJS versions, only migrating to a new wallet that generates fresh keys can restore full security.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

FSB raids 9 Moscow crypto exchanges in Ukraine-linked fraud crackdown

White House considers ethics deal on crypto divestment for Trump, tax deferral possible

Crypto hacks surged to $247 million in July, Coldcard exploit leads losses

Japan FSA urges crypto exchanges to adopt withdrawal delays to combat scams

210,000 BTC move from long-term holders after Coldcard breach, ETF inflows rise

Dr. Levent Kurt 7 August, 2026 - 8:44 pm 7 August, 2026 - 8:44 pm
Share This Article
Facebook Twitter
Share
Dr. Levent Kurt
By Dr. Levent Kurt
Follow:
Levent Kurt, who has been closely following the cryptocurrency and blockchain ecosystem since 2013, is the Editor-in-Chief and Co-Founder of COINTURK.Kurt, who holds a Ph.D. in Data Science, conducts research on Bitcoin, altcoins, blockchain technologies, digital asset markets, data analysis, and global developments in the cryptocurrency sector. He is the author of “Cryptocurrency Bitcoin: In Pursuit of Financial Freedom”, published in 2015.In the news, analysis, and research published on COINTURK, he aims to provide readers with reliable and understandable information by combining a data-driven approach with market experience and an assessment of technological developments.
Previous Article Elizabeth Warren again opposes crypto bill, CLARITY Act seen likely to pass
Next Article Morgan Stanley holds $400 million in Bitcoin after three days of accumulation
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Coldcard wallet hack leads to $111 million Bitcoin theft, median loss of 1 BTC
Bitcoin (BTC)
Morgan Stanley holds $400 million in Bitcoin after three days of accumulation
Bitcoin (BTC)
Elizabeth Warren again opposes crypto bill, CLARITY Act seen likely to pass
Ripple (XRP)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?