EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Internet wallet security breach caused the theft of US$5.7 million in multi-chain cryptocurrency

2026-08-08 12:09:27
Bookmark

Research reveals that CryptoJS vulnerability resulted in the theft of more than $5.7 million in cryptocurrency

Researchers have linked the CryptoJS vulnerability to a series of organized cryptocurrency thefts involving Bitcoin, Ethereum, Wave Field, Polygon and Rootstock networks, with a total loss of more than $5.7 million and affecting thousands of wallets. Due to flaws in random number generation, the security of mnemonic words is weakened, and attackers can violently crack vulnerable wallets using ordinary consumer-grade computers without using professional hardware. Developers have released patches for multiple affected wallets, but experts are urging users to transfer funds to newly generated secure wallets.

Vulnerability Details: Security risks related to the CryptoJS library

Researchers named the vulnerability "Ill Bloom" and traced it to outdated versions of CryptoJS used by multiple wallet developers over the years. Rather than directly attacking the blockchain infrastructure, the attacker used the regularity of mnemonic generation to recover private keys from ordinary consumer-grade computers rather than expensive professional hardware. The standard 12-word mnemonic words were supposed to provide strong encryption protection, making brute force cracking almost impossible. However, since version 3.1.2 (except versions 3.2.0 and 3.2.1), CryptoJS has been insufficiently random when generating wallets, resulting in a significant reduction in the number of possible mnemonic word combinations, allowing attackers to efficiently identify vulnerable mnemonic words. Protection that would have taken billions of years to crack can now be completed by ordinary computers in a reasonable time. The vulnerability has widespread impact because the affected CryptoJS library is integrated into hundreds of software packages, and many wallet developers are not aware of serious flaws in the underlying random number generator.

Largest attack: A single theft of more than US$3 million

The largest organized attack occurred on May 27, 2026. In one operation, hackers breached 431 wallet addresses and stole approximately US$3.14 million in digital assets. Bitcoin holders lost the most, about $2.57 million; Ethereum users lost about $286,000;Rootstock users lost nearly $177,000; wavefield users lost about $81,000; and Polygon holders lost about $23,000.

Response measures for affected wallet developers

As of August, investigators have confirmed that more than 2100 wallet addresses have been compromised, and multiple wallet providers have taken different security measures. Researchers found that affected apps include RWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet, but each developer handles it differently. Milo Wallet and RWallet shut down services after discovering the vulnerability, Bitcoin Libre fixed the vulnerability in an earlier version, and NanChat released a software update. At the same time, Bexo Wallet has completed security fixes, but users still have to wait for review by the mobile app store before receiving updates.

Experts advise: Migrate to a newly generated wallet immediately

Security experts warn that simply installing software updates will not eliminate the underlying risks, because mnemonics generated through the flawed CryptoJS library will remain permanently vulnerable. Therefore, users who create wallets using affected applications should immediately transfer assets to newly generated wallets using security software, while avoiding long-term storage of large amounts of cryptocurrency in browser-generated wallets associated with vulnerable versions of CryptoJS. The Ill Bloom incident demonstrated how weaknesses in widely used software libraries have quietly spread to many cryptocurrency applications, ultimately exposing core issues through organized attacks. The incident also highlighted the importance of secure random number generation-a software dependency that ultimately puts thousands of cryptocurrency wallets and millions of dollars in digital assets at risk.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP