CryptoJS weak RNG wallet drains ("Ill Bloom") hack — May 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | August 5, 2026 |
| Target type | Wallet software or provider |
| Loss | $5,690,922Price at time of incident |
| Method | Private key compromiseRecovery phrases generated with CryptoJS.lib.WordArray.random(), whose 128- and 256-bit requests collapsed to search spaces of roughly 2^39 and 2^47, were enumerated offline |
| Chains | Multiple chains |
| Outcome | Unresolved |
What happened
Coinspect published a disclosure on 5 August 2026 tying a series of wallet drains it calls Ill Bloom to a weak random number generator inside CryptoJS, a JavaScript cryptography library that five wallet applications had used to generate BIP39 recovery phrases. Requests for 128 or 256 bits of entropy produced effective search spaces of roughly 2^39 and 2^47 possibilities, small enough to enumerate on ordinary hardware, derive the corresponding addresses, and check them against public chain data.
The flaw was not new. A Multiply-With-Carry generator seeded from Math.random() entered the library in June 2014. Releases 3.2.0 and 3.2.1 switched to native cryptographic randomness, 3.3.0 put the weak code back because the change was treated as breaking, and native randomness only returned for good in version 4.0.0 in February 2020. The advisory carries CVE-2026-71851 at CVSS 9.0.
Two drain waves are documented. A sweep on 27 May 2026 took about $3.14m from 431 accounts, and a second run between 30 May and 13 July 2026 took about $2.55m from addresses tied to 522 seeds, for measured losses of $5,690,922 through 13 July. Coinspect describes that as a lower bound, so the figure recorded here is a floor rather than a settled total.
The five affected applications were RRWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo. Bexo fixed the issue in v20.1.0, NanChat in v1.3.0 and Bitcoin Libre in v4; RRWallet and Milo are discontinued and no fix exists for either. Anyone who generated a seed in one of them should treat it as compromised. This incident is separate from the Coldcard seed entropy flaw recorded for 30 July 2026, which involved different software and a different vendor.
Sources
- crypto-js maintainers (GitHub Security Advisory)Primary · retrieved 2026-08-26
- GitHub Advisory Database (CVE-2026-71851)Primary · retrieved 2026-08-26
- The Hacker NewsSecondary · retrieved 2026-08-26
- Security OnlineSecondary · retrieved 2026-08-26
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "CryptoJS weak RNG wallet drains ("Ill Bloom") hack — May 2026", iTokenly, accessed 2026-08-26, https://itokenly.com/hacks/cryptojs-weak-rng-ill-bloomhttps://itokenly.com/hacks/cryptojs-weak-rng-ill-bloomPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.