12-Year-Old Code Bug Strikes Web Crypto Wallets, Costing Investors $5.7 Million

NewsFri, 07 Aug 2026 20:56:05 UTC2 hours ago
12-Year-Old Code Bug Strikes Web Crypto Wallets, Costing Investors $5.7 Million

TL;DR:

  • The vulnerability named “Ill Bloom” affects more than 2,100 digital wallets distributed across the Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks.
  • Cumulative losses from this security flaw exceed $5.7 million as of early August 2026.
  • The technical issue originates from a defect in random number generation in older versions of the JavaScript CryptoJS library.

A security flaw detected in an old code library compromised the security of multiple web crypto wallets and mobile applications. Thanks to this weakness, hackers managed to guess seed phrases and steal millions of dollars from affected users across various blockchain networks.

A Historical Software Error Compromises Cryptographic Keys

A market report reveals that a vulnerability identified as “Ill Bloom” compromised the security of several digital custody applications. The origin of the incident dates back to a flaw in versions 3.x of the JavaScript library CryptoJS, which has been in use for over 12 years. According to cybersecurity analyses cited in the report, the function responsible for generating random numbers within that software package did not work properly.

… Continue reading the full article at the original source below.

Read from Source · crypto-economy.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (crypto-economy.com).

Related