A wallet-drain campaign dubbed Ill Bloom exploited weak entropy in CryptoJS.lib.WordArray.random() to steal at least $5.69 million from cryptocurrency users, according to Coinspect. The flaw affected wallet applications that used vulnerable versions of CryptoJS to generate recovery phrases, allowing attackers to guess seed phrases, derive wallet addresses, and drain funds. Coinspect linked two theft waves between May 27 and July 13 to the issue and identified five affected apps: RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo.
The underlying problem traces to a long-standing weakness in CryptoJS random-number generation, broadly covered by advisory GHSA-rg76-677x-56q9 for versions earlier than 4.0.0, though exploitation depended on whether developers used the function for security-sensitive seed generation. Coinspect warned that simply updating an affected wallet does not secure wallets already created with weak recovery phrases; users must generate a new secure seed phrase and move funds, and additional vulnerable wallet apps may still exist beyond the five publicly named.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
CryptoJS maintainer Evan Vosberg published advisory GHSA-rg76-677x-56q9 with a Critical rating and CVSS score of 9.0, warning that applications are affected if they used the vulnerable function for security-sensitive value generation.
Coinspect said the second wave ran through July 13 and stole $2.55 million in total from addresses tied to 522 seeds.
During the second drain wave, attackers stole about 2.18 million USDT from one Tron account on July 4.
Coinspect said a second Ill Bloom drain wave started on May 30, ultimately stealing funds from addresses tied to 522 seeds through July 13.
Coinspect said the first drain sweep occurred on May 27 and stole about $3.14 million from 431 accounts.
Bitcoin Libre fixed the vulnerable entropy issue in version 4. Coinspect said this release occurred in July 2024.
CryptoJS version 4.0.0 permanently switched back to native cryptographic randomness, removing the weak RNG implementation from the library.
A weak Multiply-With-Carry random-number generator seeded from Math.random() was introduced into CryptoJS, creating the entropy flaw later tied to the Ill Bloom wallet drains.
Coinspect disclosed that the Ill Bloom campaign stemmed from weak entropy in CryptoJS.lib.WordArray.random(), measured at least $5.69 million stolen, and named RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo as affected applications.
After releases 3.2.0 and 3.2.1 had switched to native cryptographic randomness, CryptoJS version 3.3.0 restored the weak random-number code because the earlier change was considered breaking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcereddit.com
Open sourcecoinspect.com
Open sourceillbloom.org
Open sourceillbloom.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.