Active exploitation of weak entropy in legacy CryptoJS versions enabled attackers to recover BIP39 wallet seed phrases and drain associated HD wallets. CryptoJS.lib.WordArray.random() in versions 3.1.2–4, including 3.1.8 and 3.1.9-1, used a Multiply-With-Carry generator seeded through non-cryptographic Math.random() rather than a CSPRNG. Researchers reported that this reduced the effective search space for nominally 128-bit and 256-bit mnemonic entropy to roughly 2^39 and 2^47, respectively, allowing attackers to enumerate candidate mnemonics, derive BIP32 wallet keys and addresses, and match them against public blockchain activity. Reported theft waves beginning in May 2026 caused at least $5.69 million in confirmed losses by mid-July.
Reportedly affected applications include RRWallet (RenrenBit), Bexo Wallet, NanChat versions before 1.3.0, Bitcoin Libre, and Milo; the affected-population list may not be complete. Upgrading to CryptoJS 4.0.0 or replacing legacy randomness with browser Web Crypto or Node.js crypto prevents generation of new weak secrets, as version 4.0.0 uses native cryptographic randomness and fails if none is available. It does not secure existing mnemonics: organizations and users that generated wallet seeds with potentially affected software should create a new seed using a system CSPRNG, transfer all assets to addresses derived from it, and audit legacy CryptoJS use for weak keys, salts, IVs, nonces, tokens, and session identifiers.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
The second wave ran through July 13 and was estimated at roughly $2.55 million. Combined measurable losses from the two waves reached at least $5,690,922 by that date.
A second wave of withdrawals began, ultimately involving 522 seed phrases. It was attributed to attackers reproducing the weak entropy-generation process and deriving BIP39 and HD-wallet addresses for on-chain matching.
Two waves of cryptocurrency theft associated with weak CryptoJS-generated wallet entropy began on May 27. The first wave affected 431 account or address states and was estimated to have caused about $3.14 million in losses.
Coinspect began investigating the Ill Bloom incident after serial withdrawals from wallets across multiple blockchain networks. Its analysis tied the activity to CryptoJS weak entropy rather than a break of secp256k1 or ECDLP.
Bitcoin Libre reported fixing the issue in version 4, though seed phrases generated by prior versions remained at risk because the original weak entropy could not be repaired.
CryptoJS 4.0.0 restored use of native cryptographic random APIs and fails when no supported CSPRNG is available, rather than silently generating predictable values. The release did not remediate secrets generated by earlier vulnerable versions.
CryptoJS version 3.1.2-4 introduced a WordArray.random() implementation based on a Multiply-With-Carry generator seeded through Math.random(), rather than a cryptographically secure random source.
Ill Bloom Research linked CVE-2026-71851 to CryptoJS.lib.WordArray.random() using an MWC-style PRNG for cryptographically sensitive values. The disclosure estimated effective search spaces of about 2^39 states for nominal 128-bit BIP39 entropy and 2^47 for nominal 256-bit entropy, enabling offline candidate verification against derived public addresses.
Coinspect conducted phased coordinated disclosure with relevant parties, shared affected-address evidence, and launched a public address checker for the Ill Bloom issue.
Bexo Wallet reported a fix in version 20.1.0, while NanChat fixed the issue in version 1.3.0 and provided migration support. These updates prevent new weak secrets but do not secure seed phrases created before patching.
Coinspect confirmed that RRWallet (RenrenBit), Bexo Wallet, NanChat, Bitcoin Libre, and Milo had been affected by the weak CryptoJS entropy path, while warning the list was not exhaustive.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
polynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcepolynonce.ru
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.