CVE-2026-71851, also known as Ill Bloom, is an insufficient-entropy vulnerability in crypto-js versions before 4.0.0, except 3.2.0 and 3.2.1. CryptoJS.lib.WordArray.random() used a custom Multiply-With-Carry pseudorandom-number generator seeded from JavaScript Math.random() rather than a platform CSPRNG. Introduced in version 3.1.2-4 and present in most subsequent 3.x releases, the implementation reduces the effective search space of nominal 128-bit and 256-bit requests to approximately 2^39 and 2^47 possibilities, respectively. The weakness is consequential when this API supplies cryptographic secret material, particularly BIP39 mnemonic entropy.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 20-file C repository is an operational offline cryptocurrency-wallet recovery/sweeping tool, described as a CVE-2026-71851-class weak-RNG research utility. Its primary executable, `sweephit.c`, enumerates inclusive-start/exclusive-end uint32 seed ranges across 16 PRNG schemes: MT19937 byte-order/byte-selection variants, glibc random(), Java Random, LCG variants, xorshift32, glibc 31-bit LCG variants, and CryptoJS 3.3.0 `WordArray.random` MWC ports (schemes 14-15). For every candidate seed it obtains 16 entropy bytes, converts them using the included English BIP39 word list, applies PBKDF2-HMAC-SHA512 with the standard `mnemonic` salt, creates the BIP32 master node with HMAC-SHA512 key `Bitcoin seed`, derives m/44'/coin'/0'/0/0, and compares the resulting 20-byte Ethereum address (default) or Bitcoin HASH160 identifier against supplied victim data. Matching candidates expose the seed and entropy necessary to regenerate wallet secrets. The repository includes self-contained SHA-1/SHA-2, SHA-3/Keccak, HMAC, PBKDF2, RIPEMD-160, memory-zeroing, and BIP39 support code, and links against `libsecp256k1` for public-key derivation. No blockchain RPC, exchange, wallet, HTTP, DNS, socket, or other runtime network communication exists in the exploit binary; victim identification is entirely local-file based. A manually dispatched GitHub Actions workflow compiles the tool, validates it against a canary, partitions the complete 0..4294967295 seed space across up to 64 jobs, executes selected schemes, and uploads shard hit results. The workflow's cloud execution can scale the brute-force activity but does not itself contact blockchain targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Weak-randomness vulnerability in CryptoJS.lib.WordArray.random() in which a Multiply-With-Carry PRNG was used instead of a system CSPRNG. When its output was used as BIP39 wallet entropy, it reduced effective entropy from 128/256 bits to approximately 39/47 bits, enabling practical enumeration of recovery phrases and derivation of wallet keys and addresses.
Insufficient-entropy vulnerability in CryptoJS WordArray.random() affecting vulnerable CryptoJS versions prior to 4.0.0. The MWC PRNG seeded via Math.random() can reduce effective mnemonic-entropy search spaces to approximately 2^39 for nominal 128-bit requests and 2^47 for nominal 256-bit requests, allowing attackers to enumerate wallet seeds, derive addresses and private keys, and steal assets.
An insufficient-entropy vulnerability in CryptoJS WordArray.random() affecting crypto-js versions below 4.0.0. Its MWC-based random-number generation can produce predictable or brute-forceable secret material, including BIP39 wallet entropy, rather than cryptographically secure randomness.
Недостаточная энтропия в CryptoJS: CryptoJS.lib.WordArray.random() использовал предсказуемый Multiply-With-Carry PRNG, инициализированный Math.random(), вместо CSPRNG. Это могло сделать BIP39 recovery phrases и производные HD-кошельки перебираемыми, сокращая эффективное пространство энтропии примерно до 2^39 для номинально 128-битной энтропии и 2^47 для 256-битной.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.