U.Today reported on Sunday that a vulnerability in the CryptoJS JavaScript library, present in digital wallets for 12 years, allowed hackers to decipher users' seed phrases and steal more than US$ 5.7 million in cryptocurrencies.

The flaw, named Ill Bloom, affects CryptoJS 3.x versions, from 3.1.2 onward, except versions 3.2.0 and 3.2.1. The random number generation function in these versions produced predictable combinations, drastically reducing the security of 12-word phrases.

More than 2,100 addresses on the Bitcoin, Ethereum, Tron, Rootstock and Polygon networks were drained. In the first wave of attacks, on May 27, 2026, 431 accounts were hit in a single day, with withdrawals of US$ 3.14 million. The biggest losses were suffered by Bitcoin holders, who lost US$ 2.57 million.

The remaining losses totaled US$ 286,000 in Ethereum, US$ 177,000 in Rootstock, US$ 81,000 in Tron and US$ 23,000 in Polygon.

The list of affected applications includes RWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet. Some, such as Milo and RWallet, have already ceased operations, leaving users without support. Bitcoin Libre fixed the flaw in earlier versions, NanChat released a patch, and the Bexo Wallet update is still awaiting approval in app stores.

Updating does not fix the problem

Experts warn that simply updating the wallet does not protect the funds. If the seed phrase was generated by the flawed system, it remains mathematically compromised. The recommendation is to check public addresses and, if there is risk, migrate immediately to new wallets, avoiding storing large amounts in wallets whose keys were generated in the browser.

More from Radar