Skip to main content
Sign in

CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)

avoid.net/cryptojs-ill-bloom-weak-rng-multi-wallet-drain-cve-2026-718514/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

CVE-2026-71851, designated 'Ill Bloom' by Coinspect, is a critical (CVSS 9.0) cryptographic vulnerability in the crypto-js npm library affecting versions 3.1.2-4 through 3.3.x, in which the library's CryptoJS.lib.WordArray.random() function used a Math.random()-seeded Multiply-With-Carry algorithm rather than a cryptographically secure PRNG, collapsing intended 128-bit entropy to approximately 2^39 bits. Active exploitation was identified from May 27, 2026, with measured losses of at least $5.69 million across at least 2,114 vulnerable wallet addresses tied to five named applications: RRWallet, Milo (both discontinued), Bexo Wallet, NanChat, and Bitcoin Libre. Public CVE disclosure occurred on August 5–7, 2026, following a staged disclosure process by Coinspect.

Connected Entities

1 entities · 10 linked investigations
Organizations
CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)
Relationships
  • + 4 more
Have evidence about CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)?

Timeline(14 events)

2014-06-19

Vulnerable Multiply-With-Carry PRNG seeded by Math.random() introduced into crypto-js codebase.

CVEReports / Coinspect

2020-02-10

A flawed wrapper patch committed to crypto-js; did not fully resolve the entropy issue.

CVEReports

2020-05-01

crypto-js version 4.0.0 released, permanently restoring native cryptographic randomness and resolving the vulnerability for new users.

CVEReports / The Hacker News

2023-01-01

crypto-js library becomes effectively unmaintained. Versions prior to 4.0.0 remain in use across downstream npm packages.

CVEReports / Coinspect

2026-05-01

Coinspect identifies active wallet drain exploitation linked to the weak PRNG; internal investigation begins.

CVEReports

2026-05-27

First large-scale coordinated sweep: 431 wallet accounts drained in one day, totaling approximately $3.14 million. Bitcoin losses represent $2.57 million of the total.

The Hacker News / CoinGeek / CoinTurk

2026-05-30

Second exploitation wave begins, continuing through July 13, 2026. 522 additional seeds drained for approximately $2.55 million.

The Hacker News

2026-06-10

Coinspect identifies additional exposed funds but is unable to alert the wallet owner in time to prevent subsequent drain.

The Hacker News (July disclosure article)

2026-06-30

Coinspect confirms 2,114 exposed addresses identified across multiple blockchains.

CoinGeek / TradingView / Cointelegraph

2026-07-04

Single Tron-based account loses approximately $2.18 million in USDT in a drain event during the second sweep.

The Hacker News

2026-07-06

Coinspect publishes initial partial disclosure of the Ill Bloom vulnerability; illbloom.org address-checker tool released. Security firm SlowMist acknowledges monitoring.

Cryptonomist / CoinGeek / Crypto Briefing / TechTimes

2026-07-13

Second exploitation sweep ends, per Coinspect's on-chain analysis.

The Hacker News

2026-07-20

Drains targeting Chinese-mnemonic wallets documented on July 20–21, 2026.

illbloom.org

2026-08-05

Full technical disclosure published by Coinspect, naming all five affected wallet applications and linking the root cause explicitly to crypto-js. GitHub Advisory GHSA-rg76-677x-56q9 and CVE-2026-71851 formally published.

The Hacker News / CVEReports / Coinspect
Provenance & Audit Trail
14 Wayback Archives

Decision Log

  • #1publish⛓ pending8/7/2026, 11:17:44 PM
    hash: 71v5SYqKhiEcF6C6oq4VfG2BqSRBMzdGpT8aZt5bPLtb

14 of 16 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/7/2026, 11:17:32 PM

last updated: 8/8/2026, 4:12:20 AM

avoid.net — verified advice for a post-truth world