CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)
Summary
CVE-2026-71851, designated 'Ill Bloom' by Coinspect, is a critical (CVSS 9.0) cryptographic vulnerability in the crypto-js npm library affecting versions 3.1.2-4 through 3.3.x, in which the library's CryptoJS.lib.WordArray.random() function used a Math.random()-seeded Multiply-With-Carry algorithm rather than a cryptographically secure PRNG, collapsing intended 128-bit entropy to approximately 2^39 bits. Active exploitation was identified from May 27, 2026, with measured losses of at least $5.69 million across at least 2,114 vulnerable wallet addresses tied to five named applications: RRWallet, Milo (both discontinued), Bexo Wallet, NanChat, and Bitcoin Libre. Public CVE disclosure occurred on August 5–7, 2026, following a staged disclosure process by Coinspect.
Connected Entities
1 entities · 10 linked investigations- + 4 more
Timeline(14 events)
2014-06-19
Vulnerable Multiply-With-Carry PRNG seeded by Math.random() introduced into crypto-js codebase.
CVEReports / Coinspect2020-02-10
A flawed wrapper patch committed to crypto-js; did not fully resolve the entropy issue.
CVEReports2020-05-01
crypto-js version 4.0.0 released, permanently restoring native cryptographic randomness and resolving the vulnerability for new users.
CVEReports / The Hacker News2023-01-01
crypto-js library becomes effectively unmaintained. Versions prior to 4.0.0 remain in use across downstream npm packages.
CVEReports / Coinspect2026-05-01
Coinspect identifies active wallet drain exploitation linked to the weak PRNG; internal investigation begins.
CVEReports2026-05-27
First large-scale coordinated sweep: 431 wallet accounts drained in one day, totaling approximately $3.14 million. Bitcoin losses represent $2.57 million of the total.
The Hacker News / CoinGeek / CoinTurk2026-05-30
Second exploitation wave begins, continuing through July 13, 2026. 522 additional seeds drained for approximately $2.55 million.
The Hacker News2026-06-10
Coinspect identifies additional exposed funds but is unable to alert the wallet owner in time to prevent subsequent drain.
The Hacker News (July disclosure article)2026-06-30
Coinspect confirms 2,114 exposed addresses identified across multiple blockchains.
CoinGeek / TradingView / Cointelegraph2026-07-04
Single Tron-based account loses approximately $2.18 million in USDT in a drain event during the second sweep.
The Hacker News2026-07-06
Coinspect publishes initial partial disclosure of the Ill Bloom vulnerability; illbloom.org address-checker tool released. Security firm SlowMist acknowledges monitoring.
Cryptonomist / CoinGeek / Crypto Briefing / TechTimes2026-08-05
Full technical disclosure published by Coinspect, naming all five affected wallet applications and linking the root cause explicitly to crypto-js. GitHub Advisory GHSA-rg76-677x-56q9 and CVE-2026-71851 formally published.
The Hacker News / CVEReports / CoinspectDecision Log
- #1publish⛓ pending8/7/2026, 11:17:44 PMhash: 71v5SYqKhiEcF6C6oq4VfG2BqSRBMzdGpT8aZt5bPLtb
14 of 16 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/7/2026, 11:17:32 PM
last updated: 8/8/2026, 4:12:20 AM
avoid.net — verified advice for a post-truth world