Skip to main content
AVOID.NET

CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)

avoid.net/cryptojs-ill-bloom-weak-rng-multi-wallet-drain-cve-2026-718514/100·88% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5ctRxG…TbHt

Summary

CVE-2026-71851, designated 'Ill Bloom' by Coinspect, is a critical (CVSS 9.0) cryptographic vulnerability in the crypto-js npm library affecting versions 3.1.2-4 through 3.3.x, in which the library's CryptoJS.lib.WordArray.random() function used a Math.random()-seeded Multiply-With-Carry algorithm rather than a cryptographically secure PRNG, collapsing intended 128-bit entropy to approximately 2^39 bits. Active exploitation was identified from May 27, 2026, with measured losses of at least $5.69 million across at least 2,114 vulnerable wallet addresses tied to five named applications: RRWallet, Milo (both discontinued), Bexo Wallet, NanChat, and Bitcoin Libre. Public CVE disclosure occurred on August 5–7, 2026, following a staged disclosure process by Coinspect.

Connected Entities

6 entities · 60 linked investigations
Organizations
Polygon54Ethereum64Trezor57Ill Bloom Vulnerability0CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)
Tokens
Relationships
  • Ethereummentioned withBitcoin(60%)
  • CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)mentioned withBitcoin(70%)
  • CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)mentioned withPolygon(65%)
  • CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)mentioned withTrezor(60%)
  • CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)mentioned withEthereum(65%)
  • Trezormentioned withBitcoin(65%)
  • Trezormentioned withEthereum(60%)
  • CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)mentioned withIll Bloom Vulnerability(80%)
  • Polygonmentioned withEthereum(70%)
  • Ill Bloom Vulnerabilitymentioned withBitcoin(70%)
  • + 2 more
Have evidence about CryptoJS Ill Bloom — Weak RNG Multi-Wallet Drain (CVE-2026-71851)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

Timeline(14 events)

19 June 2014

Vulnerable Multiply-With-Carry PRNG seeded by Math.random() introduced into crypto-js codebase.

CVEReports / Coinspect

10 February 2020

A flawed wrapper patch committed to crypto-js; did not fully resolve the entropy issue.

CVEReports

May 2020

crypto-js version 4.0.0 released, permanently restoring native cryptographic randomness and resolving the vulnerability for new users.

CVEReports / The Hacker News

2023

crypto-js library becomes effectively unmaintained. Versions prior to 4.0.0 remain in use across downstream npm packages.

CVEReports / Coinspect

May 2026

Coinspect identifies active wallet drain exploitation linked to the weak PRNG; internal investigation begins.

CVEReports

27 May 2026

First large-scale coordinated sweep: 431 wallet accounts drained in one day, totaling approximately $3.14 million. Bitcoin losses represent $2.57 million of the total.

The Hacker News / CoinGeek / CoinTurk

30 May 2026

Second exploitation wave begins, continuing through July 13, 2026. 522 additional seeds drained for approximately $2.55 million.

The Hacker News

10 June 2026

Coinspect identifies additional exposed funds but is unable to alert the wallet owner in time to prevent subsequent drain.

The Hacker News (July disclosure article)

30 June 2026

Coinspect confirms 2,114 exposed addresses identified across multiple blockchains.

CoinGeek / TradingView / Cointelegraph

4 July 2026

Single Tron-based account loses approximately $2.18 million in USDT in a drain event during the second sweep.

The Hacker News

6 July 2026

Coinspect publishes initial partial disclosure of the Ill Bloom vulnerability; illbloom.org address-checker tool released. Security firm SlowMist acknowledges monitoring.

Cryptonomist / CoinGeek / Crypto Briefing / TechTimes

13 July 2026

Second exploitation sweep ends, per Coinspect's on-chain analysis.

The Hacker News

20 July 2026

Drains targeting Chinese-mnemonic wallets documented on July 20–21, 2026.

illbloom.org

5 August 2026

Full technical disclosure published by Coinspect, naming all five affected wallet applications and linking the root cause explicitly to crypto-js. GitHub Advisory GHSA-rg76-677x-56q9 and CVE-2026-71851 formally published.

The Hacker News / CVEReports / Coinspect
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 15 of 16 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/7/2026, 11:17:32 PM

last updated: 8/27/2026, 3:34:06 AM

7 views

avoid.net — verified advice for a post-truth world