Loading market data...

CryptoJS Bug Exploited in 'Ill Bloom' Attack, $5.7M Stolen from 2,100 Wallets

CryptoJS Bug Exploited in 'Ill Bloom' Attack, $5.7M Stolen from 2,100 Wallets

A security exploit has drained $5.7 million from more than 2,100 web-based crypto wallets, and the root cause is a 12-year-old bug in the CryptoJS library. The attack, dubbed 'Ill Bloom,' exposed seed phrases that can't be fixed by a software update. Here's what we know.

The 'Ill Bloom' exploit

The numbers are stark: 2,100+ wallets hit, $5.7 million gone. The attack targeted web-based wallets, which handle keys in the browser using JavaScript libraries like CryptoJS. The exact method hasn't been fully disclosed, but the outcome is clear — the attackers walked away with