A long-standing flaw in the CryptoJS JavaScript library has been tied to coordinated crypto thefts that have drained more than 2,100 addresses and over $5.7 million across five networks. The weakness, dubbed Ill Bloom, affected how some wallets generated 12-word seed phrases, reducing what should have been strong cryptographic randomness to a far narrower and more predictable set of combinations that attackers could brute-force with ordinary home computers. The issue spans CryptoJS versions 3.x beginning with 3.1.2, excluding 3.2.0 and 3.2.1, and has been linked to wallets including RWallet, Bexo Wallet, NanChat, Bitcoin Libre and Milo Wallet. The biggest known wave of thefts came on May 27, 2026, when 431 accounts were drained for $3.14 million, led by $2.57 million in Bitcoin losses. Experts say updating an app is not enough if the original seed phrase was created with the defective generator, because the key remains permanently compromised and funds should be moved to newly created wallets instead.