News
Public · Published
New Bug Targets Web-Based Crypto Wallets: How 12-Year-Old Code Bug Cost Investors $5.7 Million
A 12‑year‑old vulnerability in the CryptoJS library was exploited in the "Ill Bloom" attack, compromising seed phrases and draining about $5.7 million from roughly 2,100 web‑based crypto wallets; app updates cannot recover the lost funds.
Published:
Updated:
What happened
A 12‑year‑old vulnerability in the CryptoJS library was exploited in the “Ill Bloom” attack, compromising seed phrases and draining about $5.7 million from roughly 2,100 web‑based crypto wallets; app updates cannot recover the lost funds.
Confirmed
Global impact / market context
The breach shows that old open‑source code can still expose modern crypto services to theft, raising concerns for investors about the security of web wallets and the need for rigorous code audits.
Analyst inference
Crypto investors are already wary after recent high‑profile hacks; this incident adds pressure on wallet providers to improve security, which could affect user adoption and the valuation of platforms relying on CryptoJS.
Analyst inference
What to watch
- Whether wallet developers replace CryptoJS with newer, audited libraries, which would reduce exposure to legacy bugs and improve user confidence. Proposed
- Regulatory responses that may require stricter security standards for crypto wallet providers, potentially increasing compliance costs. Proposed
- Investor sentiment toward crypto‑related stocks and tokens, as repeated security failures could depress demand and lower market prices. Analyst inference