Twelve-year-old CryptoJS bug still draining wallets because nobody updated anything
Coinspect's 'Ill Bloom' investigation uncovered a wallet-generation vulnerability stemming from weak randomness in CryptoJS, a library effectively unmaintained since 2023. The flaw had existed for over twelve years, was fixed six years ago, yet downstream wallet packages continued relying on insecure seed generation. Attackers were actively exploiting the vulnerability during the investigation, forcing a staged disclosure to protect unknown victims. Coinspect combined on-chain analysis, reverse engineering, and source-code research to identify affected wallets and built a public address checker for users to assess exposure.