Double Threat: Trezor Phishing Scam and 'Ill Bloom' Bug Plague Crypto Wallets, Costing Users Millions

2 hour ago 3 sources negative

Key takeaways:

  • The Ill Bloom vulnerability forces wallet migrations, likely producing short-term sell pressure on Bitcoin.
  • Phishing via Google ads exposes systemic onboarding flaws, potentially cooling new retail investor entry.
  • Dormant compromised seed phrases remain a latent risk, potentially triggering flash liquidations.

A pair of severe security incidents shook the cryptocurrency world on August 7, exposing vulnerabilities in both user-facing interfaces and the underlying software of popular wallets. The first involved a Trezor user who lost his life savings to a sophisticated Google phishing ad, while the second revealed a critical, 12-year-old bug in the CryptoJS JavaScript library that allowed attackers to brute-force wallet seed phrases, leading to more than $5.7 million in thefts.

Trezor phishing via Google sponsored ad

A crypto user identified as David (@ReallyBadDay99) reported that he lost his entire savings after clicking on a sponsored Google search result for “Trezor wallet.” The ad led him to a convincing phishing page hosted on Google Sites, which requested his wallet recovery information. Once he entered his seed phrase, attackers drained his funds into a Bitcoin address (bc1qrz33mr7tx8wrpcs2pxrvv83hqwpm907s9shkz4) that David shared with investigators ZachXBT and CertiK. The scam page was still live at the time of his post, and he claimed it was “vacuuming up millions.”

Trezor responded with a broader warning, noting an increase in spoofed websites appearing in sponsored search results. The company stressed that no one should ever enter a wallet backup on a website and urged users to verify they are on the official Trezor domain. Google ads have become a recurring attack vector; crypto.news previously reported that malicious ads for Uniswap helped scammers siphon at least $400,000, and Security Alliance data linked over $1.27 million in losses to similar campaigns within a two-week window earlier this year. The Trezor incident adds to a growing list of phishing attacks abusing Google's advertising and hosting infrastructure.

‘Ill Bloom’ vulnerability in CryptoJS drains thousands of wallets

In a separate but equally alarming development, a vulnerability dubbed Ill Bloom was disclosed, tracing back to a defective random number generator in CryptoJS library versions 3.x (except 3.2.0 and 3.2.1). The bug, present for roughly 12 years, drastically reduced the entropy of seed phrases generated by wallets that used the library. Normally, a 12-word seed phrase would be computationally infeasible to crack, but the flaw narrowed the possibilities enough that attackers could brute-force private keys using standard home computers.

The first mass exploitation occurred on May 27, 2026, when 431 accounts were drained in a single day, netting $3.14 million. By August, the attack had expanded to over 2,100 addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks. Total losses exceeded $5.7 million, with Bitcoin holders bearing the brunt at $2.57 million, followed by Ethereum ($286,000), Rootstock ($177,000), Tron ($81,000), and Polygon ($23,000).

Confirmed affected wallets include RWallet (RRWallet), Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet. Several of these projects have shut down or are no longer offering support. Bitcoin Libre patched the bug early, NanChat released a fix, but Bexo Wallet’s update was still awaiting app store approval. Critically, simply updating the wallet application does not protect users whose seed phrases were generated by a vulnerable version—those keys remain mathematically compromised forever. Experts are urging anyone who might have used an affected wallet to immediately move funds to a new wallet created with a secure seed phrase.

The dual incidents spotlight persistent security gaps in the crypto user journey, from clicking search ads to trusting third-party libraries, and underscore the need for heightened vigilance and better auditing of wallet software.

Previously on the topic:
Aug 2, 2026, 8:52 a.m.
Bitcoin Hardware Wallet Exploit Spurs Institutional Custody Debate
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.