← All stories
● Covered by 1 source · 1 reportHigh impact

Vulnerability 'Ill Bloom' Leads to $3.1 Million Loss in Cryptocurrency Wallets

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Ill Bloom vulnerability allows theft via weak recovery phrases.
  • $3.1 million was drained from 431 wallets due to this flaw.
  • Affected wallets include older or lesser-known mobile wallets.

Overview of the Ill Bloom Vulnerability

Coinspect has disclosed a critical flaw termed 'Ill Bloom', which affects how certain cryptocurrency wallets generate recovery phrases. When these phrases are generated with weak randomness, they become susceptible to exploitation by attackers.

Details of the Attack

On May 27, a coordinated attack drained about $3.1 million from 431 vulnerable wallets, with a substantial portion lost in Bitcoin. Coinspect has observed more movements from potentially exposed wallets, totaling around $2 million, although it is unclear how much of this is due to theft versus user-initiated transfers.

Affected Wallets and Users

Most modern hardware wallets and mainstream software wallets are not affected by this vulnerability, according to Coinspect. However, older or lesser-known mobile wallets from as far back as 2018 may be at risk, posing a significant concern for their users.

Identifying Vulnerable Wallets

Coinspect has not publicly disclosed the specific wallet applications involved in the vulnerability. To check if a wallet has been compromised, users can enter their public wallet address into the free checker at illbloom.org. If a match is found, users should consider transferring their assets to a secure wallet.

Technical Aspects of the Vulnerability

The vulnerability stems from a weak random-number generator used in the affected wallets, which reduced the efficacy of the recovery phrases intended to secure user funds. This inadequacy meant that an attacker could feasibly predict wallet addresses derived from the compromised phrases. Coinspect has created a watchlist of these weak wallets but has not revealed the exact parameters of the flawed randomness.

Conclusion

The Ill Bloom vulnerability highlights significant security weaknesses in certain cryptocurrency wallets, underscoring the importance of robust random number generation in securing funds. Users of potentially vulnerable wallets should take immediate precautions by checking their wallets and moving funds if necessary.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The 'Ill Bloom' vulnerability discovered by Coinspect allows attackers to exploit weakly generated recovery phrases in cryptocurrency wallets. This flaw has already resulted in the theft of approximately $3.1 million from 431 wallets, highlighting significant risks for users of older or lesser-known wallet software.