Coinspect says insecure wallet seeds since 2018 led to $3.14 million stolen last month

Coinspect says insecure wallet seeds since 2018 led to $3.14 million stolen last month

The “Ill Bloom” flaw in some self-custodial wallets’ recovery phrase generation has exposed thousands of accounts since 2018 across multiple blockchains, with about $5 million linked to thefts and recent fund movements.

BTC
ETH
SOL

Summary

Coinspect Security said a wallet-generation flaw dubbed “Ill Bloom” has left thousands of crypto wallets created with insecure code since 2018 vulnerable across Bitcoin, Ethereum, Layer 2 networks, TRON and Solana. The weakness affects some self-custodial wallets that used defective random number generators, potentially allowing attackers to predict recovery phrases and brute-force access to funds. Coinspect said $3.14 million was stolen last month, including about $3 million from hundreds of accounts on May 27, while roughly $2 million more was moved from exposed wallets in recent hours, bringing the amount linked to thefts and related wallet movements to about $5 million. The firm said many thefts were unreported, on-chain analysis showed fund consolidation and laundering patterns, and many affected users may be in China.

Terms & Concepts
  • Ill Bloom: Name given to the wallet-generation vulnerability affecting wallets created with insecure code since 2018
  • self-custodial wallets: Wallets users control without intermediaries
  • recovery phrase: Backup word sequence used to restore wallet access