
The “Ill Bloom” flaw in some self-custodial wallets’ recovery phrase generation has exposed thousands of accounts since 2018 across multiple blockchains, with about $5 million linked to thefts and recent fund movements.
Coinspect Security said a wallet-generation flaw dubbed “Ill Bloom” has left thousands of crypto wallets created with insecure code since 2018 vulnerable across Bitcoin, Ethereum, Layer 2 networks, TRON and Solana. The weakness affects some self-custodial wallets that used defective random number generators, potentially allowing attackers to predict recovery phrases and brute-force access to funds. Coinspect said $3.14 million was stolen last month, including about $3 million from hundreds of accounts on May 27, while roughly $2 million more was moved from exposed wallets in recent hours, bringing the amount linked to thefts and related wallet movements to about $5 million. The firm said many thefts were unreported, on-chain analysis showed fund consolidation and laundering patterns, and many affected users may be in China.