Thousands of crypto wallets could be drained right now. The culprit? Weak recovery phrases.
Security firm Coinspect dubbed the flaw “Ill Bloom.” It affects wallets on Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana. The root cause is a weak random number generator some software wallets used when creating seed phrases.
“If funds recently moved without your permission, this vulnerability may be why,” Coinspect warned.
The damage is already real. At least $5 million has been stolen since May 27. One attack that day hit 431 out of 2,114 vulnerable wallets, draining $3.1 million. Another $2 million moved from exposed wallets on Sunday.
The affected wallets go back as far as 2018. The vulnerability mostly shows up in lesser-known mobile wallets. Hardware wallet users are safe. Most current software wallets are fine too.
Coinspect published a checking tool so you can see if your address is exposed. They’re holding back exploit details for now.
SlowMist said it’s monitoring the situation closely.
This isn’t a new type of problem. In 2023, Ledger found that Trust Wallet browser extension seeds were vulnerable to brute-force attacks — limited to about 4 billion combinations, crackable in under a day with a few GPUs. Also in 2023, a bug in the Libbitcoin Explorer wallet led to $900,000 in stolen crypto.
The lesson keeps repeating. If your wallet software cut corners on randomness, your funds aren’t safe. Check your addresses.
