Post
CRITICAL ⚡ MUST-KNOW

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

· vulnerability · zero-day

Security firm Coinspect disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already exploiting it. The flaw lies in how certain wallet software generated recovery phrases: when the phrase is created with weak randomness, an attacker can work it out and take control of the funds it protects. Coinspect has confirmed at least one coordinated sweep, on May 27, that used this technique to drain over $5 million from affected wallets. Users of the affected wallet software should generate a new recovery phrase using a wallet confirmed to use proper randomness and move funds to it.