Ill Bloom Vulnerability Exposes Over $5 Million in Cryptocurrency Theft
The Ill Bloom vulnerability has exposed over $5 million in cryptocurrency theft, according to blockchain security firm Coinspect. The issue arises from weak and predictable randomness in wallet recovery phrases generated by certain apps.
A recovery phrase is a crucial component of a wallet's security, as it allows users to restore access to their funds even after losing their device or forgetting their password. However, when using an insecure random number generator, the phrase can be predicted, making it vulnerable to theft.
The vulnerability affects older or lesser-known mobile apps and browser extensions, some of which have been in circulation since 2018. Coinspect has identified five affected implementations but has withheld their names, following a staged disclosure process while notifying vendors directly.
The Ill Bloom vulnerability is not limited to personal use; it also applies to wallets provisioned or managed for others, such as company treasuries or client accounts. Users are advised to check their wallets against the list of exposed addresses and retire any matching wallets by generating a new one on a hardware device or current software wallet.