Coinspect Exposes Ill Bloom Wallet Recovery Phrase Flaw
Update wallet software to use cryptographically secure random generators for recovery phrases and re‑generate phrases for affected users.
Patch wallet software to use secure RNG for recovery phrases, re‑generate recovery phrases for affected users, and monitor for unauthorized access.
Summary
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. The firm has confirmed one coordinated sweep on May 27. The vulnerability affects wallet software that does not use cryptographically secure random generators. Users with weak recovery phrases are at risk of losing all funds. The incident demonstrates the criticality of secure random number generation and calls for immediate patching of wallet software.
Key changes
- Coinspect identified a crypto wallet flaw dubbed Ill Bloom
- The flaw lies in the generation of recovery phrases using weak randomness
- Attackers can derive the recovery phrase and take control of the wallet
- The vulnerability affects wallet software that does not use cryptographically secure random generators
- Users with weak recovery phrases are at risk of losing all funds
- The incident demonstrates the criticality of secure random number generation
- Coinspect recommends updating wallet software to use secure RNG
- A coordinated sweep occurred on May 27