Thousands of Crypto Wallets Exposed by 'Ill Bloom' Recovery Phrase Flaw, Coinspect Warns
Security firm Coinspect has identified a vulnerability it calls "Ill Bloom" that puts thousands of crypto wallets across multiple blockchains at risk. The flaw stems from weak recovery phrase generation, the firm said.
Key takeaways
- Security firm Coinspect disclosed a vulnerability it calls "Ill Bloom" that puts thousands of crypto wallets at risk across multiple blockchains.
- The flaw stems from weak recovery phrase generation caused by insufficient randomness or a flawed entropy source, allowing an attacker to reconstruct a victim's recovery phrase.
- The vulnerability spans more than one blockchain, so users across different networks and potentially different wallet applications may be exposed.
- Coinspect did not publish a single-chain count, describing the exposure only as "thousands" of wallets without specifying which chains are most affected.
- Users who have not moved funds since wallet creation would carry the full balance risk if their phrase could be derived by a third party.
Security firm Coinspect has identified a vulnerability it calls "Ill Bloom" that puts thousands of crypto wallets across multiple blockchains at risk. The flaw stems from weak recovery phrase generation, the firm said.
What the Vulnerability Does
Recovery phrases — typically a sequence of words generated when a wallet is created — function as a master key to a user's funds. If the process that generates those phrases relies on insufficient randomness or a flawed entropy source, an attacker can narrow the search space and reconstruct a victim's phrase without their knowledge. Coinspect's "Ill Bloom" finding centers on exactly this weakness.
The firm's disclosure indicates the problem spans more than one blockchain, meaning users across different networks and, potentially, different wallet applications may be exposed.
Scope and Risk
Coinspect did not publish a single-chain count. The characterization of "thousands" of wallets suggests meaningful exposure without specifying the full attack surface or which chains carry the greatest concentration of affected addresses. Users who have not moved funds since wallet creation would carry the full balance risk if their phrase could be derived by a third party.
What Coinspect Is
Coinspect is a blockchain security firm that conducts audits and vulnerability research across crypto protocols and wallet software. Its disclosure of "Ill Bloom" follows the pattern of named-vulnerability releases designed to pressure vendors toward patches while alerting users.
Newssos has requested additional technical detail from Coinspect. Users concerned about wallet exposure should consult the firm's full advisory and consider migrating funds to a freshly generated wallet pending patch confirmation from their wallet provider.