Code & Chain · Signal Desk

Ill Bloom Vulnerability Steals $5 Million from Crypto Wallets

Original sourceCryptonomist

Summary

A security flaw dubbed Ill Bloom affects the seed phrase generation of some crypto wallets due to a flaw in the random number generator that lets attackers predict seed phrases and steal funds. By late May, about $5 million had been stolen with hundreds of incidents reported; CertiK and PeckShield…

Key points

  • This vulnerability impacts self-custodial wallet users, especially those relying on wallets with flawed RNG for seed phrase generation, exposing wallet supply chain security issues.
  • Millions of self-custodial wallet users could be at risk of fund theft due to wallet random number generation flaws.
  • Users should check the source of their wallets, prioritize using security-audited hardware wallets or reputable software wallets, and consider changing their seed phrase.
  • Reminiscent of the 2014 Android random number bug that led to massive Bitcoin theft, again highlighting the critical role of random number generation in wallet security.

Editorial note

This page is Code & Chain's editorial summary of public sources. It may be prepared with AI assistance and published through an automated workflow. Refer to the original sources; this content is not investment, legal, or tax advice.