‘Ill Bloom’ and Bust: Weak Randomness Lets Attackers Drain Over $5M From Crypto Wallets

In cryptocurrency, the recovery phrase is everything. Those seed words are the master key to the money, and if an attacker can guess them, there is no password reset, no chargeback, and no help desk — just an empty wallet. That is precisely the nightmare Coinspect has disclosed.

According to reporting relayed from The Hacker News, security firm Coinspect has detailed a flaw it calls Ill Bloom, and says attackers are already using it. The problem lies in how some wallet software generated its recovery phrase: when that phrase is produced with weak randomness, an attacker can work out the possibilities and reconstruct it, taking control of everything the phrase protects. Coinspect reports confirming one coordinated sweep on May 27, and losses exceeding $5 million. We’ll flag that the specific affected wallet software is described in general terms in the reporting rather than as a single named product, so treat scope as still coming into focus.

Why weak randomness is fatal here

A recovery phrase is only secure because it is drawn from an astronomically large space of possibilities — so large that guessing is hopeless. That guarantee rests entirely on the randomness used to generate it. If the underlying random number generator is weak, predictable, or seeded poorly, the space of realistic possibilities collapses from “the number of atoms in the galaxy” to “something a motivated attacker can grind through.” The wallet still looks and behaves normally; the entropy that was supposed to protect it simply isn’t there. It is one of the oldest failure modes in cryptography, and it is unforgiving because the funds are irreversible.

What to do about it

  • Assume affected phrases are burned: If your wallet was generated by software implicated in this flaw, treat the recovery phrase as compromised and move funds to a wallet generated by trusted, audited software on a secure device.
  • Generate seeds on hardware: Prefer reputable hardware wallets that use vetted, dedicated randomness for seed generation.
  • Watch Coinspect’s disclosure: Follow the firm’s guidance for the specific software and versions affected as details firm up, and act quickly if yours is named.
  • Don’t reuse a suspect seed: Never import a potentially weak recovery phrase into a new wallet — the weakness is in the phrase itself, not the app.

The outrage

Weak randomness in seed generation is not an exotic, unforeseeable bug. It is a foundational mistake, well understood for decades, with well-known correct answers baked into every serious cryptography library. Shipping a wallet — a product whose entire job is to protect irreversible money — with entropy that an attacker can outrun is the software equivalent of selling a safe with a keyhole you can see through.

The victims here don’t get a do-over; that’s the cruelty of the space. If you build wallet software, generating a recovery phrase correctly is the one thing you are not allowed to get wrong. Ill Bloom is a $5-million-and-counting reminder that “we used a random number” and “we used enough randomness, correctly” are very different sentences.

Leave a Reply

Discover more from Cyber Outrage

Subscribe now to keep reading and get access to the full archive.

Continue reading