CVE Tools
Back to feed
Exploited in the wild Cryptocurrency Wallets

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

A critical vulnerability dubbed Ill Bloom has been actively exploited by attackers to steal over $3.1 million from cryptocurrency wallets. The flaw lies in how certain wallet applications generated recovery phrases—key components for accessing funds—with insufficient randomness, allowing malicious actors to predict and access them. Security firm Coinspect reported a coordinated theft on May 27, draining 431 wallets, with additional losses totaling more than $5 million since then. Older or less-known mobile wallets are particularly at risk. Coinspect advises users to use the free tool at illbloom.org to check if their wallet is affected and to move funds immediately if compromised. This issue mirrors past flaws such as CVE-2023-39910 and CVE-2023-31290, where predictable random number generators led to similar attacks.