Your secret phrase was just guessed. Hackers began to clean crypto wallets with impunity

The weak place of the crypto wallet is often hidden not in the blockchain, but in the moment when the user first receives the recovery phrase. Coinspect has described the vulnerability of Ill Bloom, which is already being used to withdraw funds from wallets created under certain conditions.

Experts have dismantled the recent incident with theft of assets and found additional addresses associated with the same cause. According to current data, the problem affects a limited set of wallets, where recovery phrases were created with a weak accident. Such a failure reduces the cryptographic stability of the phrase and allows you to choose addresses that could arise from vulnerable phrases.

Coinspect checked the script from beginning to end: determined the reason, generated addresses that could appear from weak phrases, and checked them with the public blockchain data. The first confirmed traces of operation in the network date back to May 27 of this year, but earlier cases are not yet excluded.

According to the company, users of hardware wallets are not affected. Most modern software wallets also do not look vulnerable. The most likely risk group, according to Coinspect, includes users of less common mobile software wallets, where the recovery phrase could be created by an insecure generator of random numbers.


The risk is not limited to one network. One vulnerable recovery phrase can open access to funds on different blockchains, including Bitcoin, Ethereum, Tron, Polygon, Solana, BNB Chain, Arbitrum, Optimism, Base and other networks. The public address does not show which application the wallet was created, so Coinspect does not name all potentially vulnerable programs.

The company has already launched checking at the public address. The service compares the address with a set of known vulnerable addresses that still have funds, and does not require the introduction of classified data. A negative result does not guarantee the security of the wallet, since the set of addresses is not considered complete and can be expanded as you analyze.

If the address coincided with the base of Ill Bloom, Coinspect advises to create a new wallet with a new recovery phrase and transfer funds to new addresses. Updating an application or importing an old phrase into another wallet does not eliminate the risk. Also, experts reminded that users can not enter the recovery phrase, private key, password or backup of the wallet in any verification forms.
 
Top Bottom