Ill Bloom's weak seed generation.
On July 6, security firm Coinspect disclosed Ill Bloom, a flaw in how some wallets generated their recovery phrases. About $3.1 million was drained from 431 wallets on May 27, part of nearly $5 million moved from exposed accounts across six chains.
A recovery phrase comes from a random number chosen when a wallet is created, normally impossible to guess. The affected wallets used a weak generator that shrank the possibilities to about four billion. A few graphics cards can run through four billion in under a day.
With the range that small, an attacker can regenerate the phrase without ever seeing it. The wallet worked and the cryptography held. What failed was the randomness at the moment of creation.
A seed phrase is only as strong as the randomness behind it. Seeds generated on a hardware wallet's dedicated chip were not affected. The exposed ones trace to older, lesser-known mobile apps.
Source: https://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/
Related
SciPHR