Unauthorized news on hackers, data breaches, zero-day exploits, ransomware and AI. Original reporting and analysis for people who actually read the source.

Breaches

Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets

Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets

Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million.

The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator, which shrank the pool of possible seed phrases from astronomically large to something an attacker could search. From there it was a matter of reconstructing the full set of weak phrases, deriving the corresponding addresses, and checking the blockchain for which ones held funds. Such wallets look normal, their word lists appear random, yet the phrase can be brute forced and every balance across every connected chain drained.

The main blow came on May 27, 2026: in a coordinated sweep, roughly $3.1 million was pulled from 431 wallets within hours, with funds from unrelated wallets flowing to the same collection addresses. A second, opportunistic theft followed on June 10, when $2.1 million in USDT was taken from a single exposed wallet. Bitcoin was hit hardest, around $2.57 million, with more than $1.1 million gone from one address. By June 30, Coinspect counted 2,114 vulnerable addresses across Bitcoin, Ethereum, Rootstock, Tron, and Polygon, and the number keeps growing.

The attacker's identity has not been disclosed, and no CVE has been assigned. Coinspect has launched a free checker at illbloom.org and advises owners of potentially affected wallets to treat their recovery phrase as compromised even if the funds are still in place: create a new wallet with a new phrase and move the assets there, without importing the old phrase into other apps. The firm stresses that a genuine checker never asks for secrets and will never request seed phrases, private keys, signatures, or transaction approvals.

Ill Bloom continues a string of similar weak-key incidents. Funds have been drained the same way before, through the Milk Sad bug (CVE-2023-39910) in Libbitcoin Explorer and a flaw in the Trust Wallet browser extension (CVE-2023-31290), as well as the Randstorm campaign that affected Bitcoin wallets created between 2011 and 2015.

Based on reporting by The Hacker News and Coinspect.

Share this article
Share

Written by

Martin
Martin
Editor of Russian Hackers. Unauthorized news on hackers, breaches, exploits and AI.

Read next

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
By Martin

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Comic-poster cover: a cracked security shield shattering under 570 flaws and two zero-days

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Comic-poster cover: a hacker prying open a Windows registry hive, the LegacyHive zero-day